ISO/IEC 42001 Certification: AI Management System
- Other sectors
- Healthcare and Medical Devices
- Automotive, Aerospace and Rail
- Food and beverage
- Maritime
- Finance
- Government
- Energy
Strengthen process governance and build trust in how AI solutions are developed, implemented and used across your organization
Journey continues on Veracity, DNV's trusted digital platform.
ISO/IEC 42001 Certification: AI Management System
Certification of your artificial intelligence management system to ISO/IEC 42001 demonstrates your commitment to safe, responsible and ethical implementation, development and use of AI. It provides best-practices for your organization to establish structured process governance to manage risks, strengthen oversight and meet regulatory expectations. This helps build confidence among customers, regulators and other stakeholders as to how you are managing your AI solutions.
The ISO/IEC 42001 standard defines specific requirements for an AI management system that covers the entire lifecycle of AI solutions. It enhances your ability to apply process governance to ensure that AI solutions are safe, reliable and ethical while also meeting requirements in global and national regulations and recognised frameworks.
What is the ISO/IEC 42001 standard?
Applicable to all types of companies in any industry, ISO/IEC 42001 is the first international and certifiable management system standard for artificial intelligence management systems. It provides a framework to establish, implement, maintain and improve an AI management system that applies process governance to the development, implementation and use of AI solutions to ensure that these are safe, reliable and ethical.
ISO/IEC 42001 helps you achieve:
- Establish structured governance for AI activities
- Identify and manage risks across the AI solution lifecycle
- Demonstrate that governance is applied to ensure
safe, reliable and ethical AI solutions - Strengthen oversight and reduce uncertainty in AI adoption
- Align with regulatory expectations and recognised frameworks
- Build trust with customers, regulators and other stakeholders
- Support responsible and well governed development, implementation and use of AI
- Integrate AI governance with existing management systems
ISO/IEC 42001 promotes a risk based approach to process governance of AI systems from implementation to development and use. It is built on ISO’s Harmonized Structure (HS), ensuring a consistent approach and smoother integration with management systems compliant with other ISO standards, such as ISO 9001 and ISO/IEC 27001.
Value of ISO/IEC 42001 certification
Certification to ISO/IEC 42001 by an independent third-party like DNV demonstrates that your artificial intelligence management system meets the requirements of the standard and that you have best-practice process governance in place to ensure that AI solutions are developed, implemented and use in a responsible and trustworthy way.
As a result, you get:
- Increased trust in how AI is developed, implemented and used
- Objective insights from external auditors to identify gaps and improvement opportunities
- Stronger process governance across your AI solutions to manage risk at the right level
- Greater confidence from customers, regulators and other stakeholders
Improved readiness for regulatory expectations and recognised framework
Customers
Certificates
People trained annually
Countries
How to get ISO/IEC 42001 certified
To be certified, you first need to implement an effective AI management system complying with the standard’s requirements. DNV is an accredited third-party certification body and can help you throughout the journey starting from relevant ISO/IEC 42001 or ISO/IEC 27001 information security management system training to self-assessments, gap analysis and certification services..
As a DNV customer, you also get access to a suite of digital tools that can help you ensure compliance, continually improve and manage your entire certification journey with us.
Learn how to get started and be certified
-
-
Obtain the standard:
Get a licensed copy of the relevant standard and familiarize yourself with the requirements to decide if certification/registration to this standard makes good sense for your organization.
-
Review available literature and apply digital tools
Explore available literature, guidelines from the standard owners (e.g. ISO/TS 9002 for ISO 9001, ISO 14004 for ISO 14001) and digital sources and tools that can assist with implementation. Note that as a DNV customer you get access to tailored tools that can assist you.
-
-
-
Assemble a team and define strategy:
To implement a management system should be a strategic decision for the entire organization. Senior management must be involved in the decision, committed and involved in shaping the system. They decide the business strategy the management system should support. In addition, you need a dedicated team to develop and implement your management system.
-
Determine competence needs:
First, your team implementing and maintaining the management system needs a thorough understanding of the chosen standards. Later on, the wider organization needs awareness training. DNV offers a variety of public and in-house courses worldwide that meets your competence training needs at all levels within your organization.
-
-
-
Review consultant options:
Independent consultants can advise on a workable, realistic, and cost-effective strategy plan for implementation if you do not have this competence or capacity already.
-
Develop management system documentation:
Decide on an appropriate platform for your documented information (e.g. software, process map- or SharePoint-based). The right platform is important to ensure effective management, communication and implementation.
-
-
-
Determine, manage and document processes:
First identify key processes – what they are, how they work, and how they interact. Each process should have a clear purpose, defined responsibilities, and expected outputs. The level of documented information needed depends on the organization’s size, complexity, and the importance of each process, but must include relevant processes and other documented information needed to deliver on intended outcomes and comply with the chosen standard’s requirements.
-
Implement management system:
Clear communication and necessary competence training are essential elements. During the implementation phase, you will work to ensure that your organization is working according to defined and documented processes. Once successful, you can prove system’s compliance and effectiveness.
-
-
-
Select a certification body/registrar:
Selecting the right certification body/registrar can make a difference throughout your certification journey. DNV offers a trusted partnership approach, a risk-based approach and range of free digital tools that help you manage your certification journey before, during and after the audit.
-
Consider a pre-audit gap analysis:
Consider a preliminary evaluation by your certification body/registrar to identify and correct nonconformities before starting the official certification process. The purpose is to identify areas of non-conformance or weaknesses, allowing you to correct these before you begin the official certification process.
-
ISO/IEC 42001 - FAQ
-
To achieve certification to ISO 42001 or ISO/IEC 42001 – which is the standard’s formal name – an organization must establish, implement and maintain an Artificial Intelligence Management System (AIMS) that meets the requirements of the standard. This includes defining the scope of AI activities, identifying risks and controls across the AI lifecycle, implementing governance processes, conducting internal audits and completing a management review before the certification audit.
-
An Artificial Intelligence Management System (AIMS) is a structured approach to process governance as outlined by the requirements in the ISO/IEC 42001 standard. It defines the policies, processes and controls an organization uses to govern processes related to development, implementation and use of AI solutions. The intent is to ensure safe, reliable and ethical AI solution. The AIMS supports this as it helps organizations manage risks to match the AI solution, improves transparency and strengthens trust.
-
AI laws vary significantly across regions with regulations placing different emphasis on risk management, transparency, safety or ethics, or sector specific requirements. This creates complexity for organizations, especially those operating internationally. ISO/IEC 42001 provides a globally recognised governance framework that aligns with leading regulatory and best practice approaches, helping organizations implement process governance on safety, reliability and ethical aspects of their AI solutions.
-
Most organizations are adopting Artificial Intelligence solutions to improve efficiency, decision making and innovation. Many companies face uncertainty around governance, risk management and regulatory expectations. While some companies have already implemented a structured approach to process governance, others are just recognising the need for clearer process governance, transparency and trust. As adoption of AI solutions accelerates, more organizations can benefit from certifiable frameworks like ISO/IEC 42001 to strengthen process governance and build trust in how AI is developed, implemented and used.
ISO/IEC 42001 training
You may also find interesting
ISO/IEC 42001: Artificial Intelligence Management
Guide on ISO/IEC 42001 certification for AIMS, covering governance in AI and steps to achieve certification through three key articles.
Dangers of artificial intelligence: risk management strategies
Adopting an AI Management System (AIMS) can help companies continually manage and mitigate risks. Read more.
More information
Training
Relevant insight in an active learning environment.
You added value
Find out more on the digital customer experience.