MenuMenu

ISO/IEC 42001 – Artificial Intelligence

A management system that promotes the ethical, trustable, and safe use of Artificial Intelligence in business processes

ISO/IEC 42001ISO/IEC 42001 introduced the Artificial Intelligence Management System (AIMS).

Artificial Intelligence (AI) is the discipline focused on developing the ability of an IT system to simulate typically human tasks such as reasoning, learning, planning, and creativity through structured learning processes, including machine learning.
AI is increasingly being applied in technology-enabled business processes across a wide range of sectors, including healthcare, finance, energy, transportation, human resources, entertainment, and cybersecurity.

The introduction of AI into processes that have traditionally relied on human reasoning raises ethical concerns and risks associated with delegating decision-making powers to automated tools. These systems can modify their behavior over time based on the inputs they receive and may be influenced by factors that are not fully transparent and that lie beyond the control of process owners.

The purpose of an AI management system is to provide organisations of any size and industry with the tools needed to govern AI-related processes, whether they act as developers, providers, or users of such systems. In this way, organisations can offer the market assurance that Artificial Intelligence is being used in an ethical, responsible, trustworthy, and secure manner.

Why choose RINA?

RINA can issue accredited certifications through Accredia, leveraging teams of highly qualified auditors.

In addition, our extensive experience in the ICT sector, gained through certifications such as ISO/IEC 27001 and ISO/IEC 20000-1, ensures that our audit teams possess specific expertise in information technology and software development. Furthermore, our professionals actively participate in study communities dedicated to Artificial Intelligence.

Certification process 

  • Completion of the information questionnaire. 
  • Receipt of the technical-economic offer which, once accepted, constitutes the service provision contract.
  • Conducting audit activities, both on-site and off-site, and issuing a final report.
  • If the previous phases are successful, the certification is evaluated by a Technical Committee.
  • If the previous steps are successful a certificate of conformity is issued.
  • Annual audit for certificate maintenance. 

The ISO/IEC 42001 certification is valid for years and can be renewed at the end of the three-year period.

Our experts answer to the most frequently questions

Our organization provides consulting services and we don’t develop systems based on Artificial Intelligence. Can we apply for ISO/IEC 42001 certification?

Yes, the Artificial Intelligence management system can be effectively used by developers, suppliers and users of AI-based products and services.  

Is ISO/IEC 42001 a technical standard for Artificial Intelligence programming techniques?

No. Like other standards (such as 9001, 14001 and 27001), ISO/IEC 42001 establishes the requirements for developing an Artificial Intelligence management system. This includes the organizational, operational and risk management aspects useful for achieving corporate objectives and ensuring ethical use, responsible and safe of Artificial Intelligence. 

Is it mandatory to have an ISO 9001 certification to be ISO/IEC 42001 certified?

No, ISO/IEC 42001 is a standalone certification. However, having an ISO 9001 management system related to processes that use AI techniques can facilitate the implementation of the standard. In fact, ISO/IEC 42001 is design to align perfectly with ISO 9001, making it easier to integrate with the Quality Management System (QMS). 

Regulatory Focus  

From a technical perspective, AI management systems refer to several ISO standards that provide guidance and context, including ISO/IEC TS 4213, ISO/IEC 23053, and ISO/IEC 5259 on Machine Learning, ISO/IEC 5338 on the System Life Cycle, as well as methodological standards such as ISO/IEC 22989 (Concepts and Terminology), ISO/IEC 23894 (Risk Management), and ISO/IEC 24368 (Ethical Considerations).

The National Institute of Standards and Technology (NIST) has also developed an AI Risk Management Framework.

From a regulatory standpoint, the Artificial Intelligence Act (AI Act) is now in force across the European Union (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744). It is the primary regulation governing the use of Artificial Intelligence based on the level of risk associated with AI-enabled applications.

The European standard EN 18286:2026 is aligned with and references the requirements of the EU AI Act.

 
Contact us
Embrace innovation
Find the nearest RINA office and speak with our experts
  • Country/Region
  • Albania
  • Argentina
  • Bangladesh
  • Brazil
  • Bulgaria
  • China
  • Denmark
  • Egypt
  • Germany
  • Greece
  • Hong Kong
  • India
  • Indonesia
  • Italy
  • Kazakhstan
  • Lebanon
  • Malaysia
  • Netherlands
  • Poland
  • Republic of Korea
  • Romania
  • Russia
  • Spain
  • Turkey
  • United Arab Emirates
  • United Kingdom
Resources

Certification rule

pdf

ISO 42001 rule appendix

pdf

General contract conditions

pdf

Rules governing the use of the RINA figurative mark in license agreements

pdf

Complaints, observations and appeals

General information questionnaire

docx

Specific information questionnaire

docx

Related services

You may also like