Voluntary standard · source: ISO

ISO 42001 is not law: is it still worth it for me?

In short: often yes, but as infrastructure, not as an obligation. ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS): voluntary and certifiable. For an SME its real value is readiness for the AI Act — it builds the governance backbone that the Regulation requires anyway. But adopting it is not equivalent to being compliant with the AI Act. Below are the facts from the ISO catalogue, then our reading.

The facts · fields 1–10

What the official source says.

Verified on the ISO catalogue

01 · Name

ISO/IEC 42001:2023 — AI Management System

«Information technology — Artificial intelligence — Management system». Common abbreviation: ISO 42001. It defines an AI Management System (AIMS). It is the world's first international standard dedicated to an AI management system. The official title is in English; ISO does not publish an official Italian translation of the text (any national UNI/CEI adoption is ⚠️ [to verify]).

ISO · official catalogue 42001

02 · Type of source

Technical international standard (ISO/IEC)

Published jointly by ISO and IEC, developed by the technical committee ISO/IEC JTC 1/SC 42 (Artificial intelligence). It is not a legislative act: it is a technical standard adopted on a voluntary basis.

ISO · catalogue 42001 (committee JTC 1/SC 42)

03 · Nature

Voluntary (technical soft law) and certifiable

Adoption is not imposed by law; however, an organisation can obtain a certification of conformity issued by an accredited certification body (third-party audit). It adopts the Harmonized Structure (Annex SL) — the high-level structure common to ISO management-system standards (e.g. ISO/IEC 27001, ISO 9001), built on the PDCA (Plan-Do-Check-Act) cycle of continual improvement.

ISO/IEC Directives Part 1, Annex SL · ISO catalogue 42001

04 · Subject matter

Organisational AI governance

It specifies the requirements to establish, implement, maintain and continually improve an AIMS. It provides a structured approach to govern the risks and opportunities associated with the development, provision and use of AI systems (policies, roles, risk and impact assessment, controls, oversight, improvement). It does not address the technical merits of the individual application, but its organisational governance.

ISO · official catalogue 42001

05 · Who it applies to

Every organisation, by choice

To every organisation, of any size and sector, that provides or uses AI-based products or services (public or private, for-profit or non-profit). Independent of the type of system (predictive ML, generative AI, agentic systems). Adoption is a choice of the organisation, not a personal-scope obligation defined by law.

ISO · official catalogue 42001

06 · Key dates

First edition, December 2023

  1. Publication of the first edition (Edition 1) of the standard.

The exact day of publication and the document's page count: ⚠️ [to verify] on the ISO catalogue (the full text is paywalled; the catalogue record confirms year 2023 and edition 1).

ISO · catalogue 42001 (2023 edition)

07 · Authorities / bodies

No public authority

ISO and IEC are private, non-governmental standardisation bodies; they do not supervise or impose penalties. Conformity is attested — on a voluntary basis — by accredited certification bodies under the national accreditation bodies (in Italy: ACCREDIA⚠️ [to verify] the existence of accreditation schemes specific to ISO/IEC 42001). A certification body is not a public authority and certification is not an administrative act.

ISO · nature of ISO/IEC as standardisation bodies

08 · Status

In force / published (first edition, 2023)

An active and certifiable standard. It constitutes the current international reference for AI management systems. Any subsequent editions or technical corrigenda: ⚠️ [to verify] on the ISO catalogue as at the date of consultation.

ISO · official catalogue 42001

09 · Relationship with other rules

Readiness framework towards the AI Act; integrable via Annex SL

  • ↔ AI Act (Reg. EU 2024/1689): ISO/IEC 42001 is not law and does not in itself confer compliance with the AI Act. Adopting a conforming AIMS is, however, a readiness framework: it structures the internal governance (risk management, documentation, human oversight, roles) that the AI Act requires, making it easier to demonstrate compliance.
  • ↔ ISO/IEC 27001 and ISO 9001: it shares the Harmonized Structure (Annex SL), so it is integrable with management systems already in place without duplicating the documentation framework.
  • ↔ GDPR (Reg. EU 2016/679): the AIMS can incorporate safeguards useful for the processing of personal data, but it does not replace GDPR obligations.

