ISO/IEC 42001 and AI Deployment Governance

Written by Jakub Rusinowski · Last updated 2026-09-13 · Assessment logic is deterministic and runs in your browser

This section is practitioner guidance on deployment and governance mechanics, not legal advice. Regulatory classification turns on facts about intended purpose and real-world use that a questionnaire cannot establish — involve your counsel or DPO for decisions about your specific obligations.

ISO/IEC 42001:2023 is a management-system standard: it specifies requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation. Its subject is your organisation — policies, roles, risk process, lifecycle controls and an improvement loop — not any individual model or deployment. That distinction is the whole of what most people get wrong about it.

ISO/IEC 42001 Certifiable standard — audited against your organisation

  • Version 2023
  • Publisher ISO/IEC
  • Last verified 2026-09-13

The first management-system standard for artificial intelligence. ISO describes it as specifying requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS) within an organisation. Its subject is the ORGANISATION — its policies, roles, risk process, lifecycle controls and improvement loop — not any individual model or deployment.

What this tool does not do

  • ISO/IEC 42001 certifies an organisation's management system through an accredited certification body. A model, a deployment, or an assessment produced here cannot be "ISO 42001 compliant".
  • The standard's control text is copyrighted and sold by ISO. This tool stores control identifiers and our own short descriptions, never the published wording.
  • Our mapping shows where a deployment-level control relates to an organisational clause. Relating is not satisfying: an implemented technical control does not discharge a management-system requirement on its own.

Official source ↗

A model cannot comply with ISO/IEC 42001

This sentence appears in vendor material constantly and it is a category error, in the same family as "this laptop is ISO 9001 certified". ISO/IEC 42001 is a management-system standard in the same structural family as ISO 9001 and ISO/IEC 27001: it describes what an *organisation* must establish and maintain. Certification is issued by an accredited certification body, against a defined scope, after an audit of that system.

What can be true is: *our organisation operates an AI management system certified to ISO/IEC 42001, and this deployment sits within its scope.* That is a meaningfully different claim, and it is the one to ask a vendor for — along with the scope statement, which is where the interesting detail usually is.

Nothing this tool produces is evidence of conformity to ISO/IEC 42001, and nothing it produces could be. What it does is identify the deployment-level controls that a certified management system would expect to see operating, and show you which clause family each relates to.

What a deployment contributes to an AI management system

If your organisation is working toward ISO/IEC 42001 — or already certified and adding an AI deployment into scope — the questions an auditor asks about one system are fairly predictable, and they are the same questions this assessment generates:

The overlap with EU AI Act preparation is substantial and it is not coincidental — but overlap is not equivalence, and the next section is the important one.

ISO/IEC 42001 is not a route to EU AI Act compliance

Certification to ISO/IEC 42001 is a genuine and useful thing to have. It is not compliance with the EU AI Act, and treating it as a substitute produces a specific and expensive failure: an organisation with a certified management system that has never classified its systems under Article 6 and does not know which of them are high-risk.

The differences that matter:

ISO/IEC 42001EU AI Act
NatureVoluntary standard, certifiableLegislation, mandatory in scope
SubjectThe organisation's management systemThe individual AI system and its intended purpose
Who decidesAn accredited certification bodyRegulators, market surveillance authorities, courts; a notified body for some high-risk systems
Failure modeLoss of certificationEnforcement, with penalties scaled to the violation
ClassificationNot required by the standardThe central operation — everything follows from it

A harmonised-standards route exists under the Act generally, and conformity with harmonised standards published in the Official Journal confers a presumption of conformity with the requirements they cover. That is a specific legal mechanism attached to specific standards, and it is not a general "ISO certification counts" principle. Check what is actually listed rather than assuming.

Our mappings therefore label the ISO/IEC 42001 relationship as strong rather than direct on most controls: same activity, different subject, and having the organisational process does not evidence that this system went through it.

Deployment controls that relate to ISO/IEC 42001

The identifiers below are clause families and Annex A control groups. This repository stores identifiers and our own descriptions only — ISO/IEC 42001's control text is copyrighted and sold by ISO, and reproducing it here would not be lawful.

AI risk management process CTL-RISK-001

A documented, iterative process that identifies the risks this AI system poses to health, safety and fundamental rights, estimates them against the intended purpose and reasonably foreseeable misuse, and records the mitigations adopted. Reviewed on a schedule and after material change, not written once.

Clause 6.1 / AI risk assessment — Strong · high confidence

Actions to address risks and opportunities, and the AI risk assessment process

ISO/IEC 42001 requires the organisation to define and apply an AI risk assessment process within its management system. The relationship is strong but not direct: the standard governs the ORGANISATION'S process, while this control is about one system. Having the process does not evidence this system was assessed.

