Every major information security programme today references ISO 27001. Very few organisations have an equivalent answer for AI. ISO/IEC 42001 was published to close that gap — the first international standard specifically for managing AI within an organisation, rather than treating it as an unmanaged add-on to existing systems.
What Is ISO/IEC 42001?
ISO/IEC 42001 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It covers AI risk assessment, data governance, transparency, human oversight, and continual improvement — applied specifically to how an organisation designs, deploys and monitors AI systems, rather than general IT governance.
Why It Exists
AI adoption has moved faster than governance in most organisations. Tools are deployed departmentally, data boundaries are unclear, and accountability for AI-driven decisions is often undefined. ISO/IEC 42001 gives organisations a structured framework to close that gap — the same role ISO 27001 plays for information security, or ISO 9001 for quality management.
Who Needs ISO/IEC 42001
Organisations building or embedding AI capability into governance, risk, compliance, or other sensitive business functions are the clearest candidates — anywhere AI-driven decisions carry regulatory, financial, or reputational consequences if oversight fails. It is particularly relevant to software vendors embedding AI into products used for governance and compliance, where customers will reasonably expect evidence of AI oversight as part of procurement due diligence.
What ISO/IEC 42001 Requires
At a structural level, it mirrors other ISO management-system standards: documented AI policies, risk assessment specific to AI use cases, defined roles and accountability, human oversight mechanisms, and a continual improvement cycle — plus AI-specific requirements around data quality, transparency of AI-driven outputs, and impact assessment.
How XGRC® Is Preparing
XGRC® is targeting ISO/IEC 42001 certification for September 2026. MAIA®, XGRC®'s governed AI for GRC, is already built around the principles the standard requires — permission alignment, a complete AI interaction audit trail, explainable outputs, and controlled, audited AI integrations — ahead of formal certification.
ISO/IEC 42001 will do for AI governance what ISO 27001 did for information security: turn an assumed good practice into a demonstrable, auditable standard. Organisations evaluating AI-enabled governance tools should be asking vendors where they stand against it now, not after certification becomes the market expectation.