Authority guide · updated 30 August 2026
ISO/IEC 42001: the AI management system standard, explained for Irish businesses
ISO/IEC 42001 is the international standard for AI management systems. It is voluntary, it is certifiable by an accredited certification body, and it is not an information-security certification. This page explains what it asks for, how it sits alongside the EU AI Act, how certification actually works, and — honestly — where software helps and where it cannot.
What the standard is
ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation. Like other ISO management-system standards, it is concerned with how an organisation runs a discipline rather than with the technical detail of any one system: who is accountable, what is in scope, how risks and impacts are assessed, which controls operate, how performance is monitored, and how the whole thing is audited, reviewed and improved.
An organisation can implement the standard without seeking certification, and many do — the management system is useful on its own. Certification is the separate step of having an accredited certification body audit that system and issue a certificate.
What it is not: 42001 versus 27001, SOC 2 and pen testing
This is worth stating plainly, because the categories get blurred in sales conversations. ISO/IEC 42001 is an AI management-system standard. It is not an information-security certification.
- ISO/IEC 27001 is the standard for information security management. It addresses how you protect information. It does not address how you govern AI.
- SOC 2 is a controls assurance report produced by auditors against defined trust criteria. It is a report on controls over a period, not an AI management-system certification.
- Penetration testing is a technical security assessment of systems and applications. It tells you about exploitable weaknesses, not about governance.
- ISO/IEC 42001 asks whether the organisation has a working system for managing AI: scope, leadership, risk and impact, controls, competence, monitoring, audit, review and improvement.
An organisation can hold all four positions, or none. Each answers a different question, and a customer questionnaire that treats them as interchangeable is asking the wrong thing.
How ISO/IEC 42001 differs from the EU AI Act
The shortest version: the Act is an external compliance position, the standard is an internal operating system. The Act tells you what you must do and by when. The standard gives you the machinery to keep doing it, and to show that you did.
| Dimension | EU AI Act | ISO/IEC 42001 |
|---|---|---|
| What it is | Law — Regulation (EU) 2024/1689, directly applicable in Ireland | A voluntary international standard for AI management systems, published December 2023 |
| What it asks of you | Specific legal obligations, determined by your role (provider or deployer) and the risk classification of each system | Management-system discipline: scope, leadership, risk and impact assessment, controls, monitoring, audit and improvement |
| Timing | Published deadlines, already partly in force | No deadline; adopted when the organisation chooses |
| Who says you have met it | Regulators and, in practice, customers, insurers and tender processes | An accredited certification body, if you choose to seek certification |
| What it produces | An external compliance position you must be able to evidence | An internal operating system for governing AI continuously |
| Scope of subject matter | AI systems placed on the market or used in the EU | How the organisation manages AI, wherever it operates |
They are complementary, not alternatives. In practice the same underlying material — the inventory, the owners, the risk and impact assessments, the evidence trail — serves both. That is the argument for running them together rather than one after the other. Our plain-English guide to the EU AI Act in Ireland covers the legal side in detail.
What an AI management system contains
Described generally, and in the order most organisations end up building it:
Context and scope
What the organisation does with AI, who is affected, and what the management system covers.
Leadership and policy
Senior accountability for AI, expressed in a policy that is issued, known and maintained.
Roles and responsibilities
Named ownership for AI systems and for the governance process itself, with authority to match.
Risk and impact assessment
Assessment of risk to the organisation and of impact on the people affected by an AI system, documented and revisited.
Objectives and planning
What the organisation is trying to achieve with its AI governance, and the plan to get there.
Competence and awareness
The people involved know enough to do their part, and there is a record that they do.
Operational controls
The controls that actually run day to day: approvals, restrictions, human oversight, defined exceptions.
Supplier and third-party governance
Diligence over the vendors and models you depend on, and the terms you rely on.
Monitoring and measurement
Evidence that the system is working, not merely documented.
Internal audit
Periodic internal checking against the requirements, by someone able to be objective about it.
Management review
Leadership reviewing the system at planned intervals and recording the decisions taken.
Corrective action and continual improvement
Findings, incidents and gaps are worked, closed and used to change the system.
Two things follow from that list. First, most of it is record-keeping discipline rather than technical work. Second, an organisation that has already built an EU AI Act register has done a meaningful share of it without calling it that.
Where AI Register supports the work
Read this before the table
The mapping below indicates where the platform supports these management-system disciplines. It is not a claim of complete clause coverage of ISO/IEC 42001. A clause-level mapping has not yet been reviewed and documented, and we will not imply one until it has been. Using AI Register does not make an organisation certified, compliant, or ready for audit on its own.
| Management-system discipline | Where AI Register supports it |
|---|---|
| AI scope and inventory | A guided inventory of AI systems and use cases, with business unit, purpose and status recorded in one register. |
| Roles, responsibilities and accountability | A named owner and review date on every system, plus administrator roles and an append-only history of who changed what. |
| Risk and impact assessment | Structured classification against the EU AI Act taxonomy, with the rationale and legal basis recorded alongside the outcome. |
| Objectives, controls and treatment actions | An obligation and control register, with owners, evidence and status, so treatment actions are tracked rather than remembered. |
| Competence and AI-literacy evidence | AI policy attestations and Article 4 AI-literacy records, timestamped and exportable. |
| Supplier and vendor governance | Vendor due-diligence records held against the systems that depend on them, with vendor and product-change intelligence on the Assure tier. |
| Operational approvals and exceptions | Approval and periodic-review workflows, an exception register, and an agent decision-rights register for autonomous use. |
| Monitoring, incidents and review | An incident register, review dates that come due, and a register view that shows what has moved since last time. |
| Management review evidence | Board and customer-assurance exports, a quarterly board pack on the Assure tier, and director attestations written to an append-only trail. |
| Corrective action and continual improvement | Findings and actions carried on the register with owners and dates, and an append-only history recording how each position changed, with actor, timestamp and ruleset version. |
Feature availability differs by plan — the vendor, incident, attestation and board-review capabilities sit on the higher tiers. The pricing page sets out what each plan includes.
