Short answer. ISO/IEC 42001 is the world’s first certifiable AI management system standard, published in December 2023. It sets out how an organization governs the AI it builds and uses, through 7 management clauses and 38 reference controls grouped into 9 areas. Certification is voluntary, lasts 3 years with annual surveillance audits, and is increasingly required in procurement across regulated sectors like banking and insurance.
ISO/IEC 42001 does for AI what ISO 27001 did for information security: it turns scattered good intentions into a documented, auditable system. The standard asks an organization to define who owns AI decisions, how AI risks are assessed, what data feeds each model, and how incidents get handled. An external auditor then checks that the system runs as written.
The standard has two moving parts. Clauses 4 to 10 define what the management system must do: establish context, set an AI policy, plan risk treatment, operate AI processes, evaluate performance, and improve. Annex A then lists 38 controls across 9 objectives, from AI policy and internal roles to impact assessment, the AI system life cycle, data governance, transparency, responsible use, and third-party relationships. An organization selects the controls that address its identified risks and records the choices, and any exclusions, in a Statement of Applicability.
In a financial services setting, that structure lands on concrete systems:
For banks and insurers in Central Europe, ISO/IEC 42001 arrives at the same moment as binding law. The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024, with obligations for high-risk systems phasing in through 2026 and 2027. Credit scoring and life and health insurance pricing are named high-risk uses. Certification to ISO/IEC 42001 does not replace legal compliance, and it does not deliver CE marking, EU database registration, or post-market monitoring on its own. It does build the governance backbone that those obligations assume is already there.
The overlap is direct. Independent mappings show 7 of the EU AI Act’s core requirements for high-risk systems, including risk management, data governance, technical documentation, human oversight, and incident handling, have counterparts in ISO/IEC 42001 clauses and Annex A controls. A firm that certifies first is not starting from zero when the auditor or regulator arrives. Procurement teams have noticed: enterprise buyers in regulated sectors increasingly list AI governance certification as a supplier qualification criterion, which turns the standard into a commercial gate as much as a compliance one.
ISO/IEC 42001, published December 2023, is the first certifiable AI management system standard, built on 7 clauses and 38 Annex A controls across 9 areas.
The EU AI Act is law. It applies whether or not a company wants it to, it is enforced by national authorities, and it carries fines up to 35 million euros or 7% of global turnover for the most serious breaches. ISO/IEC 42001 is a voluntary standard. No one is legally required to hold it, and certification is granted by an accredited body, not a regulator.
The two work in different registers. The AI Act tells you what outcomes are required for specific risk categories. ISO/IEC 42001 tells you how to run a management system that keeps producing those outcomes over time. A useful way to hold it: the Act sets the obligations, the standard gives you a repeatable machine for meeting them. Certification signals maturity to customers and regulators, but it does not, by itself, prove that any single high-risk system is Act-compliant.
Annex A is the control library. Its 38 controls sit in 9 objectives: AI policy, internal organization, resources for AI systems, assessing the impact of AI systems, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. Each control describes a specific safeguard, such as maintaining data-quality and provenance records, documenting system design and validation, or defining human oversight for a given use.
The controls are not all mandatory. Under clause 6.1.3, an organization runs an AI risk assessment, then selects the controls that treat the risks it found and justifies any it leaves out in the Statement of Applicability. That risk-based logic is what lets a 12-person fintech and a large universal bank both certify to the same standard while implementing very different control sets.
Certification follows the familiar two-stage audit model. Stage 1 reviews the documentation and readiness of the management system. Stage 2 tests whether the system operates in practice. A certificate is valid for 3 years, with annual surveillance audits and a full recertification in year three. Most organizations run an internal gap assessment first, close the gaps, then book the certification body.
For a mid-market bank or insurer, the realistic path is a governance program measured in months, not weeks. The heavy lifting is rarely the paperwork. It is agreeing who owns each AI system, building the risk-assessment habit, and wiring monitoring into models that were shipped before anyone thought about drift or provenance. Certification is the checkpoint, not the work itself.
Start with an inventory. Most regulated firms cannot name every AI and machine-learning system already in production, including the ones embedded in vendor tools. A complete register, tagged by business impact and EU AI Act risk category, is the foundation for both the standard and the law. Without it, the risk assessment has nothing to assess.
From there, assign owners, run impact assessments on the high-impact systems first, and map existing controls against Annex A to find the real gaps. Firms already holding ISO 27001 have a head start: the management-system scaffolding, internal audit, management review, and corrective action, carries straight over. The AI-specific work concentrates on data governance, transparency, and human oversight.
Governance only counts when it survives production. In 2025 Ableneo shipped 34 AI projects, with roughly 4 in 5 reaching production and 94% built on large language models, across banking and insurance clients including ČSOB, Erste Group, and UNIQA. That work is where a standard like ISO/IEC 42001 stops being a document and becomes an operating discipline: named owners, logged decisions, monitored models, and a clear line from data to outcome. Ableneo treats AI governance as part of the build, not a compliance layer bolted on afterward, and our teams across Slovakia, the Czech Republic, and Austria design systems to be observable and accountable from day one. See how we approach this on our AI transformation practice page.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.