AI & Governance 28 June 2026 2 min read

What Is ISO/IEC 42001? The New AI Management System Standard

ISO/IEC 42001 is the first international standard for AI management systems. Here's what it covers, who needs it, and how XGRC® is preparing.

What Is ISO/IEC 42001? The New AI Management System Standard

Every major information security programme today references ISO 27001. Very few organisations have an equivalent answer for AI. ISO/IEC 42001 was published to close that gap — the first international standard specifically for managing AI within an organisation, rather than treating it as an unmanaged add-on to existing systems.

What Is ISO/IEC 42001?

ISO/IEC 42001 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It covers AI risk assessment, data governance, transparency, human oversight, and continual improvement — applied specifically to how an organisation designs, deploys and monitors AI systems, rather than general IT governance.

Why It Exists

AI adoption has moved faster than governance in most organisations. Tools are deployed departmentally, data boundaries are unclear, and accountability for AI-driven decisions is often undefined. ISO/IEC 42001 gives organisations a structured framework to close that gap — the same role ISO 27001 plays for information security, or ISO 9001 for quality management.

Who Needs ISO/IEC 42001

Organisations building or embedding AI capability into governance, risk, compliance, or other sensitive business functions are the clearest candidates — anywhere AI-driven decisions carry regulatory, financial, or reputational consequences if oversight fails. It is particularly relevant to software vendors embedding AI into products used for governance and compliance, where customers will reasonably expect evidence of AI oversight as part of procurement due diligence.

What ISO/IEC 42001 Requires

At a structural level, it mirrors other ISO management-system standards: documented AI policies, risk assessment specific to AI use cases, defined roles and accountability, human oversight mechanisms, and a continual improvement cycle — plus AI-specific requirements around data quality, transparency of AI-driven outputs, and impact assessment.

How XGRC® Is Preparing

XGRC® is targeting ISO/IEC 42001 certification for September 2026. MAIA®, XGRC®'s governed AI for GRC, is already built around the principles the standard requires — permission alignment, a complete AI interaction audit trail, explainable outputs, and controlled, audited AI integrations — ahead of formal certification.

ISO/IEC 42001 will do for AI governance what ISO 27001 did for information security: turn an assumed good practice into a demonstrable, auditable standard. Organisations evaluating AI-enabled governance tools should be asking vendors where they stand against it now, not after certification becomes the market expectation.

Is ISO/IEC 42001 mandatory?

No, it's a voluntary international standard, though it is likely to become a procurement expectation for AI-enabled software in the same way ISO 27001 has for information security.

Is XGRC® certified to ISO/IEC 42001 yet?

Not yet — certification is targeted for September 2026. MAIA® is already built around the standard's core principles ahead of that milestone.

How does ISO/IEC 42001 relate to ISO 27001?

They're complementary — ISO 27001 covers information security management broadly, while ISO/IEC 42001 addresses AI-specific governance, risk and oversight requirements.

Take the next step

Ready to strengthen your AI & Governance programme?

See how XGRC® gives your team the visibility, accountability, and control it needs — without the spreadsheet chaos.