[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:iso-42001-certification":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","iso-42001-certification","ISO 42001 certification: what it is, and whether it is early","ISO\u002FIEC 42001 is the AI management system standard. Here is what it asks for, how it relates to an existing ISO 27001, and an honest read of current demand.","2026-08-20",{"who":10,"when":11,"do":12},"A company asked about ISO\u002FIEC 42001, the AI management system standard: it is early, with far fewer EU tender notices naming it than ISO 27001 over the same year, and a company that already holds ISO 27001 gets the shared clauses for free and takes on the Annex A controls, the AI system impact assessment and the AI-specific records.","When a customer or a tender asks for it, not before; a company that holds nothing yet starts with ISO 27001, since it is the one customers are asking for and the second standard is less work on top of it.","Count who is asking, certify when a customer's request or a tender makes it worth the audit, and where the first standard is already in place, extend the scope, the impact assessment and the records rather than starting a second system.","\nISO\u002FIEC 42001:2023 is the management system standard for artificial intelligence, and it is early: over the 365 days to 11 August 2026 it appears in 18 EU tender notices on TED against 3,408 for ISO 27001. Certify if a customer is asking. If you already hold ISO 27001 the second standard is less work, because clauses 4 to 10 are shared and what you add is 38 Annex A controls, the AI system impact assessment in clause 6.1.4, and the AI-specific records. If you hold nothing yet, start with the standard your customers are actually asking for.\n\n## Whether it is early, measured rather than guessed\n\nIt is early, and it is worth saying so plainly. TED is the EU's own procurement portal and its search API is public, so this is checkable rather than asserted. Over the 365 days to 11 August 2026:\n\n| Standard | Tender notices |\n|---|---|\n| ISO 27001 | 3,408 |\n| SOC 2 | 104 |\n| ISO 42001 | 18 |\n\nEighteen. Nobody is currently losing public tenders for want of ISO 42001. If your reason for certifying is that a customer is asking, that is a real reason. If it is that procurement demands it, the data does not support that yet.\n\nWhat the number does not capture: private procurement, and the direction of travel around the EU AI Act. Being early on AI governance is a strategic position rather than a response to demand, and it is reasonable to take it deliberately.\n\n## What it asks for\n\nClauses 4 to 10 are the Harmonized Structure, the same skeleton as ISO 27001: context, leadership, planning, support, operation, performance evaluation, improvement. If you hold 27001, you have most of that already and the records count towards both.\n\nAnnex A is where they separate. ISO 42001's Annex A has 38 controls covering AI policy, roles, the AI system life cycle, data governance, information for interested parties, and use of AI systems.\n\nThe clause with no ISO 27001 counterpart at all is **6.1.4, the AI system impact assessment**. Where 27001 asks what could go wrong for the organisation, 42001 asks what the system does to the people it touches, and to society. That is a different question and it is the reason a 42001 audit is not a 27001 audit with extra controls.\n\n## If you already hold ISO 27001\n\nThe second standard is less work than the first, because the management system underneath is shared. What you are adding is the Annex A control set, the impact assessments, and the AI-specific records. [Our clause-by-clause coverage for 42001](\u002Fiso-42001\u002Fcoverage) states what is held and what is not.\n\n## If you hold nothing yet\n\nStart with the standard your customers are actually asking for. On the numbers above, for most companies that is still ISO 27001.\n",1789383986521]