ISO/IEC 42001, explained simply
ISO/IEC 42001 is the first management-system standard for artificial intelligence. It does not tell you which AI systems are allowed — it asks whether your organisation governs AI deliberately: policies, roles, risk assessment, and evidence that the system is actually run.
- Standard
- ISO/IEC 42001:2023 (AI management system)
- Version
- ISO/IEC 42001:2023
- Jurisdiction
- International (ISO/IEC)
- Catalogue last verified
- 2026-07-16
Who it is for
Any organisation that develops, provides or uses AI systems, at any size. It is certifiable: an accredited body audits you and issues a certificate. Unlike the EU AI Act it is voluntary — but the two overlap heavily, and buyers increasingly ask for it as shorthand for "you govern your AI properly".
What is actually in it
Tawsik tracks every requirement in the published catalogue, grouped by its official numbering.
60requirements tracked
- A. · 38
- Cl. · 22
What evidence can prove — and what it can’t
We would rather tell you this up front than let a dashboard imply more certainty than it has.
Where Tawsik fits
Tawsik is not a certification body. It measures your readiness against the standard from your own evidence, shows you exactly which clauses and Annex A controls are still open, and carries the overlap into your EU AI Act work so the same proof counts twice.
Tawsik is not a certification body or an auditor.
One set of evidence, every framework
Tawsik maps one canonical control to every framework that asks for it, so a proof you gather once counts everywhere it applies.
See where you stand
Start with the free EU AI Act check — no account, no email. Your workspace covers the rest.
Tawsik guides you toward compliance. It isn’t legal advice.