ISO/IEC 42001
AI Management Systems and the Rise of Responsible AI Certification
Executive Summary

Artificial intelligence has moved rapidly from an emerging technology to a core business capability.
Organisations now use AI for:
- customer service;
- recruitment;
- fraud detection;
- forecasting;
- marketing;
- cybersecurity;
- product development;
- document processing;
- decision support;
- software development;
- content generation.
Yet the technology creates governance questions that traditional management systems were not designed to address directly.
Who is accountable for AI?
What risks are being assessed?
How is AI tested?
What data is used?
How are impacts assessed?
How are users informed?
What happens when an AI system behaves unexpectedly?
ISO/IEC 42001:2023 is the world’s first international management-system standard specifically addressing artificial intelligence. It provides a structured framework for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS).
For UK organisations, ISO/IEC 42001 is particularly significant because AI governance is moving toward a combination of regulation, customer expectations, procurement requirements and independent assurance.
UKAS granted its first accreditation for certification of AI management systems in January 2026, marking a major milestone for accredited AI assurance in the UK.
AI Has Become a Management-System Issue
A traditional technology project might ask:
“Does the AI system work?”
A management system asks a much larger set of questions:
- Was the system appropriately designed?
- Who approved it?
- What risks were identified?
- What data does it use?
- What laws and obligations apply?
- What groups could be affected?
- Is performance monitored?
- Are incidents reported?
- Is the system changed under control?
- Are users trained?
- Is there an owner?
This is why AI management cannot be reduced to an IT-security project.
AI can create risks involving:
Technology + data + people + ethics + legal obligations + operations + reputation.
What Is ISO/IEC 42001?
ISO/IEC 42001:2023 specifies requirements for an Artificial Intelligence Management System.
ISO describes it as a framework for organisations developing or using AI systems and for managing risks and opportunities associated with AI.
The standard follows the familiar management-system philosophy found in standards such as ISO 9001 and ISO 27001.
It therefore provides a structured cycle:
Context → Leadership → Planning → Support → Operation → Performance Evaluation → Improvement
This makes it easier for organisations with mature ISO systems to integrate AI governance into an existing management framework.
Certification Is Not the Same as “AI Is Safe”
This distinction is critical.
ISO/IEC 42001 certification does not mean:
- every AI output is correct;
- an organisation has eliminated AI risk;
- a specific AI product is certified;
- every future AI system will automatically be compliant.
Certification provides assurance that the organisation has established and operates an AI management system meeting the applicable requirements.
PJR’s own ISO/IEC 42001 information describes certification as assurance that AI is being used or developed responsibly, while ISO describes the standard as a management-system framework rather than a guarantee of specific technical outcomes.
That distinction should be central to responsible marketing.
The AI Inventory
One of the first questions any serious AI governance programme should answer is:
What AI does the organisation actually use?
This sounds simple.
Often it is not.
AI may exist through:
- software purchased from suppliers;
- cloud platforms;
- embedded functionality;
- employee use of generative AI;
- customer-facing chatbots;
- recruitment tools;
- analytics platforms;
- coding assistants;
- automated decision systems.
An organisation may formally approve one AI platform while employees are independently using several others.
The first task should therefore be building an AI inventory.
A useful inventory may record:
| AI System | Purpose | Owner | Data | Risk | Supplier | Users | Status |
Without an inventory, meaningful governance is difficult.
AI Risk Is Different From Traditional IT Risk
Cybersecurity asks questions such as:
- Can unauthorised users access the system?
- Can data be stolen?
- Can systems be disrupted?
AI governance adds other dimensions:
- Is the output reliable?
- Is the model biased?
- Is the training data appropriate?
- Can the system be manipulated?
- Can the organisation explain decisions?
- Are users relying on outputs inappropriately?
- Can the system produce harmful content?
- Does performance degrade over time?
This creates the need for an organisation-wide approach to AI risk.
AI Impact Assessment
AI governance increasingly requires organisations to think about impacts beyond the organisation itself.
