The short answer
The standard asks an organisation to know what AI it uses, decide who is responsible for it, assess the risks of each use, put controls in place that match those risks, keep records, and review the whole thing regularly. That is it, at the level that matters. Certification means an accredited body has audited that you do all of that and issued a certificate. Alignment means you do it, can show it, and do not claim the certificate. This site says “aligned” because that is what is true of us, and it is what we recommend for our clients.
What the standard actually contains
The annexes list the specific controls (policies, roles, data management, system lifecycle, third parties, and so on) and guidance for implementing them. Nothing in it tells you which model to use. All of it tells you how to be able to answer, in writing, the question “how do you manage this?”
- Context and leadership. Understand how AI affects your organisation and the people it serves; have leadership own the policy and assign responsibility.
- Planning. Identify the risks and opportunities of each AI use, and set objectives you can check.
- Support. Give the people involved the competence, awareness and information they need; keep documents under control.
- Operation. Assess the impact of AI systems on individuals and society, and put controls in place across the AI lifecycle, from design through operation to retirement.
- Performance evaluation. Monitor, measure, audit internally and review at management level.
- Improvement. Fix what the reviews find, and keep the system current as the technology and your use of it change.
Who actually needs certification
Organisations whose customers or regulators will require it: vendors of AI products selling into large enterprises or government, businesses in sectors where a supervisor has said so, and businesses whose contracts will demand it. If you are one of those, you will know, because someone will have asked. For everyone else, the certificate is a cost with no buyer on the other side of it.
Certification also takes time and money that most businesses would rather spend on the controls themselves. The standard is the description of good practice; the certificate is proof to a third party that an auditor checked. If nobody is asking for the proof, buy the practice.
What “aligned” means, and what it does not
Aligned means your AI policy, roles, risk assessments, controls, records and reviews are designed and reported against the structure of the standard, so that if a customer, insurer or auditor asks how you manage AI, you can show them, clause by clause, what you do. It means you could pursue certification later without starting again. It does not mean an accredited body has audited you, and it does not entitle anyone to use the certification mark or to say “ISO certified”.
A supplier who tells you they are certified when they are aligned has told you something about how they handle every other claim. Ask to see the certificate; they are issued by named bodies and are checkable.
How alignment looks in a business of fifty people
A two-page AI policy signed by a director. A list of the AI tools and systems in use, with an owner for each. A short risk assessment for each use that touches customers, money or personal information, and a note of the control chosen (a person approves, the data stays in the tenancy, the model provider does not train on it, the action is logged). A record of what the AI systems did, kept for as long as your other records. A review twice a year, minuted. That is alignment, and it is about a fortnight of work with the right help, then a few hours a quarter.
ISO/IEC 42001 and the NIST AI RMF
The NIST AI Risk Management Framework is the other reference you will see. It is a framework rather than a certifiable standard: four functions (govern, map, measure, manage) that describe how to think about AI risk. The two fit together well: the framework is a way of thinking, the standard is a way of organising. We report against both because clients’ customers ask about both, and because neither alone covers everything a board wants to know.
How it relates to ISO 27001 and the systems you already have
If your business already runs an information security management system aligned or certified to ISO/IEC 27001, most of the machinery is in place: leadership commitment, risk assessment, documented controls, internal audit, management review. ISO/IEC 42001 is built to slot beside it and to share that machinery, adding the AI-specific parts: the inventory of AI systems, impact assessments on the people affected, lifecycle controls for models and data, and oversight of AI suppliers. A business with neither standard gets both benefits from doing the AI one first, because the discipline transfers.
What an auditor would ask, even without a certificate
Show me the list of AI systems you use and who owns each. Show me the risk assessment for the one that touches customers. Show me the control you chose and the evidence it is working. Show me the record of what the system did last month. Show me the minutes of the last review. Those five questions are what alignment means in practice, and they are the questions an insurer, a large customer or a regulator will ask whether or not anyone has ever heard of the standard. Being able to answer them is the point; the certificate is a receipt.
Where to go from here
The AI Governance service on this site delivers the aligned set: policy, roles, risk assessment, controls, records and review, designed against ISO/IEC 42001 and the NIST AI RMF, and stated honestly as aligned. If a customer or regulator does require certification, we will say so and help you get there. The AI Opportunity Score below will tell you in five minutes whether governance is your first gap or your third.
Published 12 September 2026 · Be AI