ISO 42001 is the international standard for managing AI responsibly, an AI Management System (AIMS). The honest answer to whether you need it: you need it if a customer demands it, or you sell AI and have to prove your governance. Most other organisations need the governance it describes, but not the certificate, at least not yet.
It is not a law, and it is not a box every company has to tick. Here is how to tell which side of the line you are on.
What is ISO 42001?
ISO/IEC 42001, published in December 2023, is the first international standard for an AI Management System. It specifies how an organisation should govern the AI it uses and builds: an AI policy, clear roles and accountability, risk and impact assessment, controls over data and models, monitoring, and continual improvement.
If you know ISO 27001 (information security) or ISO 9001 (quality), the shape is familiar: a management system you run, not a document you file, and one an accredited body can certify. The certificate is the proof an outsider can trust without auditing you themselves.
The honest answer: it depends on who is asking
ISO 42001 earns its keep when it unlocks or protects revenue. The question is not really “are we mature enough” but “does someone we sell to, or are regulated by, need us to have it.” That reframes the whole decision.
When you probably do need ISO 42001
Lean towards certification when one or more of these is true:
- Customers or procurement ask for it. Enterprise and public-sector buyers increasingly list AI governance, sometimes ISO 42001 by name, in their vendor questionnaires. A certificate ends that conversation quickly.
- You sell an AI product or feature. If customers are trusting your AI with their data or decisions, third-party assurance is a competitive advantage and often a requirement.
- You operate in a regulated or high-stakes sector. Finance, healthcare, legal, and the public sector all face scrutiny where demonstrable governance matters.
- You face EU AI Act exposure. ISO 42001 gives you much of the governance machinery the Act expects, in an auditable form.
When you probably do not need it yet
Hold off on certification, but not on governance, when:
- Your AI use is internal, low-risk, and limited (a few productivity tools, no customer-facing decisions).
- No customer or regulator is asking, and none is likely to soon.
- You are early, and the months and cost of an audit would be better spent building the governance itself first.
Note what is missing from that list: “we do not use much AI.” Even light AI use needs basic governance, knowing what tools are in play, who is accountable, and where the risks are. You can often get there without paying for a certificate.
Certification is not the only option
This is the part most “do you need ISO 42001” answers skip. You can adopt the standard without certifying to it. Use ISO 42001 as a blueprint to stand up your AI policy, roles, risk process and controls, capture most of the benefit, and pursue the certificate later if a customer or regulator makes the audit worth it.
For many organisations the right sequence is: build the governance now, certify when it pays for itself. That is what an AI Management System actually is, with or without the badge.
ISO 42001 and the EU AI Act
They are easy to confuse, and they are not the same thing. The EU AI Act is law, with specific obligations and deadlines. ISO 42001 is a voluntary standard for how you organise yourself.
They work well together: a well-run ISO 42001 system gives you the inventory, risk assessment, oversight and evidence the Act expects, in a structure auditors recognise. But certification does not automatically make you compliant with the Act, and being compliant with the Act does not require the certificate. Treat one as the management system and the other as the legal baseline.
How to decide, in four questions
- Is anyone asking for it? A customer, a tender, a regulator. If yes, the case for certification is probably already made.
- Do we sell AI, or use it for decisions that affect people? If yes, you need strong governance regardless, and likely the certificate before long.
- Do we have the governance basics in place? If not, build those first; certification audits what exists, it does not create it.
- Would the certificate pay for itself? In unlocked deals or reduced risk. If you cannot name the payoff, start with alignment, not certification.
The short version
You do not need ISO 42001 because it exists. You need it when a buyer or regulator makes it worth having, and you need the governance behind it either way. Start by getting honest about which of those is true for you, then build the management system first and certify when it earns its place.
Not sure where you stand? The free AI governance readiness assessment gives you a quick, no-email read on your governance maturity in about ten minutes. When you want to turn that into an actual AI Management System, certified or not, talk to us.
For the full picture, see the AI governance guide.
Frequently asked questions
What is ISO 42001?
ISO/IEC 42001 is the first international standard for an AI Management System (AIMS), published in December 2023. It sets out how an organisation should govern its use and development of AI: policies, roles, risk assessment, controls, and continual improvement. Like ISO 27001 for information security, it is certifiable by an accredited body.
Do I legally need ISO 42001?
No. ISO 42001 is a voluntary standard, not a law. Nothing requires you to hold it. What can require it in practice is a customer or procurement process that asks for it as a condition of doing business, and it is one credible way to evidence the governance that regulations like the EU AI Act expect.
When is ISO 42001 worth certifying to?
When it unlocks or protects revenue: enterprise or public-sector buyers asking for it, selling an AI product where customers need assurance, or operating in a regulated sector. If a certificate would remove a sales blocker or a procurement requirement, the business case is usually clear.
Can I adopt ISO 42001 without getting certified?
Yes, and many organisations should start there. You can use the standard as a blueprint to build your AI governance and capture most of the benefit, then pursue certification later if and when a customer or regulator makes it worth the audit cost.
Is ISO 42001 the same as the EU AI Act?
No. The EU AI Act is law with specific obligations; ISO 42001 is a voluntary management-system standard. They are complementary: a well-run ISO 42001 system gives you much of the governance machinery the Act expects, but certification does not by itself make you compliant with the Act.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert