INTERNATIONAL / ISO

ISO/IEC 42001:2023

Artificial Intelligence Management Systems · Published December 2023 · Certifiable standard · Full text paywalled (ISO commercial standard)

ISO/IEC 42001 is the world's first certifiable AI management system standard. It provides a management system framework for organizations developing, providing, or using AI systems. Like ISO 27001 for information security, 42001 creates an auditable, certifiable AI governance regime.

The standard follows the ISO Annex SL high-level structure, making it compatible with other ISO management system standards (27001, 9001, 14001). Organizations can integrate AI governance into existing management systems. Certification requires third-party audit by an accredited certification body.

Note: The full standard text is a commercial ISO publication (approximately $300 CHF). This analysis is based on the publicly available structure, ISO's official description, and published analyses from accredited certification bodies.

Clauses 4-10 — Management System Core Clauses 4-10

Clause 4 — Context of the organization: Internal/external issues, interested parties, scope of the AI management system.

Clause 5 — Leadership: Top management commitment, AI policy, roles and responsibilities.

Clause 6 — Planning: AI risk assessment, AI objectives, planning to achieve objectives.

Clause 7 — Support: Resources, competence, awareness, communication, documented information.

Clause 8 — Operation: AI system lifecycle, AI risk treatment, operational planning.

Clause 9 — Performance evaluation: Monitoring, measurement, analysis, internal audit, management review.

Clause 10 — Improvement: Nonconformity, corrective action, continual improvement.

AI IMPACT

This is the management system layer — not technical controls, but bureaucracy. Organizations must establish formal AI governance: policies, risk assessments, documented procedures, internal audits, management reviews. The burden is proportional to organization size but the fixed cost of compliance favors large organizations.

Clause 6 (AI risk assessment) is the choke point. Organizations must identify and assess AI risks across the system lifecycle. For companies using many AI systems or rapidly iterating, this becomes a continuous compliance exercise that requires dedicated staff — a cost small organizations can't absorb.

Annex A — AI-Specific Controls Annex A

Annex A provides AI-specific controls organized into categories covering the AI system lifecycle:

A.2 Policies and procedures: AI policy, AI system lifecycle processes, data management policies.

A.3 Organizational roles and responsibilities: AI governance roles, AI system owner, AI risk management responsibilities.

A.4 AI system lifecycle: Requirements analysis, design, development, deployment, operation, monitoring, decommissioning.

A.5 Data management: Data governance, data quality, data provenance, data preparation.

A.6 Transparency and explainability: Documentation, communication of AI system capabilities and limitations.

A.7 Continual improvement: Feedback mechanisms, incident response, post-deployment monitoring.

AI IMPACT — CRITICAL

A.6 (Transparency and explainability) is the compliance trap. The standard requires organizations to document and explain AI system decisions. For simple models, this is feasible. For large language models with billions of parameters, full explainability is technically impossible. The standard creates a requirement that can only be partially met — which means certification bodies have discretion to decide what's "good enough." That discretion favors organizations that can afford premium auditors and extensive documentation.

A.5 (Data management) favors cloud providers. Data governance, provenance, and quality controls are built into cloud AI platforms (AWS, Azure, GCP). Self-hosted AI deployments must build these controls from scratch. The standard doesn't mandate cloud, but the compliance infrastructure is already there for cloud and absent for local AI.

Certification creates market concentration. Only organizations that can afford the certification process (audit costs, documentation overhead, dedicated compliance staff) will be certified. When enterprises require ISO 42001 certification from AI vendors — and they will, because it's the recognized standard — only large, compliant AI providers survive in the market.

Source: ISO/IEC 42001 Official Page · Published analyses from BSI, DNV, and TUV certification bodies
Certification — The Market Gate Certification

ISO 42001 certification requires a third-party audit by an accredited certification body (BSI, DNV, TUV, etc.). The process includes: gap assessment, stage 1 documentation review, stage 2 on-site/remote audit, surveillance audits (annual), and recertification (3-year cycle).

Estimated costs: $30,000-$100,000+ for initial certification depending on organization size, plus $10,000-$30,000 annually for surveillance audits. Implementation costs (staff time, documentation, process changes) can exceed $200,000.

AI IMPACT

The certification cost is a market filter. At $30K-$100K+ for certification and $200K+ for implementation, ISO 42001 certification is accessible to mid-size and large organizations but prohibitive for small AI developers and open-source projects.

Enterprise procurement will require it. Following the standard playbook (voluntary framework → procurement requirement → de facto mandatory), enterprises will add ISO 42001 certification to vendor requirements within 2-3 years. AI vendors without certification will be excluded from enterprise sales — the same pattern as ISO 27001 before it.

The 3-year recertification cycle creates ongoing dependency. Organizations must maintain compliance continuously and pay for recertification every 3 years. This creates a permanent revenue stream for certification bodies and a permanent cost for AI providers — a tax on doing AI business that scales with regulation, not with AI capability.

Source: ISO/IEC 42001 · Certification cost estimates from BSI, DNV published pricing

Related frameworks: ISO/IEC 27001 (infosec equivalent) · NIST AI RMF (US equivalent, non-certifiable) · EU AI Act (regulatory equivalent) · SAFE RFC (industry equivalent)

Investigation tracks: The Compliance Trap · The Infrastructure Play · The Asymmetry