ISO · catalogue 42001 (Harmonized Structure / relationship with ISO MSS)

10 · Official source

ISO catalogue — paywalled text

Primary source to cite: the official ISO catalogue. Transparency note: the full text of the standard is paywalled; NomotecnIA's verification is limited to the data in the official catalogue record (name, edition, year, committee, scope). The individual clauses/controls (Annex A, specific requirements) are not verifiable free of charge against the primary source and are not reproduced here.

Open the official source on ISO

Primary source · ISO (official catalogue)

NomotecnIA reading · interpretation, not a source

Fields 11–12 · our own synthesis

Our reading for an SME.

Synthesis

  • ISO/IEC 42001 is voluntary: no SME is obliged to adopt it. The question is not «must I?» but «is it worth it as a governance infrastructure?».
  • Its real value for an Italian SME is readiness for the AI Act: it builds the backbone (AI policy, roles, risk assessment, documentation, oversight) that the European Regulation requires anyway. Doing 42001 is not equivalent to being compliant with the AI Act, but it gets you there in an orderly way.
  • The major practical advantage is integration via Annex SL: those who already have ISO 27001 or 9001 reuse the structure, audits and documentation culture, reducing the marginal cost.
  • Certification is a commercial and reputational asset, but it is optional: you can adopt the standard as an internal framework without getting certified.
  • Mind the boundary: certification is issued only by an accredited body, not by a consultant. Be wary of anyone promising «ISO 42001 certification» as a consultancy service.

Practical obligations for an SME

These are not legal obligations, but the operational steps to adopt the AIMS.

  1. Define the scope: which AI systems/processes fall within the AIMS.
  2. Policy and roles: adopt an AI policy and assign clear responsibilities.
  3. Risk and impact assessment: map the risks and impacts of the AI systems used or provided, with documented mitigation measures.
  4. Operational controls and human oversight: safeguard the systems with controls, logs and human supervision.
  5. PDCA cycle: internal audits, management review, documented continual-improvement actions.
  6. (Optional) Certification: if the attestation is needed, turn to an accredited certification body (not to NomotecnIA).

Positioning note (NomotecnIA): NomotecnIA can support readiness towards ISO/IEC 42001 (gap analysis, documentation framework, audit preparation), but it is not a certification body and does not issue ISO/IEC 42001 certification: that is issued exclusively by an independent accredited body.

In depth

The articles that cite this standard.

Editorial watch · dated

Meta · fields 13–15

Review, disclaimer, changelog, author and sources

Last updated · 2026-07-10

Disclaimer

This content is provided for information and general guidance purposes only; it does not constitute legal or technical advice or an attestation of compliance. The full text of the standard is protected by ISO/IEC copyright and is available only for a fee: for any assessment, the official ISO source prevails. NomotecnIA is not a certification body and does not issue ISO/IEC 42001 certifications.

  • #ISO42001
  • #AIMS
  • #AIManagementSystem
  • #VoluntaryStandard
  • #Certification
  • #AnnexSL
  • #PDCA
  • #Readiness
  • #AIAct
  • #Governance
  • #SME

Changelog

Revision history

  1. 2026-07-06

    First publication — research verified against the official source and editorial review (CCO).

  2. 2026-07-10

    Editorial enrichment — added In-depth section, accredited author and list of sources.

Author

Matteo Colacchio

CEO · AI Governance, NomotecnIA

Author profile →

LinkedIn: to be linked

Official sources

Where we verified

  • Official ISO catalogue — ISO/IEC 42001:2023: iso.org/standard/42001primary source (catalogue record).
  • Official preview (contents / scope) — ISO Online Browsing Platform: iso.org/obp (std 81230).
  • Note: the full text of the standard is paywalled; the data above derive from the official catalogue record (see field 10 — Transparency note).

Official source · ISO

From the rule to your company

Is ISO 42001 right for your SME?

The AI Entry Assessment evaluates whether the AIMS is worthwhile for your organisation and how to integrate it with the AI Act and the GDPR: gap analysis, documentation framework, audit preparation — without duplicating the work.