UCS - Universal Certification and Services
HomeBlogsISO/IEC 42001 Certification: A Complete Guide for Organizations
guide

ISO/IEC 42001 Certification: A Complete Guide for Organizations

ISO/IEC 42001 is the first international management system standard for artificial intelligence. This guide covers what it requires, who it applies to, how certification works from application to certificate, what it costs you in effort, and the things it deliberately does not promise. Written for organisations in Angola.

UCS
27 July 2026
9 min read

ISO/IEC 42001:2023 is the first international management system standard written for artificial intelligence. It was published in December 2023 by ISO and IEC, and it does for AI governance what ISO 9001 did for quality: it sets out what a management system has to contain, and lets an independent body check that yours does.

This guide covers what the standard requires, who it applies to, how certification works in practice, and what it deliberately does not do. It is written for organisations in Angola deciding whether to pursue it.

What ISO/IEC 42001 actually is

It is a management system standard, not a technical standard for AI models. It says nothing about which architecture to use, what accuracy to reach, or which tools to buy. What it asks is whether your organisation has a deliberate, documented, reviewed way of deciding how AI gets built, bought, deployed and watched.

The system it describes is called an AI management system, usually shortened to AIMS. If you already hold ISO 9001 or ISO/IEC 27001, the shape will be familiar, because ISO uses a common structure across its management system standards. Context, leadership, planning, support, operation, performance evaluation, improvement. What changes is what goes inside each of those.

Who it applies to

ISO describes the standard as intended for organisations providing or using AI based products and services. Read that carefully, because it is broader than most people expect. Three groups are in scope:

  • Organisations that develop AI. The obvious case.
  • Organisations that provide AI to others. Including where you embed somebody else's model in your product.
  • Organisations that simply use AI. The group most likely to assume it is not in scope. If an AI system is making or shaping decisions inside your business, your use of it is what gets assessed.

Size and sector do not matter. The standard is written to apply to any organisation, and the scope you declare is what determines how much work it is.

What the standard requires, clause by clause

ISO/IEC 42001:2023 runs from clause 4 to clause 10, with annexes. Here is what each part is asking for.

Clause 4, Context of the organization

Understand the internal and external issues that bear on your use of AI, and the interested parties who care about it. Then set the scope of the AI management system, which names the AI systems, activities and sites covered. This is the sentence that ends up on the certificate, and it is the single most consequential thing you write.

Clause 5, Leadership

Top management has to own this, not delegate it into a corner. The clause calls for an AI policy and for roles, responsibilities and authorities to be assigned. Auditors look for who is empowered to stop an AI deployment, not just who is listed on a chart.

Clause 6, Planning

Actions to address risks and opportunities, AI objectives and the plans to reach them, and planning of changes. Objectives written so they cannot be measured are a recurring weakness here, because clause 9.1 then has nothing to monitor.

Clause 7, Support

Resources, competence, awareness, communication, and documented information. Competence matters more than it sounds: the people making AI decisions have to be demonstrably capable of making them.

Clause 8, Operation

This is the AI specific heart of the standard.

  • 8.1 Operational planning and control
  • 8.2 AI risk assessment, what could go wrong for the organisation
  • 8.3 AI risk treatment, what you decided to do about it
  • 8.4 AI system impact assessment, who is affected by the system and how severely

Clause 8.4 has no equivalent in ISO 9001 or ISO/IEC 27001, and it is where organisations with a strong management system background still arrive under-prepared. We cover it on its own in AI impact assessment requirements under ISO/IEC 42001.

Clause 9, Performance evaluation

Monitoring and measurement, internal audit, and management review. Both of the last two have to have actually happened before certification, not be scheduled for afterwards.

Clause 10, Improvement

Continual improvement, and nonconformity and corrective action. What caused each problem, and what you changed so it does not recur.

The annexes

Annex A holds reference control objectives and controls. Annex B gives implementation guidance across areas such as policies related to AI, internal organization, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third party and customer relationships. Annex C covers potential AI related objectives and risk sources, and Annex D deals with using the AI management system across domains and sectors.

Your system has to show which Annex A controls apply to you, which do not, and why.

What documentation you will need

The standard states requirements rather than listing file names, so there is no fixed set of documents and you should treat any article that gives a confident number with caution. What you will need follows from the clauses: a scope, an AI policy, objectives, competence records, risk and impact assessments, internal audit reports, management review minutes, and records of nonconformities.

The full breakdown is in documents required for ISO/IEC 42001 certification.

