AIWiki
Malaysia
Back to all articles
Ethics & PolicyAI governancestandardscompliance

ISO/IEC 42001

4 min readUpdated September 2026
ISO/IEC 42001
Type
International management-system standard
Full title
Information technology — Artificial intelligence — Management system
Published
18 December 2023 (first edition)
Developed by
ISO/IEC JTC 1, Subcommittee 42 (SC 42)
Structure
Requirements in clauses 4–10; Annex A reference controls grouped under nine objectives
Certification
Voluntary; granted by independent certification bodies
Related
ISO/IEC 27001, EU AI Act, PDPA, responsible AI
ISO/IEC 42001:2023, titled Information technology — Artificial intelligence — Management system, is the first international standard that defines requirements for an artificial intelligence management system (AIMS). Published in December 2023, it provides organisations with a framework for governing how AI systems are developed, provided and used, and it is certifiable by independent bodies.[1][2]

Background

As AI adoption spread through the 2010s and 2020s, organisations faced a gap: existing management standards covered information security (ISO/IEC 27001) and quality, but not the specific risks of AI systems — including bias, opacity, safety, data provenance and rapid technological change. ISO/IEC JTC 1/SC 42, the joint ISO and IEC committee for AI standards, developed ISO/IEC 42001 to fill that gap, and the standard was published on 18 December 2023.[1][2]

Unlike technology specifications, ISO/IEC 42001 is a management-system standard: it defines processes, responsibilities and controls rather than mandating particular algorithms or tools, so it can apply to developers, providers and users of AI, including organisations that only procure third-party AI systems.[2]

Key Concepts

ISO/IEC 42001 follows the harmonised structure shared by other ISO management-system standards, with requirements on organisational context, leadership, planning, support, operation, performance evaluation and improvement. That structure allows organisations to integrate it with existing systems such as ISO/IEC 27001.[2]

Its AI-specific requirements are set out in Annex A, a set of 38 reference controls organised under nine objectives: policies related to AI; internal organisation; resources for AI systems; impact assessment; the AI system life cycle; data governance; information for interested parties; responsible use; and third-party relationships. Organisations select the controls that apply to them through a Statement of Applicability and justify any exclusions, and Annex B provides implementation guidance for each control.[7]

Certification is voluntary and is performed by independent certification bodies, often accredited by national accreditation bodies; ISO itself does not certify organisations. ISO notes that the standard complements rather than replaces laws and regulations, helping organisations meet obligations on documentation, risk management, monitoring and transparency more effectively.[2]

Applications and Impact

The standard is used across sectors — technology, finance, healthcare, manufacturing and the public sector — and by organisations of all sizes. Cloud providers have pursued certification for their AI services: Microsoft obtained ISO/IEC 42001 certification covering a range of AI services, and AWS documents its certification for AI services on AWS.[3][4]

Certification is increasingly treated as a way for suppliers to demonstrate AI governance to regulators, enterprise customers and auditors, and a supporting industry of training, auditing and practitioner certification has grown around the standard since 2024. ISO notes that the standard sits within a growing family of AI standards covering concepts, terminology, risk management and governance, developed by the same joint committee.[2]

>See Also

References

🇲🇾Malaysian Context

🇲🇾 Malaysia added ISO/IEC 42001 certification to its national quality infrastructure in November 2025, when SIRIM Berhad introduced an AI Management System Certification at its annual industry event. The launch was officiated by Deputy Prime Minister Datuk Amar Haji Fadillah Haji Yusof, who linked it to the Ekonomi MADANI framework and the 13th Malaysia Plan and cited an RM8 billion allocation supporting Malaysia's aspiration to become an AI Nation by 2030. SIRIM QAS International offers the certification service, and SIRIM Academy runs training on the standard.[5][6]

For Malaysian organisations, the standard complements existing obligations such as the Personal Data Protection Act, the national AI governance framework and Bank Negara Malaysia's technology risk management guidelines for financial institutions, and can be mapped against the responsible-AI initiatives of the National AI Office.[5]

References

  1. ISO. ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. https://www.iso.org/standard/42001
  2. ISO. ISO/IEC 42001 explained. https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html
  3. Microsoft. ISO/IEC 42001:2023 artificial intelligence management system. https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-42001
  4. AWS. ISO 42001 artificial intelligence management system — FAQs. https://aws.amazon.com/compliance/iso-42001-faqs/
  5. SIRIM Berhad. (2025). SIRIM introduces new AI and innovation management certifications. https://www.sirim.my/Pages/AI-InnoCert2025.aspx
  6. SIRIM QAS International. Artificial intelligence management system certification. https://www.sirim-qas.com.my/service/artificial-intelligence-management-system/
  7. Schellman. ISO 42001 roles and responsibilities: Annex A — 38 controls across nine domains. https://www.schellman.com/blog/ai-governance/iso-42001-roles-and-responsibilities