AI governance is becoming a customer requirement, not just an internal policy.
Customers, insurers, boards and legal teams now ask for evidence that AI systems are managed responsibly. Deploying AI created a governance obligation nobody signed up for — and ISO/IEC 42001 is the structured answer to it.
30 minutes, no prep. You’ll leave knowing which of the eight ISO 42001 requirements you already satisfy.
The first international standard for governing AI.
ISO/IEC 42001:2023 specifies the requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System, or AIMS. It applies whether you develop AI, provide it, or simply use it. The easiest way to place it:
The standard is concerned with organizational management, accountability, risk management, oversight and continual improvement — not the technical accuracy of any individual model. If you’ve implemented an ISO management system before, the machinery will feel familiar. If you haven’t, the concept is the thing to get right first: this is a system you operate, not a document you produce.
This one is certifiable.
That’s the practical difference between the two AI frameworks people compare, and it changes what you’re actually signing up for.
- Status
- Voluntary framework, no certification exists
- Shape
- Four functions: GOVERN, MAP, MEASURE, MANAGE
- What you end up with
- A structured risk management approach
- How you prove it
- Your own evidence, shown to whoever asks
- Best when
- You are starting out and need structure fast
- Status
- International standard, audited and certified by an accredited body
- Shape
- A management system (AIMS) with the usual ISO machinery
- What you end up with
- An auditable system, and a certificate if you pursue one
- How you prove it
- A certificate a customer can verify independently
- Best when
- Customers are asking for something they can check
We’re not a certification body. We help you prepare: building the governance processes, assigning ownership, organizing evidence and reviewing readiness before an external audit.
Formal certification is performed by an accredited certification body. Same posture we take on CMMC and SOC 2, and for the same reason: a firm that builds your management system and then certifies it is marking its own homework.
What an AIMS actually requires.
The standard asks for considerably more than a document. Eight elements carry most of the weight.
“We’ll write an AI policy and we’re most of the way there.”
The policy is one of eight requirements, and the smallest of them.
AI policy
Documented commitments governing how AI is used across the organization.
Roles and responsibilities
Clear accountability for AI decision-making and oversight. A named person, not a committee.
AI risk assessment
Identifying and evaluating AI-related risks, per system rather than in general.
AI risk treatment
Deciding how each identified risk is addressed, and recording the decision.
Impact assessments
Evaluating effects on individuals, groups and society, not only on your organization. This is what makes 42001 different from a security standard.
AI inventory
Identifying your AI systems and documenting the role you play for each one.
Monitoring and evaluation
Reviewing whether the governance processes and controls are actually working.
Continual improvement
Updating the system as AI, risks and regulation move underneath you.
Not a policy project. A management system.
This is the concept that decides whether your program survives its first year. A management system means the activities keep happening. It runs on a cycle, the same one every ISO standard uses.
- Scope of the management systemOn change
- AI policyAnnually
- Roles and accountabilityOn change
- AI risk assessment and treatmentAnnually and on change
- AI system approvalsPer use case
- Inventory maintenanceContinuous
- Impact assessmentsPer system
- Vendor evaluationsOnboarding and renewal
- Training and awarenessAnnually, plus new starters
- Monitoring and measurementContinuous
- Internal auditAnnually
- Management reviewPeriodically
- Governance reportingQuarterly
- Corrective actionsAs raised
- Nonconformity trackingTo closure
- Policy and process updatesOn finding
- Continual improvementOngoing
They have the best operating process. A management system that stopped turning is just documentation with a date on it — and an auditor can tell the difference in about ten minutes.
The management system, as assigned work.
Every AIMS requirement becomes one or more tasks with an owner, a due date and the evidence it needs. Instead of tracking governance through spreadsheets and a recurring meeting, your team gets clear assignments and a documented record of completion, which is exactly what an ISO auditor asks to see.
Almost nobody has an AI governance team, an AI risk office or a dedicated AI compliance specialist. Greypike includes a named person who reviews completed work and makes sure governance activities are being documented in a way that will stand up when somebody asks.
Complete the impact assessment for the customer support assistant
Assess the effect of the deployed support assistant on customers and staff, not just on the business. Record who could be affected, how, and what oversight is in place.
- Owner
- Dana Whitfield, Operations
- Due
- 30 September 2026
- Evidence
- Completed impact assessment, signed off
- Accepted when
- Affected groups identified and oversight defined
- Also satisfies
- NIST AI RMF MAP and MEASURE
Not yet. The assessment covers customers but not the support staff whose work the assistant changes. 42001 asks about individuals and groups, which includes your own people. Add that section and it’s accepted.
Where are we using AI? Who approved it? How are the risks managed? How do we know it’s being used responsibly? If any of those takes more than a sentence, that’s the gap ISO 42001 closes.
It works alongside the NIST AI RMF, not instead of it.
Many organizations start with the AI RMF and move toward 42001 later. The two are complementary. One gives you the risk framework, the other gives you an auditable system and a path to a certificate.
WHICH DESCRIBES YOU?It gives you the structure quickly and without an audit timeline attached. You get an inventory, risk assessments and an approval workflow, which is most of what a customer is actually asking about when they ask how you govern AI.
- Faster to something you can show a customer
- No certification body, no audit window
- Everything you build carries into 42001 later
- Certify when a customer genuinely requires it
The AI RMF work maps substantially onto the AIMS. What 42001 adds is the management system machinery, scope, internal audit, management review and corrective action, rather than a second set of governance activities.
