Authority guide · updated 30 August 2026

ISO/IEC 42001: the AI management system standard, explained for Irish businesses

ISO/IEC 42001 is the international standard for AI management systems. It is voluntary, it is certifiable by an accredited certification body, and it is not an information-security certification. This page explains what it asks for, how it sits alongside the EU AI Act, how certification actually works, and — honestly — where software helps and where it cannot.

What the standard is

ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation. Like other ISO management-system standards, it is concerned with how an organisation runs a discipline rather than with the technical detail of any one system: who is accountable, what is in scope, how risks and impacts are assessed, which controls operate, how performance is monitored, and how the whole thing is audited, reviewed and improved.

An organisation can implement the standard without seeking certification, and many do — the management system is useful on its own. Certification is the separate step of having an accredited certification body audit that system and issue a certificate.

What it is not: 42001 versus 27001, SOC 2 and pen testing

This is worth stating plainly, because the categories get blurred in sales conversations. ISO/IEC 42001 is an AI management-system standard. It is not an information-security certification.

  • ISO/IEC 27001 is the standard for information security management. It addresses how you protect information. It does not address how you govern AI.
  • SOC 2 is a controls assurance report produced by auditors against defined trust criteria. It is a report on controls over a period, not an AI management-system certification.
  • Penetration testing is a technical security assessment of systems and applications. It tells you about exploitable weaknesses, not about governance.
  • ISO/IEC 42001 asks whether the organisation has a working system for managing AI: scope, leadership, risk and impact, controls, competence, monitoring, audit, review and improvement.

An organisation can hold all four positions, or none. Each answers a different question, and a customer questionnaire that treats them as interchangeable is asking the wrong thing.

How ISO/IEC 42001 differs from the EU AI Act

The shortest version: the Act is an external compliance position, the standard is an internal operating system. The Act tells you what you must do and by when. The standard gives you the machinery to keep doing it, and to show that you did.

DimensionEU AI ActISO/IEC 42001
What it isLaw — Regulation (EU) 2024/1689, directly applicable in IrelandA voluntary international standard for AI management systems, published December 2023
What it asks of youSpecific legal obligations, determined by your role (provider or deployer) and the risk classification of each systemManagement-system discipline: scope, leadership, risk and impact assessment, controls, monitoring, audit and improvement
TimingPublished deadlines, already partly in forceNo deadline; adopted when the organisation chooses
Who says you have met itRegulators and, in practice, customers, insurers and tender processesAn accredited certification body, if you choose to seek certification
What it producesAn external compliance position you must be able to evidenceAn internal operating system for governing AI continuously
Scope of subject matterAI systems placed on the market or used in the EUHow the organisation manages AI, wherever it operates

They are complementary, not alternatives. In practice the same underlying material — the inventory, the owners, the risk and impact assessments, the evidence trail — serves both. That is the argument for running them together rather than one after the other. Our plain-English guide to the EU AI Act in Ireland covers the legal side in detail.

What an AI management system contains

Described generally, and in the order most organisations end up building it:

Context and scope

What the organisation does with AI, who is affected, and what the management system covers.

Leadership and policy

Senior accountability for AI, expressed in a policy that is issued, known and maintained.

Roles and responsibilities

Named ownership for AI systems and for the governance process itself, with authority to match.

Risk and impact assessment

Assessment of risk to the organisation and of impact on the people affected by an AI system, documented and revisited.

Objectives and planning

What the organisation is trying to achieve with its AI governance, and the plan to get there.

Competence and awareness

The people involved know enough to do their part, and there is a record that they do.

Operational controls

The controls that actually run day to day: approvals, restrictions, human oversight, defined exceptions.

Supplier and third-party governance

Diligence over the vendors and models you depend on, and the terms you rely on.

Monitoring and measurement

Evidence that the system is working, not merely documented.

Internal audit

Periodic internal checking against the requirements, by someone able to be objective about it.

Management review

Leadership reviewing the system at planned intervals and recording the decisions taken.

Corrective action and continual improvement

Findings, incidents and gaps are worked, closed and used to change the system.

Two things follow from that list. First, most of it is record-keeping discipline rather than technical work. Second, an organisation that has already built an EU AI Act register has done a meaningful share of it without calling it that.

Where AI Register supports the work

Read this before the table

The mapping below indicates where the platform supports these management-system disciplines. It is not a claim of complete clause coverage of ISO/IEC 42001. A clause-level mapping has not yet been reviewed and documented, and we will not imply one until it has been. Using AI Register does not make an organisation certified, compliant, or ready for audit on its own.

Management-system disciplineWhere AI Register supports it
AI scope and inventoryA guided inventory of AI systems and use cases, with business unit, purpose and status recorded in one register.
Roles, responsibilities and accountabilityA named owner and review date on every system, plus administrator roles and an append-only history of who changed what.
Risk and impact assessmentStructured classification against the EU AI Act taxonomy, with the rationale and legal basis recorded alongside the outcome.
Objectives, controls and treatment actionsAn obligation and control register, with owners, evidence and status, so treatment actions are tracked rather than remembered.
Competence and AI-literacy evidenceAI policy attestations and Article 4 AI-literacy records, timestamped and exportable.
Supplier and vendor governanceVendor due-diligence records held against the systems that depend on them, with vendor and product-change intelligence on the Assure tier.
Operational approvals and exceptionsApproval and periodic-review workflows, an exception register, and an agent decision-rights register for autonomous use.
Monitoring, incidents and reviewAn incident register, review dates that come due, and a register view that shows what has moved since last time.
Management review evidenceBoard and customer-assurance exports, a quarterly board pack on the Assure tier, and director attestations written to an append-only trail.
Corrective action and continual improvementFindings and actions carried on the register with owners and dates, and an append-only history recording how each position changed, with actor, timestamp and ruleset version.

