What ISO/IEC 42001 Asks of Your Organisation
- September 20, 2026
- Posted by: Ahmed Elrayes
- Category: Digital Transformation
Boards and executive committees across the GCC are being asked a new question: can you demonstrate that your use of artificial intelligence is governed? ISO/IEC 42001, published in December 2023, is the first international management system standard for AI, and it is quickly becoming the reference point for that answer. This article explains what the standard actually requires, in plain terms, for leaders in government, banking and similar institutions.
In brief
- ISO/IEC 42001 is the first certifiable international standard for managing AI
- Leadership owns it: policy, roles and resources, not just the IT department
- Four disciplines carry it: an AI inventory, risk and impact assessment, lifecycle governance and continual improvement
- It shares the harmonised structure of ISO 27001, ISO 20000 and ISO 22301, so it extends an existing integrated management system rather than duplicating it
- In the GCC it aligns naturally with the UAE AI Strategy 2031 and SDAIA guidance
- The right starting point is an honest maturity reading, not documentation
What the standard is
ISO/IEC 42001 defines the requirements for an Artificial Intelligence Management System, often shortened to AIMS. It follows the same structure as the management system standards most organisations already know, such as ISO 27001 for information security and ISO 9001 for quality. That familiarity matters: if your organisation has run a certified management system before, the discipline of ISO 42001 will feel recognisable, even though the subject is new.
The standard is certifiable. An organisation can be independently audited against it, which is why regulators, boards and large customers increasingly treat it as evidence rather than intent.
What it asks of leadership
The first and heaviest requirement sits with leadership. The standard expects top management to define an AI policy, assign clear roles and responsibilities for AI, and commit resources to governing it. AI governance cannot live solely inside the IT department. If the organisation deploys AI in credit decisions, citizen services or operations, accountability for its behaviour must be visible at the top.
What it asks of the organisation
Beneath leadership, the standard requires a small number of disciplines done consistently:
Know your AI. Maintain a clear view of where AI is used in the organisation, whether built in house, bought from vendors or embedded inside other products. Most organisations discover during this exercise that they have more AI in production than they believed.
Assess risk and impact. For each significant AI system, assess the risks to the organisation and the impact on the people affected by it: customers, citizens, employees. The AI impact assessment is one of the features that distinguishes ISO 42001 from earlier standards, and it aligns naturally with the expectations of regulators in the UAE and Saudi Arabia.
Govern the lifecycle. Define how AI systems are specified, developed or procured, tested, deployed, monitored and retired. Human oversight, data quality and transparency requirements belong in this lifecycle, not as afterthoughts.
Improve continually. Like every management system standard, ISO 42001 runs on the plan, do, check, act cycle. Incidents, audit findings and monitoring results feed back into the policy and the controls. The standard also provides an annex of reference controls that organisations select from and justify, similar in spirit to the control catalogue in ISO 27001.

Why it matters in the GCC now
The regional context makes the standard more relevant here than almost anywhere else. The UAE AI Strategy 2031 sets a national trajectory for AI adoption across government and priority sectors, and Saudi Arabia’s SDAIA has published guidance that expects responsible, governed use of AI. Organisations that adopt AI faster than they govern it accumulate a gap between what they deploy and what they can demonstrate. ISO 42001 is the most direct way to close that gap with something auditable.
How it fits with ISO 27001, ISO 20000 and ISO 22301
Most organisations that take ISO 42001 seriously already hold one or more of the established management system certifications. That is an advantage, not a complication. All four standards share the same harmonised structure, with common clauses for context, leadership, planning, support, operation and improvement, so an AI management system can be built as an extension of the integrated system you already run rather than as a parallel bureaucracy.
ISO 27001, information security. AI systems consume and produce sensitive information, so the security controls your organisation already operates underpin any credible AI deployment. The AI impact assessment required by ISO 42001 sits naturally beside the 27001 risk assessment, and mature organisations run the two as one exercise with one register.
ISO 20000, IT service management. An AI system in production is a live service. The change management, incident management and availability disciplines of 20000 are exactly what keep deployed models stable, and extending them to AI services is far easier than inventing new operational processes from scratch.
ISO 22301, business continuity. When critical services depend on AI, model failure, data pipeline breaks and vendor outages become continuity scenarios. The impact analysis and continuity planning of 22301 extend to cover them, so AI dependence is planned for rather than discovered during an incident.
The practical implication is one integrated audit programme, shared documentation and a single governance forum instead of four. For organisations already certified, ISO 42001 is usually a shorter journey than they expect.
Where to begin
The practical starting point is not documentation. It is an honest reading of where the organisation stands today: which AI is in use, who owns it, what governance already exists and where the gaps are. That reading tells you whether ISO 42001 adoption is a six month effort or a two year one, and which gaps deserve attention first.
See where your organisation stands
The Transformation Compass is a free self assessment, completed in about fifteen minutes, that reads your AI governance maturity against ISO/IEC 42001 with the regulatory context of the UAE and Saudi Arabia built in.