Request a scoping call Contact
← Research

ISO/IEC 42001 is a management system, not a badge

ISO/IEC 42001 asks an organisation to maintain an AI management system. Procurement assurance depends on that system continuing to operate as models, suppliers and use cases change, rather than on documents prepared for an audit.

Governance / Conceptual study
Trace the evidence.
  1. Sources
  2. Evidence links
  3. Decision record

Keep sources linked to the record used for review. The diagram does not represent automatic approval.

A procurement requirement or board decision can make ISO/IEC 42001 certification an immediate priority. The programme sponsor needs to decide what the organisation will maintain after the assessment, as well as what it will present during it.

A certification plan should therefore define operating responsibilities, evidence and review triggers. Preparing policies and assembling an inventory may be necessary steps. They do not establish that those activities will continue when the programme team moves on.

ISO/IEC 42001 is an artificial intelligence management system standard. That phrase is doing all of the work. It is built in the same shape as ISO/IEC 27001 for information security and ISO 9001 for quality: context, leadership, planning, support, operation, evaluation, improvement — a loop the organisation runs, not a list of controls it installs. The controls in Annex A matter, and they are the part everybody reads first, and they are downstream of the loop rather than a substitute for it.

The value of an AI management system depends on how it responds to change. Annex A controls need to sit within a maintained process for setting objectives, assessing risks, reviewing performance and improving the system. A collection of controls without that process leaves important decisions about new models and suppliers unresolved.

Where each version of the work ends up

Two ways to arrive at the same certificate Fig. 01
Implemented as a checklist Implemented as a management system
An inventory assembled for the audit An inventory maintained because a system cannot go live without an entry
Impact assessments written for the systems in scope An assessment triggered by a stage gate, for anything that meets a stated threshold
Policies approved and filed Policies that name an owner and a review date, and are read by the people who build
Supplier questions answered once, at onboarding Supplier obligations in the contract, tested on a cycle
Objectives described qualitatively Objectives with measures, reviewed by management on a schedule that exists

The second column turns audit preparation into ordinary work. Its costs depend on the estate and existing processes. The practical test is whether an owner can produce current evidence without reconstructing it for each assessment.

The loop, in the order it actually has to be built

The sequence that makes an AI management system operate rather than exist Fig. 02
  1. 01 Inventory What AI is in use, including what was bought inside something else.
  2. 02 Classification Which systems matter, against a threshold somebody wrote down.
  3. 03 Controls Annex A, scoped to what the classification says is needed.
  4. 04 Evidence The artefacts each control produces, in the ordinary course of work.
  5. 05 Review Management review with measures, and internal audit that can say no.

An inventory must cover AI embedded in purchased products as well as systems developed internally. Summarisation in a customer relationship platform, triage in a service desk and ranking in a recruitment tool can enter the estate through ordinary product updates. An engineering-only survey can miss those uses. Include procurement owners and business teams, and record the intended purpose and affected people for each entry.

Stage two is where the standard is most often mis-scoped in the other direction. Not every system needs the full apparatus. A threshold written down in advance — consequence to individuals, autonomy of the decision, reversibility, scale — lets an organisation apply weight where it is warranted, and defend the decision not to apply it elsewhere. Without that threshold, everything is either in scope, in which case the programme collapses under its own paperwork, or nothing is, in which case the certificate is describing a very small system indeed.

What it does and does not buy you commercially

A management system assessment and a model evaluation answer different questions. The buyer still needs evidence that a particular system performs adequately in its intended setting. A certificate cannot replace testing of accuracy, access controls, oversight or consequential failure modes.

The relationship to the EU AI Act is similarly oversold. A functioning AI management system produces a great deal of what a high-risk provider would need under the Act — the quality management system, the documentation discipline, the post-market monitoring habit — and that overlap is real and worth having. It is not the same as conformity, the Act has its own harmonised-standards route, and a percentage figure for how much of one covers the other is a marketing artefact rather than a finding.

What this does not tell you

We do not certify anyone, and we are not an accredited certification body. What we do is design the operating model the standard assumes you already have, and tell you honestly which parts of your estate the scope statement should exclude. Interpretation of what the Act requires of your organisation remains a matter for your counsel and your notified body.

Certification need not be the first investment for every organisation. Where external assurance is not yet required, compare it with the immediate value of maintaining an inventory, defining risk thresholds and assessing consequential uses. Choose the sequence that addresses the organisation’s actual exposure and procurement needs.

Before approving the programme, ask who will update the inventory, reassess changed systems and act on review findings after the audit. Fund those responsibilities explicitly. Certification is most useful when it provides assurance about an operating system the organisation intends to maintain.

Filed under · Governance · ISO/IEC 42001 · Governance · Assurance Inference Institute · 02 Oct 2026 (updated)

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.