Topic
AI Standards
Technical and management standards from ISO, IEC, IEEE, ITU and national bodies.
Last reviewed 2026-08-22
Overview
Standards can operationalize risk management and interoperability. They are usually voluntary until law or contracts say otherwise. Participation and whose requirements get encoded are governance questions, not only engineering questions.
AI governance certification: what ISO/IEC 42001 covers
ISO/IEC 42001 is the standard behind most current use of the phrase "AI governance certification": it specifies requirements for an AI management system, and an accredited certification body can audit an organization against those requirements and issue a certificate. What certification attests to is narrower than the phrase suggests. It confirms that a management system—documented policies, defined roles, a risk-assessment process, procedures for monitoring and improvement—exists and operates as specified; it does not certify that any specific model is safe, unbiased or legally compliant, and it does not replace conformity assessment required by binding law such as the EU AI Act's high-risk provisions. The standard addresses how an organization manages AI-specific risk across a system's lifecycle, similar in structure to how ISO 9001 organizes quality-management requirements or ISO/IEC 27001 organizes information-security requirements, rather than prescribing a fixed checklist for any single AI system. Procurement teams increasingly reference the standard when evaluating vendors, since it offers a documented, third-party-audited baseline instead of a vendor's own unverified claims—but a procurement requirement for "ISO 42001" should specify certification against the standard, not merely internal alignment with it, since the two carry very different levels of assurance.