Feature availability differs by plan — the vendor, incident, attestation and board-review capabilities sit on the higher tiers. The pricing page sets out what each plan includes.

What the platform does not replace

  • Your own decisions. The register records a position; it does not decide what risk your organisation is willing to carry.
  • Competent people. A management system runs on people who understand the AI in use and have the authority to act on it.
  • Legal advice. The platform provides general regulatory information and structured self-assessment, not advice on your legal position.
  • An accredited certification audit. Certification is granted by a certification body after auditing your organisation. Software cannot confer it.

To be explicit, because this is where marketing usually overreaches: AI Register Ireland is not certified to ISO/IEC 42001, Acuity AI Advisory is not an accredited certification body, and no subscription to this product certifies anyone. Nor does the product guarantee compliance with the EU AI Act or any other law.

Preparing for an assessment? Read what should be in place before an ISO 42001 certification audit, including an original illustration of how a decision connects to operating evidence.

How certification actually works

Certification to ISO/IEC 42001 is granted by an accredited certification body following an audit of your organisation. Software cannot confer it, a consultant cannot confer it, and an internal declaration is not certification. The general shape of the route is consistent across ISO management-system standards:

  1. 1

    Readiness

    The management system is designed, implemented and operating: scope set, policy issued, roles named, risks and impacts assessed, controls running, records accumulating. Certification bodies expect to see a system that has actually been used, not one written the week before.

  2. 2

    Internal audit

    The organisation audits itself against the requirements, records findings, and works them. This is a requirement of the management system in its own right, not merely preparation.

  3. 3

    Management review

    Leadership reviews the system at a planned interval, considers performance, findings and changes, and records the decisions. This is usually the evidence an auditor asks for first.

  4. 4

    Stage 1 audit

    The certification body reviews the documented system and the organisation's readiness, and identifies anything that would prevent a full audit succeeding.

  5. 5

    Stage 2 audit

    The certification body audits the system in operation, testing whether what is documented is what actually happens. Findings are raised and must be addressed before a certificate issues.

  6. 6

    Surveillance and recertification

    Certification is not a one-off. The certification body returns on a periodic cycle to confirm the system is still operating, and the certificate is renewed after a further full audit at the end of the cycle.

Timelines, audit durations and cycle lengths vary by certification body and by the size and complexity of the organisation, so treat the sequence above as the shape rather than the schedule. Confirm the specifics with the certification body you intend to use, and check that it holds accreditation for this standard.

How Assure supports readiness and continuing review

Assure is the tier for organisations that want the register actively reviewed rather than merely hosted. It supports readiness and the ongoing review rhythm a management system needs — it does not, and cannot, deliver certification.

  • An ISO/IEC 42001 gap and readiness view over your own register, showing where the management-system disciplines are supported by evidence and where they are not.
  • A quarterly expert review of the register with Acuity, with the findings written down.
  • A quarterly board pack drafted from the live register, plus director attestations recorded on an append-only trail.
  • Proactive regulatory, vendor and product-change intelligence matched against the systems in your own register, with commentary on what to do.
  • A named assurance lead: the review is led by Ger Perdisatt, a certified ISO/IEC 42001 Lead Auditor. That is his individual professional qualification — it is not a certification of your organisation, and it is not a substitute for an audit by an accredited certification body.

Assure · from €1,500 / month, from €18,000 billed annually

Get the register reviewed, quarter by quarter

An ISO/IEC 42001 gap and readiness view over your own register, a quarterly expert review, a board pack your directors can attest to, and proactive intelligence matched to the systems you actually run. Onboarded personally.

Request a briefing

Frequently asked questions

ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation. It is a management-system standard, in the same family as other ISO management-system standards, and it is voluntary.

No. ISO/IEC 42001 governs how an organisation manages AI: scope, leadership, roles, risk and impact assessment, controls, monitoring, audit and improvement. Information security management is the subject of ISO/IEC 27001. SOC 2 is a controls assurance report produced by auditors, and penetration testing is a technical security assessment. They answer different questions and none of them substitutes for another.

No. The EU AI Act is law and creates obligations tied to your role and to the risk classification of each system, on published deadlines. ISO/IEC 42001 is a voluntary certifiable standard that gives you a management system for governing AI continuously. They are complementary: the Act sets the external compliance position, the standard gives you the internal operating system that keeps it current.

No. Certification is granted by an accredited certification body following an audit of your organisation. No software product can confer it, and AI Register does not. What software can do is hold the inventory, assessments, decisions and evidence that an audit will ask to see, and keep that record current between reviews.

No, and we do not claim to be. Acuity AI Advisory is not an accredited certification body and cannot certify anyone. Ger Perdisatt is a certified ISO/IEC 42001 Lead Auditor — that is an individual professional qualification held by a person, not a certification of AI Register, of Acuity, or of any customer.

Start with the same foundations the Act requires: a complete inventory of AI systems and use cases, a named owner for each, a documented risk and impact assessment, and an evidence trail that survives inspection. Those are also the foundations of an AI management system, which is why the two workstreams are worth running together rather than sequentially.

Statutory notice

This tool provides general regulatory information and structured self-assessment. It does not constitute legal advice. Seek professional advice for decisions with legal consequences.

Nothing on this page is a certification, an audit opinion, or a statement that any organisation meets ISO/IEC 42001. The full disclaimer applies.