ISO/IEC 42001:2023 - AI MANAGEMENT

Turn "responsible" AI from a slide into a system

Proks Certification badge for compliance with ISO/IEC 42001 standard featuring a checkmark.

Your investor deck has a slide titled “Responsible AI.” Your enterprise prospect just asked you to prove it. The EU AI Act starts biting in 2026, and within three years every serious AI buyer will demand a certificate most of your competitors don’t have yet. This is your first-mover window - ISO/IEC 42001:2023 is open, the auditors are ready, the market hasn’t fully moved.

Proks Certification badge for compliance with ISO/IEC 42001 standard featuring a checkmark.
2023

The world’s first AI management system standard

~40%

Of controls overlap with ISO/IEC 27001:2022

3 - 6 mo

To certify if ISO/IEC 27001:2022 is already in place

3 years

Certificate validity, with annual surveillance

1

THE DIRECTIVE

What ISO/IEC 42001:2023 actually is

The world's first
AI management
system standard.

"We use AI responsibly" needs a paper trail. ISO/IEC 42001:2023 is the standard that turns the claim into an auditable system - not a slide.

Published in December 2023, it sits next to ISO/IEC 27001:2022 the way ISO 13485 sits next to ISO 9001:2015 - shared management-system DNA, with sector-specific extensions. Its Annex A adds controls specific to AI: training-data governance, model lifecycle management, transparency and explainability, human oversight, bias and fairness testing, and incident response for AI-specific failures.

About 40% of the controls overlap with ISO/IEC 27001:2022 - which is why ISO/IEC 27001-certified companies reach ISO/IEC 42001:2023 in 3–6 months instead of 9–12. The audit cycle is identical to ISO/IEC 27001:2022: a two-stage audit, a three-year certificate, and annual surveillance to keep it alive.

2

THE FIT

Who actually needs this

ISO/IEC 42001:2023 stops being a “later” problem the moment one of these describes you.

01
You are building AI products for enterprise.

Vendor AI-governance questionnaires are the new vendor security questionnaires. Buyers will ask - you can be the answer or the excuse.

02
You touch an EU AI Act high-risk category.

Credit scoring, employment, education, healthcare, public services, migration, critical infrastructure. The Act enters full force in August 2026, and ISO/IEC 42001:2023 is the most defensible evidence that you took it seriously before the deadline.

03
You are a foundation-model or LLM provider.

Every downstream customer inherits your governance. They need to prove their stack is governed; you need to prove yours is. The certificate makes that math work.

04
You are closing a Series A or B in 2026.

Sophisticated VCs now ask AI-governance questions in diligence. A certificate shifts the conversation from “tell us about your approach” to “here’s the audit report.”

If none of these describe you - wait. If even one does - yesterday was the best time to start.

3

THE PAYOFF

What you actually get from certification

We could write four paragraphs of marketing copy - instead:

I.

Replace the AI-governance section of every RFP with one PDF. One certificate answers the question your competitors are still drafting paragraphs about.

II.

Hedge the EU AI Act. The Act will demand documented governance for high-risk systems. ISO/IEC 42001:2023 is the most mature framework available today for delivering it.

III.

Earn investor and board credibility. AI governance is moving from optional to expected. Showing up with a certificate is showing up serious.

IV.

Reduce model risk in production. Documented evaluation pipelines, bias testing and incident response mean fewer drift incidents reach production.

V.

Be the AI vendor the cautious enterprise can finally say yes to. The biggest deals are blocked by the most cautious buyers - and caution wants evidence.

4

ANNEX A - THE AI CONTROLS

Annex A is your AI control menu, not your sentence

Where ISO/IEC 27001:2022’s Annex A governs information security, ISO/IEC 42001:2023’s adds the controls a classic ISMS never covered — the ones that make AI auditable. You select what applies to your systems; here are the domains they fall into.

01
Training-data governance

How training, validation and test data is sourced, documented, quality-controlled and kept fit for purpose across the model’s life.

02
Model lifecycle management

Disciplined development, versioning, deployment and decommissioning of models - so what runs in production is what was actually assessed.

03
Transparency & explainability

Making system behaviour, limitations and decisions intelligible to the people who rely on, oversee or are affected by them.

04
Human oversight

Defined points where a human can understand, intervene in and override the system - oversight by design, not by aspiration.

05
Bias & fairness testing

Systematic testing for unfair or discriminatory outcomes, with the evidence trail to show it was done and acted upon.

06
AI incident response

Detection, handling and learning for AI-specific failures - the kind a classic security playbook was never written to cover.

5

THE EU AI ACT

If you touch a high-risk category, the clock is already running

The EU AI Act enters full force in August 2026 and will demand documented governance for high-risk systems. ISO/IEC 42001:2023 is the most defensible evidence that you took it seriously before the deadline.

High-risk categories the act calls out

01
Credit scoring
02
Employment
03
Education
04
Healthcare
05
Public services
06
Migration
07
Critical infrastructure
August 2026
is when eu ai act enters full force

The Act will require documented governance for high-risk systems. ISO/IEC 42001:2023 is the most mature framework available today for delivering it - and the certificate shifts a diligence conversation from “tell us about your approach” to “here’s the audit report.”

6

THE CERTIFICATION ROADMAP

From application to certificate, in four moves

The same transparent, digital-first workflow as our ISO/IEC 27001:2022 audits. Your client portal gives real-time visibility into audit status, reports and non-conformities at every stage.

01

DIGITAL

Application & proposal

Submit your details and AI scope through streamlined digital forms. You receive a clear, transparent proposal tailored to your systems and size.

02

HYBRID / ONSITE

Stage 1 - document review

We review your AI management system: policies, the Annex A controls you’ve selected, risk and impact assessments - confirming you’re ready for the main audit.

03

HYBRID / ONSITE

Stage 2 - implementation

We verify the AI controls work in practice - that data governance, oversight, bias testing and incident response are embedded in how models are actually built and run.

04

OUTCOME

Certification issuance

On success you receive your ISO/IEC 42001:2023 certificate - valid three years, subject to annual surveillance, on the same cycle as ISO/IEC 27001:2022.

7

BUILD ON THE ISMS YOU HAVE

Certify the AI system on the foundation ISO/IEC 27001:2022 already laid

ISO/IEC 42001:2023 doesn’t start from zero. About 40% of its controls overlap with ISO/IEC 27001:2022’s Annex A - the same evidence, extended to cover models and data. If the ISMS already exists, the AI management system is months of work, not a year.

And it rarely stands alone. SOC 2, ISO/IEC 27017, ISO/IEC 27018 and BSI C5 all assume an ISO/IEC 27001:2022-class foundation, and the EU AI Act reads ISO/IEC 42001:2023 as the governance framework. Build the foundation once and every subsequent certificate costs less - one coordinator across the whole engagement.

WHAT ONE FOUNDATION CAN SUPPORT

ISO/IEC 27001:2022

EU AI Act

SOC 2

ISO/IEC 27017

ISO/IEC 27018

BSI C5

GET IN TOUCH

Start your application process
now

Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.

8

FAQs

Clear answers, the same way we run an audit

What exactly is ISO/IEC 42001:2023?

How does ISO/IEC 42001:2023 relate to the EU AI Act?

The standard is new - does the certification body matter?

We already hold ISO/IEC 27001:2022 - how much faster is ISO/IEC 42001:2023?

What does the audit cycle look like?

Why certify now rather than wait?