ISO 42001: what it actually asks for, and who genuinely needs it
The AI management standard is being sold hard to organisations that do not need it yet. Here is what it asks for, and the honest threshold.
ISO 42001 is a management system standard, not a control checklist. It asks you to know which AI systems you use, to assess their impact on the people affected by them, to keep a human accountable for outputs, and to evidence that whoever oversees them is competent to do so.
If you already maintain an honest register of AI tools - what each one is for, what data it touches, who is responsible - you have done the groundwork for most of it. The parts that catch organisations out are impact assessment and competence records, because both require somebody to write down a judgement rather than run a report.
Who needs it today? Realistically: organisations where AI touches decisions about people, and where a commissioner, regulator or enterprise client has started asking. Care providers using AI in record-keeping are in that group. An eleven-person accountancy practice trialling AI bookkeeping is not, however energetic the sales approach.
Our advice has not changed: keep the register honest, do a DPIA where AI touches sensitive data, and revisit the certificate when somebody actually asks for it. Doing the useful eighty per cent costs very little. Certifying it early costs a great deal.
- ✓Start a register: every AI tool, its purpose, its data, its owner.
- ✓Do an impact assessment wherever AI affects decisions about people.
- ✓Name a human accountable for anything reaching a client or a record.
- ✓Keep evidence that the people overseeing it are competent to.
- ISO/IEC 42001:2023 - AI management systems ISO ↗
- Guidance on AI and data protection INFORMATION COMMISSIONER'S OFFICE ↗
- AI assurance techniques DSIT ↗
- Certification bodies and the 42001 market COMPUTER WEEKLY ↗
Links open each publisher’s live coverage of this topic.