🤖 AI Governance🌐 ISO 42001🎯 Applicability

Who Needs ISO 42001? Applicability Guide for AI Developers and Deployers

ISO/IEC 42001:2023 is the world’s first certifiable AI Management System (AIMS) standard — but does your organization actually need it? Applicability is role-based, not industry-based, spanning AI developers, deployers, and users alike.

CM
Chandrika Mulage
🔐 Security Engineer·📖 8 min read
📅 June 4, 2026·🏢 SecComply
Who needs ISO 42001 — applicability guide for AI developers, deployers, and users

Applicability follows your role in the AI ecosystem — developer, deployer, or user — not your industry label.

Artificial intelligence has moved from experimental side projects to core business infrastructure, and regulators, customers, and boards are now asking a pointed question: how do you govern it? ISO/IEC 42001:2023 — the world’s first certifiable AI Management System (AIMS) standard — was created to answer exactly that. But a common source of confusion remains: does your organization actually need it? This guide breaks down who ISO 42001 applies to, why the answer is broader than most teams expect, and how to decide whether certification belongs on your roadmap.

What ISO 42001 Actually Is

Published in December 2023 by ISO/IEC JTC 1/SC 42, ISO/IEC 42001 is a management system standard for artificial intelligence. Rather than prescribing how a specific model should be built, it defines how an organization should govern the AI it develops or uses across the full life cycle — from strategy and design through deployment, monitoring, and retirement.

Crucially, it is built on the Annex SL High-Level Structure (Clauses 4 through 10), the same backbone used by ISO/IEC 27001 (information security) and ISO 9001 (quality). If your organization already runs a certified management system, ISO 42001 will feel familiar: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. This shared structure means the AIMS integrates with existing systems rather than sitting awkwardly beside them.

The standard is deliberately risk-based and technology-neutral. It does not care whether you are running classic predictive machine learning, generative large language models, or emerging agentic systems. What it cares about is whether you have identified the risks those systems create, put controls in place, and can demonstrate continual improvement.

The Core Principle: Applicability Is Role-Based, Not Industry-Based

The most important thing to understand about ISO 42001 is that applicability follows your relationship to AI systems, not your sector. The standard explicitly addresses three overlapping roles:

  • AI developers — organizations that design, train, and build AI models or systems, whether for internal use or to sell.
  • AI deployers — organizations that put someone else’s AI (or their own) into operational use in a real-world context.
  • AI users — organizations and functions that consume AI outputs as part of their workflows.

Because most companies now occupy more than one of these roles simultaneously, the practical footprint of ISO 42001 is wide. A fintech that fine-tunes a foundation model (developer) to power a customer-facing chatbot (deployer) that its support team relies on (user) touches all three roles at once.

💡
KEY DISTINCTION

Applicability follows your role in the AI ecosystem — developer, deployer, or user — not your industry label. Most organizations occupy more than one role at once, which is exactly why the standard’s practical footprint is wider than most teams expect.

Who Should Seriously Consider ISO 42001

1. Companies Building or Selling AI Products

If you develop AI systems that other organizations rely on, ISO 42001 is fast becoming a commercial expectation. Enterprise procurement teams and security reviewers increasingly ask vendors to demonstrate governance maturity. A certificate provides third-party assurance that you assess impacts, manage data responsibly, and control your AI life cycle — shortening sales cycles and reducing the friction of endless bespoke security questionnaires.

For AI-native startups in particular, early certification can be a differentiator that signals seriousness to enterprise buyers and investors who are wary of governance risk.

2. Enterprises Deploying AI at Scale

Even if you never train a model, deploying third-party AI creates real accountability. When you embed a large language model into hiring, credit decisions, medical triage, or customer service, you inherit responsibility for its outputs. ISO 42001 gives deployers a structured way to run AI system impact assessments, define human oversight, and manage the third-party and customer relationships that come with buying AI from others.

3. Organizations in Regulated or High-Stakes Sectors

Financial services, healthcare, insurance, HR, and public sector bodies face heightened scrutiny when AI touches consequential decisions. Annex D of the standard specifically anticipates sector-specific application. For these organizations, an AIMS is both a risk-reduction measure and a way to evidence due diligence to regulators.

4. Companies Preparing for the EU AI Act and Global Regulation

This is where 2025-2026 context matters.

⚠️
EU AI ACT TIMELINE — STILL MOVING

The EU AI Act — a binding, risk-tiered law — began applying its prohibitions and AI-literacy requirements on 2 February 2025, with obligations for general-purpose AI models following on 2 August 2025. High-risk system obligations were originally set for 2 August 2026, though the November 2025 “Digital Omnibus” simplification package proposed deferring them to 2 December 2027; the Council gave its final green light to that direction around 29 June 2026. This remains an evolving development, so timelines should be confirmed against the latest official text.

