ISO 42001
A plain-English guide to ISO/IEC 42001, the certifiable AI management standard — what it is, how it differs from the NIST AI RMF, who's asking for it, and how a small business runs an ISO 42001 gap assessment without consultants.
What is ISO 42001?
ISO/IEC 42001:2023 is the world's first certifiable standard for an AI Management System (AIMS) — published December 2023 by the same body behind ISO 27001. Where the NIST AI RMF is a voluntary framework you self-assess against, ISO 42001 is a management standard you can be formally certified to by an accredited certification body, the way companies certify to ISO 27001 today.
The structure is deliberately familiar: management commitment, defined roles, risk and impact assessment, documented policies, supplier management, monitoring, and continual improvement — applied to how your organization develops, buys, and uses AI. Its Annex A provides the reference set of AI controls certifiers look at.
Like ISO 27001, "ISO 42001 compliant" means one of two things: you run an aligned AI governance program internally, or you've achieved formal certification. Most small businesses need the first well before anyone pays for the second.
Who's actually asking for it?
- Enterprise customers, especially in Europe — ISO 42001 is becoming the AI line item on the same vendor questionnaires that ask for ISO 27001, and the EU AI Act rewards exactly the management-system evidence it produces.
- Larger partners and primes — companies building their own AI compliance programs push the requirement down their supply chain, the way SOC 2 propagated.
- Regulated industries — finance, health, and legal buyers want a certifiable, auditable answer to "how do you govern AI?", not just a policy PDF.
If your counterparties are U.S.-centric, they'll usually reference the NIST AI RMF first — start there. If enterprise or EU deals are pulling you toward certifiable, ISO 42001 is the destination, and NIST publishes an official crosswalk between the two, so the work transfers.
What ISO 42001 expects (the core idea)
- An AI policy and accountable leadership for AI use
- An inventory of AI systems with owners, purpose, and lifecycle status
- Risk and impact assessments for AI use cases — including impacts on individuals
- Data governance for what goes into and comes out of AI
- Supplier management for vendors providing AI capabilities
- Human oversight, transparency, and incident handling for AI in operation
- Monitoring and continual improvement — a running system, not a binder
How CyberPolicify helps
CyberPolicify runs a 30-control ISO 42001 gap assessment: a dedicated 12-control AI Governance family (policy and accountability, AI inventory, risk and impact assessment, data governance, third-party AI, human oversight, transparency, AI security, incident management, monitoring, acceptable use) plus the 18 existing security controls the standard leans on, each referenced to the relevant ISO 42001 Annex A clauses.
- Guided assessment with evidence notes per control and a prioritized gap list — the honest picture of where you stand against the standard.
- The 8-document AI governance pack, generated: AI Governance Policy, Generative AI Acceptable Use Guidelines, AI Risk & Impact Assessment Procedure, Third-Party AI Vendor Review Procedure, AI Data Governance Standard, AI Transparency & Disclosure Standard, AI Incident Response Annex, and AI/ML Security Governance — customized to your organization, exported to editable Word.
- One controls picture: gaps become tracked risks with owners and treatment plans alongside your SOC 2, ISO 27001, NIST CSF, CMMC, and AI RMF work.
One honest note: certification itself requires an audit by an accredited certification body — no software subscription replaces that. What CyberPolicify replaces is the consultant-priced readiness work: knowing your gaps, closing them, and holding the documentation certifiers expect.
ISO 42001 vs. NIST AI RMF — which one?
Run the AI RMF first if you're U.S.-facing: it's free, public, and what questionnaires reference today. Choose ISO 42001 when a customer or market demands a certifiable standard. In CyberPolicify they're separate assessments that share the same AI document pack — start with either, and the second is mostly incremental.
The order of operations
- Inventory your AI use — tools, product features, and AI at your vendors.
- Run the ISO 42001 gap assessment and get your control-by-control picture.
- Generate and adopt the AI governance pack — policy first, acceptable use second.
- Put open gaps in the risk register with owners and dates.
- Re-assess quarterly; pursue formal certification only when a deal actually requires it.
Answering "how do you govern AI?" with a management-system gap assessment and signed policies puts a small business ahead of most competitors — certifiable when you need it, credible immediately.
Generate documentation mapped to frameworks
Start with policies and procedures aligned to the framework, then close gaps with a clear plan.