ISO/IEC 42001:2023

AI governance is becoming a customer requirement, not just an internal policy.

A FEW YEARS AGO YOU WERE ASKED “Do you have a cybersecurity program?”
INCREASINGLY YOU’RE ASKED “How do you govern AI?”

Customers, insurers, boards and legal teams now ask for evidence that AI systems are managed responsibly. Deploying AI created a governance obligation nobody signed up for — and ISO/IEC 42001 is the structured answer to it.

THE OBLIGATION APPLIES TO ALL OF THESE
Microsoft CopilotChatGPT EnterpriseGoogle GeminiClaudeAI coding assistantsInternal AI applications

30 minutes, no prep. You’ll leave knowing which of the eight ISO 42001 requirements you already satisfy.

Veteran-Owned Small Business 20+ DIB contractors on active contracts Cyber AB RP & RPA credentialed

The first international standard for governing AI.

ISO/IEC 42001:2023 specifies the requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System, or AIMS. It applies whether you develop AI, provide it, or simply use it. The easiest way to place it:

ISO 27001YOU PROBABLY KNOW THIS ONE
Governs information security.
ISO 42001SAME SHAPE, NEW SUBJECT
Governs artificial intelligence.
It’s about how you manage AI, not how well your models perform.

The standard is concerned with organizational management, accountability, risk management, oversight and continual improvement — not the technical accuracy of any individual model. If you’ve implemented an ISO management system before, the machinery will feel familiar. If you haven’t, the concept is the thing to get right first: this is a system you operate, not a document you produce.

This one is certifiable.

That’s the practical difference between the two AI frameworks people compare, and it changes what you’re actually signing up for.

NIST AI Risk Management FrameworkVOLUNTARY
ISO/IEC 42001:2023CERTIFIABLE
Status
Voluntary framework, no certification exists
International standard, audited and certified by an accredited body
Shape
Four functions: GOVERN, MAP, MEASURE, MANAGE
A management system (AIMS) with the usual ISO machinery
What you end up with
A structured risk management approach
An auditable system, and a certificate if you pursue one
How you prove it
Your own evidence, shown to whoever asks
A certificate a customer can verify independently
Best when
You are starting out and need structure fast
Customers are asking for something they can check
NIST AI Risk Management FrameworkVOLUNTARY
Status
Voluntary framework, no certification exists
Shape
Four functions: GOVERN, MAP, MEASURE, MANAGE
What you end up with
A structured risk management approach
How you prove it
Your own evidence, shown to whoever asks
Best when
You are starting out and need structure fast
ISO/IEC 42001:2023CERTIFIABLE
Status
International standard, audited and certified by an accredited body
Shape
A management system (AIMS) with the usual ISO machinery
What you end up with
An auditable system, and a certificate if you pursue one
How you prove it
A certificate a customer can verify independently
Best when
Customers are asking for something they can check
Greypike does not issue ISO 42001 certifications.

We’re not a certification body. We help you prepare: building the governance processes, assigning ownership, organizing evidence and reviewing readiness before an external audit.

Formal certification is performed by an accredited certification body. Same posture we take on CMMC and SOC 2, and for the same reason: a firm that builds your management system and then certifies it is marking its own homework.

What an AIMS actually requires.

The standard asks for considerably more than a document. Eight elements carry most of the weight.

THE MYTH

“We’ll write an AI policy and we’re most of the way there.”

THE REALITY

The policy is one of eight requirements, and the smallest of them.

1

AI policy

Documented commitments governing how AI is used across the organization.

2

Roles and responsibilities

Clear accountability for AI decision-making and oversight. A named person, not a committee.

3

AI risk assessment

Identifying and evaluating AI-related risks, per system rather than in general.

4

AI risk treatment

Deciding how each identified risk is addressed, and recording the decision.

5

Impact assessments

Evaluating effects on individuals, groups and society, not only on your organization. This is what makes 42001 different from a security standard.

6

AI inventory

Identifying your AI systems and documenting the role you play for each one.

7

Monitoring and evaluation

Reviewing whether the governance processes and controls are actually working.

8

Continual improvement

Updating the system as AI, risks and regulation move underneath you.

Not a policy project. A management system.

This is the concept that decides whether your program survives its first year. A management system means the activities keep happening. It runs on a cycle, the same one every ISO standard uses.

