It is an international standard providing requirements and guidance for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). ISO 42001:2023 applies to organizations of all sizes that use or provide AI-based products or services. It is the world's first AI management system standard.
The EU AI Act (Regulation 2024/1689) entered into force on August 1, 2024, and applies in phases. Prohibited practices have applied since February 2025 and general-purpose AI model obligations since August 2025. The Digital Omnibus on AI, in force since July 27, 2026, moved the high-risk deadlines: standalone Annex III systems now apply from December 2, 2027, and AI embedded in regulated products under Annex I from August 2, 2028. A new prohibition covering non-consensual intimate imagery generation applies from December 2, 2026. Penalties reach €35 million or 7% of global annual turnover.
ISO 42001 aligns with key AI Act requirements, including risk management, data governance, documentation, transparency, human oversight, and quality management. Implementing it first can simplify AI Act compliance.
However, ISO 42001 does not replace legal compliance. CE marking, EU registration, prohibited-practice screening, and incident reporting remain separate requirements.
| Objective | Covers |
|---|---|
| A.2 Policies Related To AI | AI Policy, Alignment With Other Organisational Policies, Review |
| A.3 Internal Organization | Roles, Responsibilities, Reporting Of Concerns |
| A.4 Resources For AI Systems | Data, Tooling, Compute, Human Resources |
| A.5 Assessing Impacts Of AI Systems | Impact On Individuals, Groups And Society; Documentation |
| A.6 AI System Life Cycle | Responsible Design, Development, Verification, Deployment |
| A.7 Data For AI Systems | Provenance, Quality, Preparation, Acquisition |
| A.8 Information For Interested Parties | Documentation, Transparency, Incident Reporting To Users |
| A.9 Use Of AI Systems | Responsible Use, Defined Objectives, Human Oversight |
| A.10 Third-Party & Customer Relationships | Supplier Obligations, Allocation Of Responsibility |
Kratikal supports AIMS implementation and internal audits, helping your organization prepare for external audits and achieve ISO 42001 certification.
We assess AI governance maturity, identify ISO 42001 gaps, prioritize recommendations, and develop a roadmap for AIMS implementation.
We identify and categorize technical, ethical, legal, and societal AI risks to design appropriate controls for responsible AI use.
We develop tailored AIMS policies, including AI Governance and Responsible AI policies, based on identified gaps, risks, and organizational needs.
We support AIMS implementation by establishing governance roles, integrating responsible AI practices, deploying monitoring tools, and aligning operations.
We conduct training sessions to strengthen employee awareness, clarify responsibilities, and build internal capabilities for responsible, compliant AI practices.
We evaluate AIMS effectiveness, identify findings, recommend corrective actions, and ensure organizational readiness and conformity before external certification audits.
We support Stage 1 and Stage 2 audits, address certification findings, and help achieve sustainable ISO 42001 certification.
ISO 42001 is voluntary from a regulatory perspective, but enterprise buyers increasingly expect AI governance standards during procurement. For organizations offering AI-enabled products or services, certification can strengthen trust, meet customer requirements, and unlock new business opportunities.
Indian GCCs and IT Services Firms
SaaS Companies
BFSI, NBFCs and Fintech
Healthtech and Diagnostics
HR Tech and Staffing Platforms
Organisation Procuring Third-Party AI
We sincerely appreciate your team's professionalism and diligence throughout the ISO certification process. The structured approach and attention to compliance have been commendable. Your efforts have greatly contributed to strengthening our organization's quality and process standards.
Thanks for prompt response on the project and the follow-ups. Appreciate both Ishita and Kushagra for jumping in quickly to resolve a client-side issue with the report. We might look forward to a few more compliance projects like ISO shortly.
Regular third-party audits give customers and boards verifiable proof, not promises.
Maps to EU AI Act governance articles and MeitY's seven principles.
Clears the AI section now appearing in every enterprise security questionnaire.
Extends your existing ISO 27001 ISMS rather than duplicating the programme.
ISO/IEC 42001:2023 is the world's first AI management system standard. It gives organisations a governance structure for AI-specific risks - bias, explainability, data provenance, drift, and human oversight that information security standards do not address.
Any organisation that develops, provides, or uses AI-based products or services. Demand is strongest among Indian GCCs building AI for European clients, SaaS vendors shipping AI features, and anyone facing AI questions in enterprise procurement.
Annex A contains 38 controls under 9 objectives, numbered A.2 to A.10. They cover AI policies, impact assessment, the AI life cycle, data, transparency, use, and third-party relationships. Controls are selected by risk.
Yes. BIS adopted it as IS/ISO/IEC 42001:2023, an Indian national standard. MeitY's India AI Governance Guidelines name it directly in Annexure 6. Certification is voluntary but increasingly appears in enterprise and public sector procurement.
No. It is a management system standard, not a conformity assessment, and confers no presumption of conformity. It maps closely to the Act's governance obligations but excludes CE marking, EU database registration and incident reporting.
The DPDP Act applies to any AI system processing personal data. MeitY's guidelines are voluntary and rely on existing law for enforcement. ISO 42001 supplies the auditable management system that turns those principles into evidenced practice.
Three years, subject to annual surveillance audits by the certification body in years two and three, with a full recertification audit before the cycle ends. This is the same cycle as ISO 27001.
It evaluates an AI system's consequences for individuals, groups, and society: fairness, discrimination, safety, and transparency.