ISO 42001

Management-system discipline for AI: applies when models make decisions you answer for.

Conditional standard · ISO/IEC 42001:2023, Artificial intelligence management systems

Issued by

ISO/IEC

Region

International

Effective

First edition, December 2023

Oversight

Certifiable; accreditation schemes still maturing

Applies when

You develop or deploy AI systems whose behaviour you must govern

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

ISO 42001 does for AI what 27001 did for security: it defines a management system, with policy, roles, impact assessment and lifecycle controls, for organisations that build or use AI.

For financial institutions it lands with unusual force: the CBN's automated-AML baseline demands governed, explainable, demonstrably effective models, and 42001 is the international standard closest to that shape. If AI touches your regulated decisions, this is the discipline that makes it defensible.

Where programmes are tested.

01

AI governance

Policy, accountability and competence for the AI you build or buy.

02

Impact assessment

Understanding what a system can do to the people it affects, before and during deployment.

03

Lifecycle controls

Data, development, validation, deployment and monitoring, managed and evidenced end to end.

Curated once, evidenced continuously.

  • 42001 requirements are curated and cross-mapped to the Model Governance module: inventory, independent validation and change control on one register.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

ISO 42001, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who needs ISO 42001?

Organisations that develop, provide or use AI systems whose behaviour they must answer for. It is conditional by nature: if models influence decisions about customers, money or risk, the management-system discipline applies; if you run no AI, it does not.

Does ISO 42001 apply if we only use third-party AI?

Yes. The standard covers use as well as development: an AI system you bought is still an AI system you deploy, and the impact assessment, oversight and supplier controls remain your responsibility, the same logic Nigerian regulation applies to vendor-built AML models.

How does ISO 42001 relate to the CBN automated-AML baseline?

They share a shape: inventory, ownership, independent validation, change control and monitoring. The CBN baseline is the supervisory mandate for AML systems; 42001 is the certifiable international wrapper, which is why the two are cross-mapped in the catalog.

Is ISO 42001 certification available today?

Yes, certification bodies offer it, though accreditation schemes are still maturing. Early adopters mostly certify to demonstrate governance maturity to enterprise buyers and regulators ahead of AI-specific regulation landing.

Where it connects.

The full catalog

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.