ISO/IEC 42001 is the first international standard for an artificial intelligence management system (AIMS). Published by ISO and IEC in 2023, it sets requirements for how an organization governs the development, provision, and use of AI systems, covering risk, accountability, transparency, and continual improvement across the AI lifecycle.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 defines requirements for an AI management system (AIMS): the policies, processes, and controls an organization uses to manage AI responsibly. It was published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023, and it is the first certifiable standard of its kind.
The standard follows the same high-level structure as other ISO management system standards such as ISO 13485 and ISO/IEC 27001, so it slots alongside a quality management system rather than replacing it. ISO/IEC 42001 is organization-level governance. It does not certify a single product or model. Instead, it confirms that a company has a working system for identifying AI risks, assigning responsibility, and improving over time.
Why ISO/IEC 42001 matters in medical device development
AI and machine learning now sit inside diagnostics, imaging, patient monitoring, and clinical decision support, often as software as a medical device (SaMD). Existing frameworks like ISO 13485 and IEC 62304 govern quality and software lifecycle, but they were not written for AI-specific risks such as biased training data, model drift, opaque decisions, and the need for human oversight. That is the gap ISO/IEC 42001 fills.
Regulation is moving in the same direction. Under the EU AI Act, an AI-enabled medical device that requires notified-body review is treated as a high-risk AI system, with obligations layered on top of MDR or IVDR rather than replacing them. Compliance dates are still settling: the deadline for high-risk AI embedded in regulated products has been proposed to move from August 2027 toward August 2028 under the Digital Omnibus package, and the scope remains under active debate. A recognized AIMS gives teams a structured, auditable way to prepare for whatever lands.
How ISO/IEC 42001 works
ISO/IEC 42001 is built on the familiar management-system cycle: understand context, set leadership and policy, plan, resource, operate, evaluate, and improve. On top of that base, it adds AI-specific requirements.
Core elements include:
- An AI policy and clear governance roles for AI systems.
- AI risk assessment, which can reuse the risk methods teams already run under ISO 14971.
- An AI system impact assessment that looks at effects on individuals and groups, not just the organization.
- Annex A controls covering areas like data management, transparency, human oversight, and lifecycle management.
Certification is voluntary and handled by an accredited body through a Stage 1 and Stage 2 audit, with surveillance audits and a three-year cycle, similar to ISO/IEC 27001. Because it shares structure with ISO 13485, a device maker can integrate the AIMS with an existing quality management system instead of standing up a separate one. It also connects naturally to IEC 62304 for software lifecycle and IEC 81001-5-1 for health software security.
Common challenges and best practices
A common trap is treating ISO/IEC 42001 as a documentation exercise. An AIMS that lives only in a binder does little for a device that keeps learning after release. Another is bolting AI governance onto the side of the quality system, which creates duplicate records and conflicting owners.
Data governance is where many teams underestimate the effort. AI risk depends heavily on data quality, representativeness, and traceability, and those need real process behind them. Post-deployment monitoring is another weak spot, since model performance can shift once a device meets real-world data.
Good practice starts with integration. Map ISO/IEC 42001 clauses onto the existing ISO 13485 structure and reuse ISO 14971 for hazard analysis so AI risk sits inside one coherent risk file. Define the AI system impact assessment early, tie drift monitoring to the post-market surveillance plan, and, for adaptive algorithms, align it with a predetermined change control plan. One point worth stating plainly: ISO/IEC 42001 is not a harmonized standard for the EU AI Act, so certification does not grant presumption of conformity. It is strong preparation, not a shortcut.
Frequently asked questions
No. ISO/IEC 42001 is a voluntary standard, and certification is optional. That said, it is becoming a practical baseline for organizations that build or deploy AI, and it supports readiness for the EU AI Act. For AI-enabled medical devices, it offers a structured governance framework that regulators, notified bodies, and customers increasingly expect to see, even though no law currently requires the certificate itself.
The two standards address different things. ISO 13485 is the quality management system standard for medical devices, covering design, production, and traceability. ISO/IEC 42001 governs how an organization manages AI systems and their specific risks, such as data quality, bias, and human oversight. They share the same high-level structure, so a device maker can run both together as one integrated management system.
Not automatically. ISO/IEC 42001 is a voluntary governance framework, not a harmonized standard under the EU AI Act, so certification does not by itself grant presumption of conformity. It does help teams build the risk management, data governance, and oversight processes the Act expects. Harmonized standards being developed for the AI Act will define the formal conformity route once they are published.
Yes. Certification is issued by an accredited certification body after a Stage 1 and Stage 2 audit of the AI management system. It is valid for three years with annual surveillance audits, mirroring ISO/IEC 27001. Because ISO/IEC 42001 uses the same structure as ISO 13485, companies that already hold a quality management certification often find the path shorter.
Related terms
- Software as a Medical Device (SaMD)
- ISO 13485
- ISO 14971
- EU AI Act
- IEC 62304