ISO has now published ISO/IEC 42005:2025 on AI system impact assessment, providing a structured approach to identifying, analysing and documenting intended and unintended impacts of AI systems on individuals, groups and society.
This is an important development because it moves the question from:
“Does the organisation face AI risk?”
to:
“Who could be affected by the AI system, and how?”
For example, an AI recruitment system could affect:
- applicants;
- employees;
- recruiters;
- the organisation;
- protected or vulnerable groups.
The impact assessment should therefore consider more than technical performance.
Data Governance
AI systems are only as good as the data and controls surrounding them.
Organisations should understand:
- what data is used;
- where it originates;
- whether it is appropriate;
- who can access it;
- how it is retained;
- how it is protected;
- how errors are addressed;
- whether sensitive information enters external AI tools.
For generative AI, this can be particularly important.
An employee copying confidential client information into a public AI tool may create a governance problem regardless of whether the employee intended to cause harm.
Human Oversight
AI should not automatically be treated as an autonomous decision-maker.
Organisations should determine when human oversight is needed.
For example:
Low consequence
AI generates an internal meeting summary.
Moderate consequence
AI prioritises customer support cases.
High consequence
AI influences employment, credit, safety or other decisions with significant consequences.
The level of human oversight should be proportionate to the use and risk.
A mature AIMS should make these decisions systematic rather than leaving them to individual employees.
AI Literacy
A governance system is ineffective if employees do not understand the technology.
Different groups require different knowledge.
Board and senior management
Need to understand:
- strategic AI risk;
- accountability;
- major use cases;
- regulatory exposure;
- organisational risk appetite.
Developers
Need to understand:
- testing;
- validation;
- security;
- data;
- monitoring.
Business users
Need to understand:
- acceptable use;
- confidentiality;
- verification of outputs;
- escalation.
Procurement
Needs to understand:
- AI suppliers;
- contracts;
- data handling;
- third-party risk.
The concept of AI competence therefore extends beyond an IT department.
AI Suppliers
Many organisations will not develop their own AI models.
They will buy AI-enabled services.
This creates supplier-management challenges.
Questions may include:
- Where is data processed?
- Is customer information used to train the model?
- What happens when the supplier changes the model?
- How are incidents reported?
- What controls does the supplier operate?
- How is performance monitored?
- What contractual rights does the organisation have?
AI governance should therefore connect with procurement and supplier-management systems.
Change Management
AI systems can change rapidly.
A model can be:
- retrained;
- updated;
- replaced;
- integrated with another system;
- connected to a new data source;
- given a new purpose.
That means governance cannot be a one-time approval.
The organisation should know:
When does an AI change require reassessment?
A significant change in model, purpose, data or user population may create a different risk profile.
Performance Monitoring
An AI system that worked effectively six months ago may not perform the same way today.
Organisations should consider performance indicators appropriate to the use case.
Examples include:
- accuracy;
- false positives;
- false negatives;
- complaints;
- bias indicators;
- security events;
- abnormal outputs;
- user escalations.
Monitoring must be proportionate.
Not every AI application requires the same level of surveillance.
The management system should explain why.
Incident Management
AI-related incidents should be capable of being identified, reported and investigated.
Examples could include:
- harmful output;
- inappropriate disclosure;
- unexpected decision;
- model failure;
- biased outcome;
- data breach;
- misuse;
- unauthorised AI deployment.
The organisation should be able to answer:
What happened?
Who was affected?
What stopped the problem?
What caused it?
What must change?
How will recurrence be prevented?
Why ISO/IEC 42001 Is Particularly Relevant to UK Organisations
The UK’s AI governance environment is developing rapidly.
For UK businesses, AI management is increasingly influenced by:
- customer expectations;
- procurement requirements;
- contractual obligations;
- data protection;
- sector regulation;
- corporate governance;
- international supply chains.
The significance of accredited AI certification in the UK increased substantially in January 2026 when UKAS granted BSI the first accreditation for AI management-system certification to ISO/IEC 42001:2023. UKAS describes the development as an important step in trusted and responsible AI assurance.
