Live 16 practitioner certifications live · First lesson free on every course Back to main site →

What ISO/IEC 42001 actually is, and why 2026 turned it into a procurement gate

Let me start the way most CIOs and Heads of AI actually start with this standard — with a customer or a regulator asking for a certificate they have never heard of. This lesson walks what ISO/IEC 42001:2023 actually is, where it sits in the ISO family, and why 2026 turned it from optional to line item on procurement questionnaires.

Free preview 12 min read Under review
Legal basis
ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.

Let me start where most Indian CIOs and Heads of AI actually start with this standard. I want to tell you about a conversation I had earlier this year with a Bengaluru CTO. Smart engineer. Ten years at a good company. Just been made CTO of a mid-size B2B SaaS. They had built a working product with three AI features baked in — a customer support co-pilot, an anomaly detector in the analytics dashboard, and a natural-language query interface for the reporting module. They were in the second round of a tender for a large European bank. Multi-year contract. Big deal for them.

The European bank's procurement team sent a compliance questionnaire. On page four, item 3.1 said: "Provide a copy of your current ISO/IEC 42001:2023 certificate for the AI Management System covering the AI capabilities embedded in the offered solution." The CTO called me. He said, "I know ISO 27001. I have a SOC 2 Type II. What is ISO 42001?" I told him. He said, "How long does it take to get?" I told him: twelve to eighteen months, first time. He looked at the calendar. The bank's decision was in ninety days. The deal died on Item 3.1.

That story is the beginning of why this course exists. Through 2024 and 2025, ISO 42001 was an optional badge that most Indian companies had not heard of. Through 2026, it has quietly become a procurement gate for anyone selling AI-enabled anything to a European or American enterprise buyer. If your organisation deploys AI in production, and if your customers are enterprise or your regulators are SEBI, RBI, IRDAI or CERT-In, this standard is going to land on your desk. Better to see it coming than to see it kill a tender.

What ISO/IEC 42001 is, in one paragraph

ISO/IEC 42001:2023 is the international standard for an AI Management System. It was published on 18 December 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) jointly, through Subcommittee 42 of Joint Technical Committee 1 — which is the ISO/IEC committee that also produces the ISO 22989 AI terminology standard and the ISO 23894 AI risk management guidance standard [L1-C1]. It sets out requirements for establishing, implementing, maintaining and continually improving an AI Management System within an organisation that develops or uses AI. The certificate is not self-issued. An organisation demonstrates conformity by passing a two-stage audit performed by a certification body that is itself accredited by a national accreditation body that is itself a signatory to the IAF Multilateral Recognition Arrangement. The certificate is valid for three years. It covers a defined scope — the AI systems, teams and processes covered by the AIMS — not the whole organisation by default.

Read that paragraph again carefully. It contains four concepts that new practitioners routinely mix up. Let me draw them apart clearly, because if you do not have this distinction firmly in your head, you will spend the next twelve months making the same mistake in every conversation.

  • The standard — ISO/IEC 42001:2023 — is the document that says what an AIMS must contain. ISO sells you the PDF. It costs about CHF 168.
  • The AI Management System (AIMS) — that is the actual thing you build in your organisation. Policies, roles, processes, documented information, running cadences. It is what the standard describes.
  • The certificate — that is the piece of paper an accredited certification body (CB) issues you after your AIMS has passed a two-stage audit.
  • The accreditation chain — that is the chain of authority (ISO/IEC publishes standard, IAF signs the Multilateral Recognition Arrangement, national accreditation body accredits the CB, CB audits you, CB issues certificate). Without the accreditation chain, the certificate is a piece of paper that means nothing.

When your European buyer asks for "the certificate," they mean the fourth item. But you cannot skip to the fourth item. You have to build the second item first. And you have to pick a CB from the third item that is accredited under the first item. The whole system only works if all four pieces connect. This course walks each piece in turn.

Why 2026 changed the game

ISO 42001 was published in December 2023. Through 2024 it was mostly a topic of conference talks. Through 2025 the early enterprise adopters started certifying — Mphasis was the first Indian IT services firm to publicly hold the credential [L1-C10]. KPMG India got certified by SGS in December 2025 [L1-C11]. That was already unusual for the Big Four, who often audit certifications rather than hold them.