- Inventory, risk and treatment largely carry across
- Impact assessments may need broadening to groups and society
- Internal audit and management review are the genuinely new parts
- Your compliance manager identifies the gap before anything is assigned
If the requirement is a certificate a customer can verify, the AI RMF will not satisfy it, because there is nothing to certify against. Read the clause first, though: some customers ask for alignment rather than certification, and those are very different programs.
- An accredited certification body performs the audit, not us
- Plan for a real timeline, not a sprint
- The system has to have been operating, not just written
- We prepare you and review readiness before the audit
The AI RMF is the lighter starting point, and nothing you do there is wasted if you certify later.
You have already built most of this. It just wasn’t called AI governance.
This is where 42001 turns out easier than organizations expect. Most of the required activities already exist somewhere in the business, they just haven’t been pointed at AI yet.
Build a second governance program that runs in parallel.
Extend the governance program you already have to include AI.
Who’s doing the work.
AI governance is new. Building management systems that survive an audit is not.
- 20+ years across government and the Defense Industrial Base
- 14 years as a cybersecurity and fraud investigator
- Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA)
- MIT Sloan certificate in artificial intelligence for business strategy and governance
Greypike is a Veteran-Owned Small Business supporting 20+ Defense Industrial Base contractors on active contracts that support defense missions. We build and run compliant environments rather than only advising on them, and we bring the same evidence discipline to AI governance that a CMMC assessment demands.
That matters here because ISO 42001 is not a writing exercise. An auditor does not read your policy and leave. They ask who owns the decision, when it was last reviewed, what evidence exists, and whether the system has actually been running. We have spent two decades producing exactly that kind of record under regulators who do not accept good intentions.
Same posture we take on CMMC and SOC 2: we build the management system, an accredited body certifies it.
AI GRC is in early access.
We’d rather tell you that plainly than imply it ships today. The AI GRC module supports both ISO/IEC 42001 and the NIST AI RMF, with its own connectors into your AI stack, and it’s being built with the organizations using it.
Early access customers help decide what ships first, and get in before general availability.
It will be, the same way everything else on this site is. Until the module reaches general availability, quoting a number would be a guess.
- ISO/IEC 42001
- NIST AI RMF
- AI risk assessments
- AI inventories
- Governance workflows
- Compliance manager review
ISO 42001, answered.
The questions we get asked most often, before anyone signs anything.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international standard for governing artificial intelligence. It specifies the requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS). It governs how your organization manages AI, not how well any individual model performs.
Is ISO 42001 certifiable?
Yes. ISO/IEC 42001 is certifiable by an accredited certification body. That is the practical difference between ISO 42001 and the NIST AI Risk Management Framework, which is a voluntary framework with no certification path.
Does ISO 42001 apply if we only use AI tools rather than build them?
Yes. ISO/IEC 42001 applies whether your organization develops AI, provides it, or simply uses it. Deploying tools such as Microsoft Copilot, ChatGPT Enterprise, Google Gemini, Claude, AI coding assistants or internal AI applications creates a governance obligation under the standard. What changes is the role you document for each system, not whether the standard applies.
What does an ISO 42001 AI management system require?
Eight elements carry most of the weight: an AI policy, named roles and responsibilities, per-system AI risk assessment, AI risk treatment, impact assessments covering individuals and groups, an AI inventory, monitoring and evaluation, and continual improvement.
It is a management system operated on a Plan-Do-Check-Act cycle, not a document produced once. An auditor will ask whether the system has actually been running, not whether the policy exists.
Should we start with the NIST AI RMF or ISO 42001?
The two are complementary. Organizations starting from nothing usually begin with the NIST AI RMF, because it gives structure quickly without an audit timeline attached and delivers an AI inventory, risk assessments and an approval workflow.
Everything built there carries into ISO 42001 later. Go straight to 42001 when a customer specifically requires a certificate they can verify independently.
How does ISO 42001 relate to ISO 27001?
Same shape, different subject. ISO 27001 governs information security; ISO 42001 governs artificial intelligence. If you already run an ISO management system, the machinery will feel familiar, and your existing vendor management, risk assessment, policy management, access management, training and internal audit processes extend to cover AI rather than being rebuilt in parallel.
Does Greypike issue ISO 42001 certificates?
No. Greypike is not a certification body. We prepare you: building the governance processes, assigning ownership, organizing evidence and reviewing readiness before an external audit. Formal certification is performed by an accredited certification body.
We take the same posture on CMMC and SOC 2, for the same reason. A firm that builds your management system and then certifies it is marking its own homework.
We’re a defense contractor already doing CMMC. Does that help?
Considerably. Risk assessment, policy lifecycle, access management, training, internal audit and evidence discipline are already in place and already being examined by an assessor. ISO 42001 extends that machinery to AI rather than starting a second program. The genuinely new work is the AI inventory, impact assessments that look beyond your own organization, and management review of the AIMS.
Build AI governance before customers demand it.
Where are we using AI? Who approved it? How are the risks managed? How do we know it’s being used responsibly? ISO 42001 is a structured answer to all four, and it’s a far better position to be asked from than assembling one under pressure.
30 minutes, no prep. You’ll leave knowing which of the eight ISO 42001 requirements you already satisfy.
Early access · We prepare you · Certification is performed by an accredited body