This means UK organisations procuring AI certification should look carefully at the certification body’s specific accreditation scope, rather than assuming that every ISO/IEC 42001 certificate represents accredited certification.
ISO/IEC 42001 and ISO 27001
These standards are complementary.
ISO 27001
Focuses on information-security management.
Questions include:
- confidentiality;
- integrity;
- availability;
- information-security risk.
ISO/IEC 42001
Focuses on AI management.
Questions include:
- responsible AI;
- AI-specific risk;
- AI lifecycle;
- impacts;
- accountability;
- AI governance.
An organisation operating both systems can create a strong integrated governance model.
For example:
AI system inventory
→ ISO/IEC 42001
Information-security controls
→ ISO 27001
Privacy obligations
→ applicable privacy framework
Business continuity
→ ISO 22301 where applicable.
The result can be a unified digital-governance ecosystem.
What an AI Certification Audit May Examine
A robust AI management-system audit should connect governance documents with actual AI applications.
An auditor may examine evidence such as:
- AI policies;
- AI inventories;
- AI risk assessments;
- impact assessments;
- objectives;
- supplier evaluations;
- competence records;
- data controls;
- incident records;
- monitoring;
- internal audits;
- management review;
- corrective actions.
The strongest evidence will come from actual AI systems.
For example, rather than simply reviewing an “AI Policy”, the audit can follow one live AI system through its lifecycle:
Acquisition → approval → risk assessment → deployment → monitoring → incident handling → change → review
This demonstrates whether the management system operates in practice.
Who Should Consider Certification?
ISO/IEC 42001 can be relevant to:
- software companies;
- AI developers;
- SaaS businesses;
- technology providers;
- financial institutions;
- professional-services businesses;
- healthcare-related organisations;
- manufacturers;
- retailers;
- public-sector organisations;
- organisations using AI at material scale.
The question is not simply:
“Are we an AI company?”
A better question is:
“Does our organisation develop, provide, use or govern AI systems in a way that creates material organisational risk or stakeholder expectations?”
If the answer is yes, AI management deserves formal consideration.
A Practical AI Readiness Programme
A sensible starting point is:
Step 1 — Inventory
Identify every significant AI system.
Step 2 — Categorise
Determine purpose, owner, data and users.
Step 3 — Assess risk
Consider operational, legal, ethical, security and stakeholder impacts.
Step 4 — Establish governance
Assign accountability.
Step 5 — Introduce controls
Develop proportionate controls for data, testing, monitoring, suppliers and human oversight.
Step 6 — Test
Conduct an internal audit and management review.
Step 7 — Certify
Use an appropriate independent certification process.
The Strategic Opportunity
AI governance should not be viewed purely as a defensive exercise.
A mature AIMS can help organisations demonstrate:
- responsible innovation;
- customer confidence;
- governance maturity;
- supplier assurance;
- internal accountability;
- operational discipline.
For organisations selling AI-enabled services, the ability to demonstrate independently assessed AI governance may increasingly become part of the sales conversation.
PJR and the Emerging AI Certification Market
PJR currently offers ISO/IEC 42001 certification information and positions the standard within its wider portfolio of information-security and technology-related management-system certifications.
However, UK organisations should always verify the current accreditation position and exact scope of the certification body before commissioning accredited certification.
This is particularly important in a new certification market where national accreditation arrangements are still developing.
Conclusion
The strategic importance of AI is increasing faster than the governance structures of many organisations.
ISO/IEC 42001 provides a way to close that gap.
It transforms AI governance from:
“We have an AI policy.”
into:
“We have a structured, auditable management system governing how AI is selected, developed, deployed, monitored and improved.”
As AI becomes embedded into everyday business processes, that distinction will become increasingly important.
PJR Registrars
Independent certification for organisations building structured and responsible AI governance.
Organisations should confirm the applicable accreditation scope and certification arrangements with the certification body before contracting for accredited certification.