PHASE 1PlanSET UP, THEN REVISIT
Establish the AIMS: scope it, write the policy, name who is accountable, assess the risks and decide how each will be treated. Most organizations do this once and assume it is finished. It is revisited every time the scope changes.
  • Scope of the management systemOn change
  • AI policyAnnually
  • Roles and accountabilityOn change
  • AI risk assessment and treatmentAnnually and on change
PHASE 2DoTHE OPERATING PART
Run the system. New AI gets approved before it is adopted, systems land on the inventory, impact assessments happen, vendors are evaluated, people are trained. This is where most of the actual work lives.
  • AI system approvalsPer use case
  • Inventory maintenanceContinuous
  • Impact assessmentsPer system
  • Vendor evaluationsOnboarding and renewal
  • Training and awarenessAnnually, plus new starters
PHASE 3CheckPROVE IT WORKS
Monitor, measure and evaluate whether the governance actually functions. Internal audit sits here, and so does management review: leadership genuinely looking at the program rather than being told it is fine.
  • Monitoring and measurementContinuous
  • Internal auditAnnually
  • Management reviewPeriodically
  • Governance reportingQuarterly
PHASE 4ActCLOSE THE LOOP
Correct what the checking found and improve the system. Nonconformities get owners and dates; findings change the way the system runs rather than being noted and filed.
  • Corrective actionsAs raised
  • Nonconformity trackingTo closure
  • Policy and process updatesOn finding
  • Continual improvementOngoing
The organizations that succeed at this don’t have the biggest policy binder.

They have the best operating process. A management system that stopped turning is just documentation with a date on it — and an auditor can tell the difference in about ten minutes.

The management system, as assigned work.

Every AIMS requirement becomes one or more tasks with an owner, a due date and the evidence it needs. Instead of tracking governance through spreadsheets and a recurring meeting, your team gets clear assignments and a documented record of completion, which is exactly what an ISO auditor asks to see.

WHO THIS USUALLY LANDS ON
CIOsCISOsCTOsLegal teamsOperations leadersCompliance leaders
A dedicated compliance manager, included

Almost nobody has an AI governance team, an AI risk office or a dedicated AI compliance specialist. Greypike includes a named person who reviews completed work and makes sure governance activities are being documented in a way that will stand up when somebody asks.

ILLUSTRATIVE EXAMPLE — NOT A REAL CUSTOMER RECORD
TASK 047 · ISO/IEC 42001, AIMS

Complete the impact assessment for the customer support assistant

Assess the effect of the deployed support assistant on customers and staff, not just on the business. Record who could be affected, how, and what oversight is in place.

Owner
Dana Whitfield, Operations
Due
30 September 2026
Evidence
Completed impact assessment, signed off
Accepted when
Affected groups identified and oversight defined
Also satisfies
NIST AI RMF MAP and MEASURE
MOMarcus O., compliance manager

Not yet. The assessment covers customers but not the support staff whose work the assistant changes. 42001 asks about individuals and groups, which includes your own people. Add that section and it’s accepted.

Can you answer these four questions today?

Where are we using AI? Who approved it? How are the risks managed? How do we know it’s being used responsibly? If any of those takes more than a sentence, that’s the gap ISO 42001 closes.

It works alongside the NIST AI RMF, not instead of it.

Many organizations start with the AI RMF and move toward 42001 later. The two are complementary. One gives you the risk framework, the other gives you an auditable system and a path to a certificate.

WHICH DESCRIBES YOU?
OUR SUGGESTION Start with the AI RMF

It gives you the structure quickly and without an audit timeline attached. You get an inventory, risk assessments and an approval workflow, which is most of what a customer is actually asking about when they ask how you govern AI.

  • Faster to something you can show a customer
  • No certification body, no audit window
  • Everything you build carries into 42001 later
  • Certify when a customer genuinely requires it

The AI RMF is the lighter starting point, and nothing you do there is wasted if you certify later.

You have already built most of this. It just wasn’t called AI governance.

This is where 42001 turns out easier than organizations expect. Most of the required activities already exist somewhere in the business, they just haven’t been pointed at AI yet.

WHAT YOU ALREADY RUN
WHAT IT BECOMES UNDER 42001
Vendor management
Evaluation of AI providers and embedded AI
Risk assessments
AI risk assessment and treatment
Policy management
The AI policy, in the same lifecycle
Access management
Who can reach which AI system
Training and awareness
AI competence and acceptable use training
Internal audit and management review
The same machinery, extended to the AIMS
NOT THE GOAL

Build a second governance program that runs in parallel.

THE GOAL

Extend the governance program you already have to include AI.

Who’s doing the work.

AI governance is new. Building management systems that survive an audit is not.