ISO 42001 is not legally mandated by the AI Act, and the formal presumption-of-conformity route runs through harmonized EN standards being developed by CEN-CENELEC. Nonetheless, ISO 42001 is widely regarded as a practical way to operationalize and demonstrate the governance discipline the AI Act demands. Organizations that stand up an AIMS now build muscle they will need regardless of how the final deadlines settle.

Who Might Not Need It (Yet)

ISO 42001 is not mandatory anywhere, and not every organization needs certification today. If your AI footprint is minimal — say, occasional use of a consumer productivity tool with no consequential decisions attached — a full AIMS may be premature. Similarly, organizations still in early experimentation may benefit more from lightweight governance and a NIST AI Risk Management Framework-style approach (a voluntary US framework worth knowing as context) before pursuing formal certification.

ℹ️
DOCUMENT THE DECISION

“We don’t need it yet” should be a documented, revisited decision rather than a default. AI adoption tends to outpace governance, and the gap is exactly where risk accumulates.

What Implementation Actually Requires

If you conclude ISO 42001 applies to you, here is what the standard expects you to put in place:

  • An AI policy setting direction and commitments at the leadership level.
  • Defined roles and responsibilities for AI governance across the organization.
  • AI risk assessment and treatment — identifying, analyzing, and mitigating risks specific to your AI systems.
  • AI system impact assessments that consider effects on individuals, groups, and society, not just the business.
  • A Statement of Applicability (SoA) documenting which of the 38 Annex A controls apply and why.
  • Operational controls across the AI life cycle and data management.
  • Internal audit, management review, and continual improvement following the familiar Plan-Do-Check-Act (PDCA) cycle.

Annex A organizes those 38 controls under nine control objectives (A.2–A.10): AI policy, internal organization, resources for AI systems, impact assessments, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Annex B provides implementation guidance, Annex C catalogs risk sources and objectives, and Annex D addresses sector-specific use.

The Path to Certification

ISO 42001 certification is achieved through a two-stage external audit by an accredited certification body:

  • Stage 1 reviews your documentation and readiness — is the management system designed and in place?
  • Stage 2 evaluates operational effectiveness — is the system actually working as documented?

A successful audit results in a certificate valid for three years, with annual surveillance audits to confirm the system remains effective. Accredited certification bodies now active in this space include Schellman (the first ANAB-accredited body for the standard), BSI, DNV, A-LIGN, and SGS.

Bottom Line

If your organization builds, deploys, or meaningfully depends on AI — and especially if it does more than one of those — ISO 42001 is relevant to you. Applicability is defined by your role in the AI ecosystem, not your industry label. The standard scales: a small startup can implement a proportionate AIMS, while a global enterprise can integrate it into an existing ISO 27001 or 9001 program. With the EU AI Act’s obligations tightening and enterprise buyers demanding assurance, standing up an AI management system is quickly shifting from a nice-to-have to a baseline expectation.

Key Takeaways

💡
KEY TAKEAWAYS
  • ISO/IEC 42001:2023 is the first certifiable AI management system standard, applicable to developers, deployers, and users of AI.
  • Applicability is role-based, not sector-based — most organizations occupy several roles at once.
  • It is technology-neutral, covering predictive ML, generative AI, and agentic systems alike.
  • Certification involves a two-stage audit, a three-year certificate, and annual surveillance.
  • While not legally required, it is widely used to operationalize EU AI Act readiness amid shifting 2026-2027 deadlines.

Ready to Build Your AI Governance Framework?

SecComply’s compliance team helps organizations determine ISO 42001 applicability and stand up a certification-ready AI Management System — from role mapping and impact assessments to Stage 1 and Stage 2 audits.

Frequently Asked Questions

Is ISO 42001 mandatory?

No. ISO 42001 is a voluntary, certifiable standard. It is not legally mandated by any current regulation, including the EU AI Act, though it is widely adopted to demonstrate responsible AI governance and support regulatory readiness.

Do we need ISO 42001 if we only use third-party AI tools?

Potentially, yes. Deployers and users of AI fall within scope. If you embed third-party AI into consequential decisions or workflows, you inherit accountability, and the standard helps you manage impact assessments, human oversight, and vendor relationships.

How long does ISO 42001 certification take?

Timelines vary with organizational size and AI maturity, but the process involves building the management system, then passing a two-stage external audit. The resulting certificate is valid for three years with annual surveillance audits.

How does ISO 42001 relate to ISO 27001?

Both share the Annex SL High-Level Structure, so an AIMS integrates cleanly with an existing information security management system. Organizations already certified to ISO 27001 typically find implementation faster because governance foundations are already in place.

This article is general information and does not constitute legal advice; consult qualified professionals for guidance on your specific circumstances.