Standards › ISO 42001

Certifiable standard

ISO 42001 — Artificial Intelligence Management

The international standard for AI management systems: governing how an organisation develops or uses AI responsibly — risk, impact, oversight and accountability.

What it covers

Governance of AI use: policy, roles, risk and impact assessment for AI systems, lifecycle controls, data considerations, transparency and human oversight.

Who it is for

Businesses deploying AI in ways that affect decisions about people or safety — including construction firms adopting AI tools for design review, progress monitoring, bid writing or safety analytics.

Key requirement themes

  • AI policy, roles and accountability
  • Inventory of AI systems and their intended use
  • AI risk and impact assessment before and during use
  • Lifecycle controls: data, development or procurement, monitoring, decommissioning
  • Transparency and human oversight proportionate to impact

Theme-level description in our own words — the standard itself defines the requirements, and no standard text is reproduced here.

Construction-sector relevance

If AI tools inform safety-relevant decisions — progress against temporary works sequences, plant proximity alerts, automated design checking — the governance question is "who is accountable and how is the tool validated?". ISO 42001 structures the answer.

Benefits

  • Documented accountability for AI-assisted decisions
  • Client and regulator questions answered with a system, not assurances
  • Discipline before AI becomes embedded and unexaminable

Common gaps we find

  • No inventory of AI already in use
  • Procurement without validation requirements
  • No human-oversight rule for safety-relevant outputs

Implementation process

  1. Gap analysis of current arrangements against the standard
  2. Prioritised closure plan with owners and dates
  3. Documents and registers built or adapted with the people who use them
  4. System operated: records, audits, review — evidence accumulating
  5. Readiness review and mock assessment
  6. Independent certification-body assessment (their decision, not ours)

Typical documents

  • AI policy
  • AI system inventory
  • Risk and impact assessments
  • Oversight and validation records

Typical evidence

  • Assessments preceding deployment
  • Monitoring records
  • Oversight decisions logged

Certification-readiness route

We take organisations to the point where an accredited certification body can assess them with confidence: gap analysis → implementation → operating evidence → internal audit and management review → readiness review. The assessment and the certificate belong to the certification body; our role ends at prepared-and-ready, and continues afterwards only as support.

Related standards

Certifiable standard

ISO 27001 — Information Security

The international standard for information security management systems: protecting the confidentiality, integrity and availability of the information you hold.

Certifiable standard

ISO 9001 — Quality Management

The international standard for quality management systems: consistent processes, controlled documents, measured performance and evidenced improvement.

Questions we are actually asked

We only use AI chat tools — does this apply?

A proportionate system can still be worthwhile: an inventory, a policy on what may and may not be delegated to the tools, and a rule about human review of outputs that matter.

Is ISO 42001 certifiable?

Yes — it is a requirements standard and certification schemes exist. Check that any certification body offering it holds appropriate accreditation.

Does it make AI outputs correct?

No standard can do that. It makes the organisation accountable for how it selects, validates and supervises the tools it uses.

Professional disclaimer: this page is orientation, not advice on your specific circumstances, and not a reproduction of any standard. Implementation support, templates and platform tools do not confer certification or legal compliance; certification decisions rest solely with independent certification bodies, and legal duties apply regardless of certification.