Compliance
ISO 42001
ISO/IEC 42001 artificial intelligence management system
ISO/IEC 42001 is the international standard for an artificial intelligence management system, published in 2023 as the first international management-system standard specifically for AI. It provides a structured framework for how an organisation governs the AI systems it builds, deploys, monitors, and continually improves, rather than addressing AI risk through ad hoc policy alone.
Why ISO 42001 matters in a Microsoft estate
ISO 42001 matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How ISO 42001 shows up in practice
Structurally, it follows the same management-system pattern as ISO 27001, covering leadership commitment, risk assessment specific to AI systems, defined objectives and controls, and a continual improvement cycle. That means an organisation already operating an ISO 27001 information security management system has a genuine, meaningful head start on 42001, since audit evidence, governance structures, and management review processes can often be extended and adapted rather than built again from nothing. The standard's AI-specific control areas address concerns that a general information-security standard does not directly cover: AI system impact assessment before deployment, evaluating potential harms to individuals, groups, and wider society; data quality and provenance for the data used to train and operate a system; transparency about when and how AI is being used, particularly where it materially affects individuals; and ongoing monitoring for model drift and performance degradation as real-world data and usage patterns diverge over time from the conditions a system was originally validated against.
For organisations building or deploying AI-driven products, whether an internally-used automation feature or an AI capability offered directly to customers, ISO 42001 certification is emerging as a genuine trust signal in commercial and public-sector procurement, in much the same way ISO 27001 became an expected baseline for information security over the preceding two decades. It gives customers a recognised, externally-audited framework for evaluating whether an AI system's development and operation are actually governed, rather than merely subject to an internal policy document nobody outside the organisation can independently verify.