What the platform does not replace
- Your own decisions. The register records a position; it does not decide what risk your organisation is willing to carry.
- Competent people. A management system runs on people who understand the AI in use and have the authority to act on it.
- Legal advice. The platform provides general regulatory information and structured self-assessment, not advice on your legal position.
- An accredited certification audit. Certification is granted by a certification body after auditing your organisation. Software cannot confer it.
To be explicit, because this is where marketing usually overreaches: AI Register Ireland is not certified to ISO/IEC 42001, Acuity AI Advisory is not an accredited certification body, and no subscription to this product certifies anyone. Nor does the product guarantee compliance with the EU AI Act or any other law.
Preparing for an assessment? Read what should be in place before an ISO 42001 certification audit, including an original illustration of how a decision connects to operating evidence.
How certification actually works
Certification to ISO/IEC 42001 is granted by an accredited certification body following an audit of your organisation. Software cannot confer it, a consultant cannot confer it, and an internal declaration is not certification. The general shape of the route is consistent across ISO management-system standards:
- 1
Readiness
The management system is designed, implemented and operating: scope set, policy issued, roles named, risks and impacts assessed, controls running, records accumulating. Certification bodies expect to see a system that has actually been used, not one written the week before.
- 2
Internal audit
The organisation audits itself against the requirements, records findings, and works them. This is a requirement of the management system in its own right, not merely preparation.
- 3
Management review
Leadership reviews the system at a planned interval, considers performance, findings and changes, and records the decisions. This is usually the evidence an auditor asks for first.
- 4
Stage 1 audit
The certification body reviews the documented system and the organisation's readiness, and identifies anything that would prevent a full audit succeeding.
- 5
Stage 2 audit
The certification body audits the system in operation, testing whether what is documented is what actually happens. Findings are raised and must be addressed before a certificate issues.
- 6
Surveillance and recertification
Certification is not a one-off. The certification body returns on a periodic cycle to confirm the system is still operating, and the certificate is renewed after a further full audit at the end of the cycle.
Timelines, audit durations and cycle lengths vary by certification body and by the size and complexity of the organisation, so treat the sequence above as the shape rather than the schedule. Confirm the specifics with the certification body you intend to use, and check that it holds accreditation for this standard.
How Assure supports readiness and continuing review
Assure is the tier for organisations that want the register actively reviewed rather than merely hosted. It supports readiness and the ongoing review rhythm a management system needs — it does not, and cannot, deliver certification.
- An ISO/IEC 42001 gap and readiness view over your own register, showing where the management-system disciplines are supported by evidence and where they are not.
- A quarterly expert review of the register with Acuity, with the findings written down.
- A quarterly board pack drafted from the live register, plus director attestations recorded on an append-only trail.
- Proactive regulatory, vendor and product-change intelligence matched against the systems in your own register, with commentary on what to do.
- A named assurance lead: the review is led by Ger Perdisatt, a certified ISO/IEC 42001 Lead Auditor. That is his individual professional qualification — it is not a certification of your organisation, and it is not a substitute for an audit by an accredited certification body.
Assure · from €1,500 / month, from €18,000 billed annually
Get the register reviewed, quarter by quarter
An ISO/IEC 42001 gap and readiness view over your own register, a quarterly expert review, a board pack your directors can attest to, and proactive intelligence matched to the systems you actually run. Onboarded personally.
Request a briefingFrequently asked questions
ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation. It is a management-system standard, in the same family as other ISO management-system standards, and it is voluntary.
No. ISO/IEC 42001 governs how an organisation manages AI: scope, leadership, roles, risk and impact assessment, controls, monitoring, audit and improvement. Information security management is the subject of ISO/IEC 27001. SOC 2 is a controls assurance report produced by auditors, and penetration testing is a technical security assessment. They answer different questions and none of them substitutes for another.
No. The EU AI Act is law and creates obligations tied to your role and to the risk classification of each system, on published deadlines. ISO/IEC 42001 is a voluntary certifiable standard that gives you a management system for governing AI continuously. They are complementary: the Act sets the external compliance position, the standard gives you the internal operating system that keeps it current.
No. Certification is granted by an accredited certification body following an audit of your organisation. No software product can confer it, and AI Register does not. What software can do is hold the inventory, assessments, decisions and evidence that an audit will ask to see, and keep that record current between reviews.
No, and we do not claim to be. Acuity AI Advisory is not an accredited certification body and cannot certify anyone. Ger Perdisatt is a certified ISO/IEC 42001 Lead Auditor — that is an individual professional qualification held by a person, not a certification of AI Register, of Acuity, or of any customer.
Start with the same foundations the Act requires: a complete inventory of AI systems and use cases, a named owner for each, a documented risk and impact assessment, and an evidence trail that survives inspection. Those are also the foundations of an AI management system, which is why the two workstreams are worth running together rather than sequentially.
Statutory notice
This tool provides general regulatory information and structured self-assessment. It does not constitute legal advice. Seek professional advice for decisions with legal consequences.
Nothing on this page is a certification, an audit opinion, or a statement that any organisation meets ISO/IEC 42001. The full disclaimer applies.