David Dillow Founder, Greypike
  • 20+ years across government and the Defense Industrial Base
  • 14 years as a cybersecurity and fraud investigator
  • Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA)
  • MIT Sloan certificate in artificial intelligence for business strategy and governance

Greypike is a Veteran-Owned Small Business supporting 20+ Defense Industrial Base contractors on active contracts that support defense missions. We build and run compliant environments rather than only advising on them, and we bring the same evidence discipline to AI governance that a CMMC assessment demands.

That matters here because ISO 42001 is not a writing exercise. An auditor does not read your policy and leave. They ask who owns the decision, when it was last reviewed, what evidence exists, and whether the system has actually been running. We have spent two decades producing exactly that kind of record under regulators who do not accept good intentions.

Same posture we take on CMMC and SOC 2: we build the management system, an accredited body certifies it.

IN DEVELOPMENT

AI GRC is in early access.

We’d rather tell you that plainly than imply it ships today. The AI GRC module supports both ISO/IEC 42001 and the NIST AI RMF, with its own connectors into your AI stack, and it’s being built with the organizations using it.

Early access customers help decide what ships first, and get in before general availability.

Pricing isn’t published yet

It will be, the same way everything else on this site is. Until the module reaches general availability, quoting a number would be a guess.

WHAT THE MODULE SUPPORTS
  • ISO/IEC 42001
  • NIST AI RMF
  • AI risk assessments
  • AI inventories
  • Governance workflows
  • Compliance manager review

ISO 42001, answered.

The questions we get asked most often, before anyone signs anything.

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first international standard for governing artificial intelligence. It specifies the requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS). It governs how your organization manages AI, not how well any individual model performs.

Is ISO 42001 certifiable?

Yes. ISO/IEC 42001 is certifiable by an accredited certification body. That is the practical difference between ISO 42001 and the NIST AI Risk Management Framework, which is a voluntary framework with no certification path.

Does ISO 42001 apply if we only use AI tools rather than build them?

Yes. ISO/IEC 42001 applies whether your organization develops AI, provides it, or simply uses it. Deploying tools such as Microsoft Copilot, ChatGPT Enterprise, Google Gemini, Claude, AI coding assistants or internal AI applications creates a governance obligation under the standard. What changes is the role you document for each system, not whether the standard applies.

What does an ISO 42001 AI management system require?

Eight elements carry most of the weight: an AI policy, named roles and responsibilities, per-system AI risk assessment, AI risk treatment, impact assessments covering individuals and groups, an AI inventory, monitoring and evaluation, and continual improvement.

It is a management system operated on a Plan-Do-Check-Act cycle, not a document produced once. An auditor will ask whether the system has actually been running, not whether the policy exists.

Should we start with the NIST AI RMF or ISO 42001?

The two are complementary. Organizations starting from nothing usually begin with the NIST AI RMF, because it gives structure quickly without an audit timeline attached and delivers an AI inventory, risk assessments and an approval workflow.

Everything built there carries into ISO 42001 later. Go straight to 42001 when a customer specifically requires a certificate they can verify independently.

How does ISO 42001 relate to ISO 27001?

Same shape, different subject. ISO 27001 governs information security; ISO 42001 governs artificial intelligence. If you already run an ISO management system, the machinery will feel familiar, and your existing vendor management, risk assessment, policy management, access management, training and internal audit processes extend to cover AI rather than being rebuilt in parallel.

Does Greypike issue ISO 42001 certificates?

No. Greypike is not a certification body. We prepare you: building the governance processes, assigning ownership, organizing evidence and reviewing readiness before an external audit. Formal certification is performed by an accredited certification body.

We take the same posture on CMMC and SOC 2, for the same reason. A firm that builds your management system and then certifies it is marking its own homework.

We’re a defense contractor already doing CMMC. Does that help?

Considerably. Risk assessment, policy lifecycle, access management, training, internal audit and evidence discipline are already in place and already being examined by an assessor. ISO 42001 extends that machinery to AI rather than starting a second program. The genuinely new work is the AI inventory, impact assessments that look beyond your own organization, and management review of the AIMS.

Build AI governance before customers demand it.

Where are we using AI? Who approved it? How are the risks managed? How do we know it’s being used responsibly? ISO 42001 is a structured answer to all four, and it’s a far better position to be asked from than assembling one under pressure.

30 minutes, no prep. You’ll leave knowing which of the eight ISO 42001 requirements you already satisfy.

Early access · We prepare you · Certification is performed by an accredited body