Four things happened in 2025 and 2026 that turned the temperature up. Let me walk them in order because you need this context to understand why your customer is now asking.

First: MeitY published the India AI Governance Guidelines in November 2025

These Guidelines were released by the Ministry of Electronics and Information Technology in November 2025 ahead of the India AI Impact Summit that Bharat hosted in February 2026 [L1-C3]. The Guidelines are non-binding. They are principle-driven. But they explicitly recommend, in Annexure 6, that Indian organisations align with ISO/IEC 42001 as the operational management-system standard. When MeitY names a specific ISO standard in an official Guidelines document, procurement teams inside PSUs, government contractors, and any organisation that responds to central-government tenders start listing that standard as a requirement.

Second: MeitY notified the IT Amendment Rules 2026 on 10 February 2026

These Rules became effective on 20 February 2026 [L1-C4]. They amended the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules of 2021 to introduce a new due-diligence category called Synthetically Generated Information (SGI). Every intermediary — which means, in practice, every social platform, search engine, e-commerce marketplace, hosting provider and cloud storage service — must now clearly and prominently label AI-generated content, embed metadata identifying the computer resource that generated it where feasible, and comply with expedited takedown timelines. Non-consensual synthetic intimate content and CSAM must be taken down in 2 to 3 hours, not the earlier 24-36 hour window. Organisations that deploy AI to generate content — even non-intermediaries who supply the generative tools — now need to think about labelling as part of their AI governance. ISO 42001 Annex A.8 (Information for interested parties) becomes the operational hook.

Third: SEBI issued the 5 May 2026 AI Advisory

SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 is addressed to every category of regulated entity in the Indian securities market — exchanges, depositories, brokers, mutual funds, custodians, credit rating agencies, merchant bankers, portfolio managers, investment advisors, everyone [L1-C5]. It was triggered by a specific incident involving an advanced AI-driven vulnerability detection tool called Mythos. SEBI recognised that AI tools now cut both ways — attackers use them to find and exploit vulnerabilities at machine speed, and defenders use them for the same purpose. The Circular constituted a task force called Cyber-suraksha.ai and mandated a set of cybersecurity strengthening measures. If your organisation is a SEBI-regulated entity and it uses AI in customer-facing or infrastructure roles, you now have a regulator-issued requirement to demonstrate your AI risk management, not just your cybersecurity. ISO 42001 is the cleanest operational fit for that demonstration.

Fourth: the RBI FREE-AI Committee Report was released in August 2025

On 13 August 2025 the Reserve Bank of India released the report of its Committee on the Framework for Responsible and Ethical Enablement of Artificial Intelligence, chaired by Professor Pushpak Bhattacharyya of IIT Bombay [L1-C6]. The report is technically not a binding master direction — it is a committee report — but you already know how RBI works. The Master Direction that follows a committee report of this weight is usually a matter of when, not whether. The report structures itself around seven guiding sutras and 26 recommendations across six pillars: Infrastructure, Policy, Capacity, Governance, Protection, Assurance. If you are a regulated entity in BFSI, you should treat this as the shape of what is coming. And ISO 42001 is again the cleanest operational fit for the Governance and Assurance pillars.

Add these four together and you can see what your European buyer, your SEBI regulator, your RBI regulator, and now your government-tender procurement team have all started asking about at roughly the same time. This is not coincidence. AI has crossed the threshold from novelty to system-critical, and every serious regulator and every serious buyer is now catching up. ISO 42001 is the international management-system standard that everyone converges on because it exists and is certifiable and other things (NIST AI RMF, EU AI Act) are either non-certifiable frameworks or hard-law regulations rather than operational management systems.

Who this course is for, and what you will actually be able to do at the end

This is a working practitioner course. It is written for the Indian CIO, CISO, Head of AI, Head of Data Science, DPO or General Counsel who has to build, run and pass a first-time ISO 42001 certification of an AI Management System in their organisation. It is written the way a senior advocate teaches a student, not the way an ISO PDF is translated. I will walk you through every clause of the standard, every one of the 38 Annex A controls, the AI Impact Assessment methodology from ISO 42005:2025, the AI risk management methodology from ISO 23894:2023, the Statement of Applicability, the certification body selection, the Stage 1 and Stage 2 audits, the surveillance cycle, and — this is the part most classroom courses will not touch — the whole India regulatory overlay that sits on top of the ISO baseline.

