ISO/IEC 42001 is a voluntary standard — until it isn’t. Under Article 6 of the EU AI Act, high-risk AI systems now require mandatory conformity assessment, and ISO 42001 is fast becoming the standard organizations turn to in order to prove it. Below, I explain what “required” actually means in ISO language, how the Act’s four AI risk tiers determine whether your AI system needs certification, who will be authorized to issue that AI certification once ISO/IEC 42006 is finalized, and the steps to start your own certification journey.
What is ISO/IEC 42001:2023 AI Management System?
ISO/IEC 42001 is a new international standard published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023. It is a voluntary standard. It is also an auditable and certifiable one, meaning that if you choose to implement or adopt it, someone from outside your organization, usually called a certification body (CB), can come in to assess whether your AI system meets the standard’s controls.
Why AI certification matters
If a third party can attest that your AI system conforms to a set of principles agreed upon by industry peers and experts, expressed in the form of an international standard, that’s good news for you. It sends a positive message about your AI system, your management practices, your responsible approach, and your overall AI culture. More importantly, it helps your team develop responsible practices that, over time, enhance stakeholder trust, reduce legal exposure, and shield your products and services from risks inherent to ML technology.
What does “required” actually mean?
As I said, the standard is voluntary. But if you choose to implement it, you have to conform to every control it lists. In ISO language, a “required” standard requires a third-party assessment to determine whether the controls required by 42001 are present in your organization. This is different from a non-required standard, called a technical report, which is simply a set of guideline practices you may or may not choose to implement.
The EU AI Act: a new legal requirement
The EU AI Act has introduced a new certification requirement for certain AI systems. While certification in general is driven primarily by market forces, in the EU, for certain AI systems, it is now a legal one. The Act classifies AI systems into four categories:
- Unacceptable risk. Systems that cross certain risk thresholds are simply prohibited. Because they violate fundamental human rights and go against basic EU values, these systems cannot be developed. Examples include social credit scoring systems, systems that use biometric identification such as facial recognition, and systems known in law enforcement as predictive policing. These systems are illegal under Article 5 of the Act.
- High-risk AI systems. Systems that present a higher risk of harm must be assessed to confirm that developers and users have evaluated their risk of harm. Examples include systems used to make decisions about access to education and employment, such as HR decisions. There is agreement among experts that most AI systems used in business functions such as HR, finance, and marketing, as well as systems used in industries such as public safety and law enforcement, fall under the high-risk category. Certification for these systems is required by law (Article 6 of the Act).
- Limited risk. AI systems with a limited harmful impact on EU citizens’ rights and safety do not require conformity assessment. Providers and users of these systems need to make sure their systems follow transparency requirements.
- Minimal risk. AI systems with minimal risk are subject to industry protocols. This category includes every AI system not covered by the first two categories above.
Practically speaking, you are required to conduct a conformity assessment for high-risk AI systems. That category includes AI applications used in HR, accounting, finance, customer service, IT support, and legal functions. Even for AI with limited risk (categories 3 and 4), certification is worth considering: it isn’t legally required, but it’s a strong signal of transparency and trustworthiness.
Who can certify your organization?
The first thing to know is that ISO/IEC is currently developing another standard that will clarify who can conduct certification, and how: ISO/IEC 42006, Requirements for Bodies Providing Audit and Certification of Artificial Intelligence Management Systems. This standard, still under development, will define the certification process and clarify the conditions under which an AI system can be audited. It will most likely address who can certify AI systems, the knowledge and skills required of those conducting certification, and the rules and processes under which a certificate can be issued. Traditionally, for other required ISO standards, such as ISO 9001 (quality management), ISO 45001 (occupational health and safety), and ISO/IEC 27001 (cybersecurity), established certification bodies have dominated the market. For AI, that will most likely change as more consulting companies enter the certification space.
How do you certify your company?
Before answering that, it’s worth noting that outside of ISO/IEC, many national and regional organizations are developing their own standards. In the U.S., the National Institute of Standards and Technology has published the NIST AI Risk Management Framework 1.0. In Europe, to address the EU AI Act’s requirements, two organizations, the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), are developing companion standards. There is significant coordination between ISO/IEC and CEN-CENELEC to define a common certification process, so if you start with 42001, you should be well positioned to meet future European requirements too.
If you want to start certifying your organization, here are four steps I suggest:
- Appoint a team to lead the certification process. Most organizations start by appointing a compliance officer and an audit officer, but I’d suggest going further: appoint a cross-functional team as diverse as possible. AI is not an IT issue, and it isn’t purely a business issue either. It’s an everything issue that goes beyond traditional organizational boundaries.
- Run an inventory of your current ML systems. This is a critical step. You need to know where the risks are. Some may come from your own AI applications, but others may come from vendor applications, and as a user, you carry legal exposure for those too. Ideally, your vendor selection process already surfaced these risks; if not, this is the place to start. Your AI procurement contracts should identify foreseeable risks to safety and fundamental rights, and ways to mitigate them.
- Engage your senior leadership. Without leadership support, the certification process stalls. AI certification is new and complex for everyone, because the technology itself is complex. Very few organizations meet every requirement out of the gate, so you’ll need early, sustained commitment from senior leadership on issues beyond your immediate control.
- Adopt responsible AI practices. Explainability, fairness, nondiscriminatory treatment, robustness, transparency, privacy protection, and accountability are widely accepted responsible AI practices. Use the certification process as an opportunity to embed these principles into your AI management practices, and to show your data scientists the long-term ROI of building this way.
A concluding thought
ISO/IEC 42001 is a new standard, and many organizations will rush into certification just to check the box. I’d suggest taking the time to build the foundations of a sound AI governance system instead. Buy the standard and read the requirements yourself. Work with certification bodies, or with those who prepare you for certification, to help your team understand the complexity of AI governance. Engage with it seriously, and build a strong foundation. The certification process is just the beginning.