How certification works

At UCS the route runs in this order, and it is set out in full on our ISO certification process page:

  1. Application. You submit an application to start the process.
  2. Certification Agreement. Scope, terms and the audit programme are agreed.
  3. Stage 1 Audit. A thorough review of your documentation, processes and overall readiness against the standard.
  4. Stage 1 Audit Report. Written findings, while there is still time to act on them.
  5. Stage 2 Audit. The full assessment, where you document how the system complies by using objective evidence.
  6. Final Report and Certification. Any nonconformities identified at Stage 2 must be addressed before certification is formally granted.
  7. Surveillance audits, carried out annually thereafter.

The certificate is not the end of the work. Surveillance means the records have to keep accumulating, and a system that goes quiet the week after the certificate arrives will show at the first surveillance visit.

What certification does not do

Worth stating plainly, because the marketing around AI governance rarely does.

  • It does not certify your AI models. It certifies the management system around them. A certified organisation can still ship a model that performs badly; what it cannot do is ship one without having governed the decision.
  • It does not make you legally compliant. It is a voluntary international standard, not legislation, and it substitutes for no legal obligation anywhere.
  • It promises no particular outcome. No management system standard does, and no certification body is permitted to offer one.
  • It does not transfer responsibility. The decisions your AI systems make remain yours.

Who writes the system, and who audits it

You write it, or an adviser you appoint writes it with you. Your certification body audits it. Those two roles cannot be the same organisation.

UCS operates as an accredited certification body under ISO/IEC 17021-1:2015, which requires impartiality towards the organisations we certify. We do not design AI management systems, write policies or produce impact assessments for clients we then assess. Reading a system and reporting what is missing is a different activity and is permitted, which is what a Stage 1 audit is. Any body offering to build the system and certify it is offering a certificate that a serious client can take apart.

ISO/IEC 42001 certification in Angola

The standard does not change from one country to another, so what follows is about how the decision tends to look on the ground in Angola.

It is a voluntary standard, not Angolan law. Certification is evidence that you run an AI management system meeting an international standard. It settles no legal obligation, and it is not a licence to operate. Where a regulator, a client contract or a tender in Angola imposes its own duties on your use of AI, those continue to apply and need their own legal advice.

Most of the organisations asking about it are users of AI, not builders of it. The standard covers organisations that develop, provide or use AI based products and services, and the third of those is the one most often overlooked. If you have licensed an AI screening tool, an AI chatbot or an AI analytics product, your use of it sits inside scope.

A common trigger is somebody else asking. An enterprise client's procurement questionnaire, a tender that asks how AI decisions are governed, or a parent company setting a group requirement. Certification is a way of answering all of them once, in a form the person asking can check independently.

Frequently asked questions

How long does ISO/IEC 42001 certification take?

That depends almost entirely on the state of your management system when you start, and on the scope you declare. The audit stages themselves are scheduled around your readiness, which is what the Stage 1 review establishes. Ask for an indication once your scope is settled rather than before.

Do we need ISO/IEC 27001 first?

No. They are separate certifications with separate scopes and neither is a prerequisite for the other. Organisations that already hold ISO/IEC 27001 usually find the management system mechanics familiar, which is not the same as being ready.

Can we certify only part of the business?

Yes, and most organisations do. That is what the scope statement in clause 4.3 is for. Be honest in it: a scope that names two AI systems when the auditor finds five in use is the first thing that has to be resolved.

How long is the certificate valid?

Certification runs on a three year cycle with annual surveillance audits and recertification at the end of the cycle.

What happens if we fail the Stage 2 audit?

Nonconformities are raised in writing and have to be addressed before certification is granted. That is the mechanism working as intended rather than a failure state, which is also why Stage 1 exists.

Does certification cover AI tools we bought from vendors?

Your use of them, yes, where they fall inside your declared scope. The vendor's own arrangements cover the vendor's context, not yours.

Next steps

Our ISO/IEC 42001 certification page sets out the standard and how certification works in Angola. To discuss your scope with an auditor, request a free assessment or contact UCS on +244 935 793 270.

ISO 42001AI management systemAI governanceCertificationAIMS

Ready to Get ISO Certified?

Get a free assessment and tailored quote within 3–4 hours.

1000+ Businesses Certified
7–10 Day Certification
Quote in 3–4 Hours
UCS Assistant
Online — Typically replies instantly
Book a 15-Min Call
Speak directly with our certification team.
Powered by UCS