At the end of this course, you should be able to sit down in front of an executive team and say: "Here is what ISO 42001 requires. Here is the twelve to eighteen month path to certification. Here are the ten templates we lift straight into implementation. Here is the audit body I recommend. Here is the India regulatory overlay we build alongside. Here is what it costs and here is what we get for it." That is the practical capability this course exists to build.

Next lesson, I want to zoom out and place ISO 42001 in the ISO family — because you are going to run into ISO 27001, ISO 27701, ISO 23894 and ISO 42005 in this work, and you need to know how they connect. Then we will place it against NIST AI RMF and the EU AI Act, so you know which one your customer actually wants when they say "AI governance."

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 42001:2023, ISO/IEC 42001:2023 (Dec 2023 first edition) (AI management systems Requirements) L1-C1
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. First edition published 18 December 2023 by ISO/IEC JTC 1/SC 42 (AI subcommittee). The worlds first international management-system standard specifically for artificial intelligence. Structure: ten main clauses (0 Introduction through 10 Improvement) following the Annex SL harmonised structure shared with ISO 27001 and ISO 9001, plus Annex A (38 controls across 9 control groups A.2 through A.10), Annex B (implementation guidance for Annex A controls), Annex C (potential AI-related organisational objectives and risk sources), and Annex D (using an AIMS in specific domains).
MeitY AI Governance Guidelines, India AI Governance Guidelines Nov 2025 (Seven sutras + six pillars) L1-C3
MeitY released the India AI Governance Guidelines in November 2025. Techno-legal principle-driven approach anchored by seven sutras: Trust, People-first governance, Innovation over restraint, Fairness and equity, Accountability, Understandability by design, Safety-resilience-sustainability. Six pillars: Infrastructure, Capacity building, Policy and regulation, Risk mitigation, Accountability, Institutions. Non-binding but reflects governmental direction. Annexure 6 recommends ISO/IEC 42001 as the operational management-system standard for organisations.
IT Amendment Rules 2026, IT Rules Amendment 2026 SGI (SGI due-diligence obligations) L1-C4
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 were notified on 10 February 2026 and became effective 20 February 2026. Rule 3(1)(v) introduces Synthetically Generated Information (SGI) as a due-diligence category. Non-prohibited AI-generated content must be clearly and prominently labelled (visual for visual, audio for audio). Metadata must be embedded to trace the computer resource where feasible. Takedown timelines for harmful content reduced from 24-36 hours to 2-3 hours.
SEBI Circular 5-May-2026, SEBI Advisory 5-May-2026 Mythos (AI vulnerability detection advisory) L1-C5
SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 addressed to every regulated entity in the Indian securities market (exchanges, depositories, brokers, mutual funds, custodians, credit rating agencies, merchant bankers, portfolio managers, investment advisors). Response to advanced AI-driven vulnerability detection tools such as Mythos. Requires strengthened cybersecurity, immediate patch management, AI-assisted vulnerability assessments, enhanced API security, continuous SOC monitoring, system hardening and onboarding with the centralised Market SOC platform. Established the Cyber-suraksha.ai task force.
RBI FREE-AI Report, RBI FREE-AI Report 13-Aug-2025 (Bhattacharyya Committee framework) L1-C6
Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay, released 13 August 2025. Seven guiding sutras and 26 recommendations across six pillars: Infrastructure, Policy, Capacity, Governance, Protection, Assurance. Non-binding today; sets RBI direction for future master directions applicable to banks, NBFCs, HFCs, AIFIs and payment system operators.
Public ISO 42001 Certification, Mphasis first Indian IT services ISO 42001 (Mphasis 2025 certification) L1-C10