Last verified 2026-09-13

Human oversight of AI output CTL-OVERSIGHT-001

A named human role that can understand the system's output and limitations, decide not to use it, and override or reverse it — with the authority and the time to actually do so. Oversight is a staffed procedure, not a checkbox in a UI.

Annex A — human oversight and AI system lifecycle controls — Strong · medium confidence

Controls on responsible use, including defined human oversight of AI systems

ISO/IEC 42001's Annex A includes controls on the responsible use and operation of AI systems, human oversight among them. Strong rather than direct because the standard asks the organisation to determine appropriate oversight, while Article 14 specifies capabilities the system must afford.

Last verified 2026-09-13

Input and reference data governance CTL-DATA-001

Know what data reaches the model and whether it is fit for the purpose: where it came from, whether it is relevant and sufficiently representative for the people the system is used on, what is excluded, and how errors and gaps are handled. For a retrieval system this covers the corpus, not just the prompt.

Annex A — data for AI systems — Strong · high confidence

Controls on data provenance, quality and preparation for AI systems

ISO/IEC 42001's Annex A includes a group of controls specifically on data for AI systems — provenance, quality, and preparation. This is the closest non-legal analogue to Article 10.

Last verified 2026-09-13

Disclosure to the people who use or are affected by the system CTL-TRANSPARENCY-001

Tell people they are interacting with an AI system, at the point of interaction. Where the system is high-risk and makes or assists decisions about a person, inform that person as well.

Annex A — information for interested parties — Strong · medium confidence

Controls on communicating AI system information to users and affected parties

ISO/IEC 42001 includes controls on providing information about AI systems to interested parties. Strong: same objective, organisation-scoped.

Last verified 2026-09-13

System and model documentation CTL-DOC-001

A record of what is deployed: the model and its exact version, the quantisation and serving stack, the hardware, the configuration, the known limitations, and the intended purpose. This is the document every other control cites.

Clause 7.5 / Annex A — AI system documentation — Strong · high confidence

Documented information requirements and AI system documentation controls

The standard requires documented information across the management system and carries specific AI system documentation controls in Annex A.

Last verified 2026-09-13

Post-deployment performance monitoring CTL-MONITOR-001

Measure whether the system still does what the documentation says it does. For a system affecting people, measure it across the groups it affects, not only in aggregate.

Clause 9 / Annex A — performance evaluation — Strong · high confidence

Monitoring, measurement, analysis and evaluation within the AI management system

Clause 9 is the management system's performance evaluation requirement, which encompasses monitoring of AI systems in scope.

Last verified 2026-09-13

Named accountability and AI literacy CTL-GOV-001

Someone owns this system by name. The people operating it understand what it can and cannot do. Article 4 of the AI Act makes AI literacy a duty for providers and deployers, and it applied from February 2025 — earlier than most of the rest.

Clause 5 / Clause 7.2 — Direct · high confidence

Leadership and organisational roles, and competence requirements

Leadership, roles and competence are core management-system clauses and are the closest direct analogue to a named-owner-plus-literacy control.

Last verified 2026-09-13

Assess a specific deployment

The generic answer is on this page. The specific one depends on what your system is for, who it affects and what it decides — which is what the assessment asks about.

Create Compliance Profile →

Automated assessment based on the information you provide. Not legal advice, certification or an audit.

Frequently asked questions

Can LLM Configurator certify us to ISO/IEC 42001?
No, and neither can any other software. ISO/IEC 42001 certification is issued by an accredited certification body after an audit of your management system against a defined scope. This tool identifies deployment-level controls that relate to the standard and shows which clause family each maps to. That is preparation material, not evidence of conformity.
Does ISO/IEC 42001 replace ISO/IEC 27001?
No — they address different risk universes and organisations increasingly run both. ISO/IEC 27001 concerns the confidentiality, integrity and availability of information. ISO/IEC 42001 concerns the responsible development and use of AI systems, including impacts on individuals that have nothing to do with a security failure. The two share the harmonised management-system structure, so an organisation with a working ISO/IEC 27001 system has most of the scaffolding already.
We are certified to ISO/IEC 42001. Do we still need an EU AI Act assessment?
Yes. The standard does not require you to classify your AI systems under Article 6, and the Act does not care whether you are certified. The two are complementary: the certification says you operate a system for managing AI responsibly; the Act asks which specific obligations attach to each specific system. An organisation can hold the first and be in breach of the second.
Why do your mappings say "strong" rather than "direct" for most ISO/IEC 42001 controls?
Because the subject differs. A mapping is direct when the target requires substantially the same activity on the same object. ISO/IEC 42001 requirements attach to the organisation's process; our canonical controls attach to one deployment. Having a documented AI risk assessment process is not evidence that this system was assessed, so calling the relationship direct would overstate it — and a mapping that overstates is worse than no mapping, because someone will rely on it.

Keep going