Mphasis became the first Indian IT services firm publicly known to hold ISO/IEC 42001:2023 certification. Widely covered in Indian IT trade press through 2025 as the beginning of an Indian IT services rush to certify. Public reference point when illustrating that certification of Indian services companies is operationally feasible today.
Public ISO 42001 Certification, KPMG India ISO 42001 by SGS Dec 2025 (KPMG India certification) L1-C11
KPMG India obtained ISO/IEC 42001 certification from SGS in December 2025. Referenced in Indian trade press for illustrating the audit-firm-doing-its-own-certification recursion and the growing adoption of ISO 42001 across the Big Four in India.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: What ISO/IEC 42001 actually is, and why it turned into a procurement gate in 2026
Module 2: Reading Clauses 4, 5 and 6: Context, Leadership and Planning
  • Clauses 4.1 and 4.2: understanding your context and identifying interested parties
  • Clause 4.3: writing an AIMS Scope Statement that a certification body will accept
  • Clause 5: Leadership, AI Policy and Roles — where an AIMS becomes real
  • Clause 6.1: the AI risk assessment methodology — the beating heart of the AIMS
  • Clauses 6.2 and 6.3: AI objectives and planning of changes
Module 3: Reading Clauses 7, 8, 9 and 10: Support, Operation, Performance evaluation, Improvement
  • Clauses 7.1 to 7.4: Resources, Competence, Awareness, Communication
  • Clause 7.5: Documented information — what must be in writing, and how it is controlled
  • Clause 8: Operation — executing the risk methodology and running the AIIA
  • Clause 9: Performance evaluation — monitoring, internal audit, management review
  • Clause 10: Continual improvement, nonconformity and the CAPA process
Module 4: Annex A controls Part 1: A.2 Policies, A.3 Internal organisation, A.4 Resources, A.5 Impact assessment
  • Annex A.2 — Policies related to AI: three controls that anchor the AIMS
  • Annex A.3 — Internal organisation: AI roles and the concerns-reporting channel
  • Annex A.4 Part 1 — Data and tooling resources (A.4.2 and A.4.3)
  • Annex A.4 Part 2 — Compute, human and financial resources (A.4.4 to A.4.6)
  • Annex A.5 — AI Impact Assessment: the four controls that decide whether an AIMS is real
Module 5: Annex A controls Part 2: A.6 AI lifecycle, A.7 Data, A.8 Information, A.9 Use, A.10 Third-party
  • Annex A.6 Part 1 — AI lifecycle: requirements, design and development
  • Annex A.6 Part 2 — Verification, deployment, operation, monitoring and event logs
  • Annex A.7 — Data for AI systems: five controls with the DPDP overlay
  • Annex A.8 — Information for interested parties: where the IT Rules 2026 SGI obligations land
  • Annex A.9 and A.10 — Responsible use of AI systems and third-party relationships
Module 6: Building the AIMS end-to-end: inventory, impact assessment, risk assessment, Statement of Applicability, tooling
  • Building the AI system inventory — the foundation everything else hangs on
  • Running an AI Impact Assessment per ISO/IEC 42005:2025 — the operational template
  • Running the AI risk assessment methodology per ISO/IEC 23894:2023
  • Building the Statement of Applicability — the single most-audited document
  • GRC tooling landscape — buy versus build for an AIMS
Module 7: Certification body selection, Stage 1 audit, Stage 2 audit, certificate issuance
  • The accreditation chain — why the certificate means anything, and where NABCB stands on ISO 42001
  • CB selection — the RFP process, scoring criteria and negotiation
  • Stage 1 — the documentation review: what the auditor tests and how to pass first time
  • Stage 2 — the operating-effectiveness audit: sampling, interviews, evidence
  • The three-year sustain cycle — surveillance, recertification and living with the certificate
Module 8: The India overlay + the next five years: AI Governance Guidelines, IT Rules 2026, SEBI, RBI FREE-AI, DPDP, EU AI Act, NIST AI RMF
  • The India AI Governance Guidelines in operational depth — the seven sutras and six pillars, clause by clause
  • IT Amendment Rules 2026 SGI obligations in operational depth — the first binding AI law in India
  • Sector-specific overlays — SEBI 5-May-2026, RBI FREE-AI, and the wider sectoral picture
  • DPDP intersection with AI, and EU AI Act extraterritorial reach on Indian exporters
  • NIST AI RMF crosswalk and the next five years — closing the course