Resources · 26 June 2026

ISO 42001 explained: does your UK business need the AI management standard?

By the Operating Bench Team · Last reviewed 26 June 2026

ISO/IEC 42001 is the first international standard for managing artificial intelligence, published at the end of 2023. If you have started to see it mentioned in tenders, client questionnaires or LinkedIn posts and wondered whether you need it, the honest answer for most UK businesses is: not the certificate, not yet, but you do need the discipline behind it. Here is what it is and what to actually do about it.

What ISO 42001 actually is

It is a management system standard, in the same family as ISO 27001 for information security and ISO 9001 for quality. It does not tell you which AI tools to use or what your policy should say word for word. It sets out how an organisation should govern its use of AI: define a policy, assign roles and responsibilities, assess the risks of your AI uses, put controls in place, monitor how it is working, and improve it over time. An accredited body can audit you against it and issue a certificate, much as they do for ISO 27001.

In plain terms, it is a recognised way to show, with evidence, that your AI use is managed rather than accidental.

Who actually needs certification

Certification earns its cost in specific situations:

If that is you, ISO 42001 is worth planning for. For the much larger group of UK businesses that simply use AI tools, such as ChatGPT, Copilot or an AI notetaker, full certification right now is usually premature and expensive. You would be paying to certify a management system you have not built yet.

The discipline matters even if the certificate does not

Strip away the audit and the standard is asking the questions any sensible business should answer anyway:

You can adopt the substance without the certificate. Doing so makes you defensible now, and gives you a running start if you ever decide to certify.

What to do first

For a UK business that uses AI, this is the practical order:

  1. Write a short AI policy that sets out what is allowed, what is not, and who is accountable.
  2. Decide your approved tools, and which data may go into each.
  3. Classify your data so staff can tell in seconds what is safe to put into an AI tool.
  4. Keep a risk register that names your real AI risks, with owners and controls.
  5. Name an owner for AI use, even if it is one person wearing several hats.
  6. Keep records, so you can show your reasoning if a client or regulator asks.

That is a defensible baseline in its own right, and it maps directly onto what ISO 42001 expects from a management system. If certification becomes a requirement later, you are building the foundation now rather than starting cold.

When to revisit it

Put ISO 42001 back on the agenda when a tender or major client asks for it, when you start embedding AI into what you sell, or when your use grows enough that “we manage it sensibly” needs to become “here is the certificate”. Until then, the foundation is the priority.

That foundation is exactly what our AI Safe-Use Pack gives you: the policy, the approved-tools matrix, the data-classification guide and the risk register, written for UK businesses. It will not certify you, and it does not claim to. It builds the managed, evidenced AI use that ISO 42001 is ultimately about. To dip a toe in first, the free AI Starter Kit covers the ground rules on a single page.

This article is general information, not legal or certification advice. Whether and how to pursue ISO 42001 should be decided with a qualified certification body or adviser.

Frequently asked questions

What is ISO 42001?
ISO/IEC 42001 is the first international standard for managing artificial intelligence, published in late 2023. It sets out how an organisation should govern its AI use: a policy, clear roles, risk assessment, controls, monitoring and improvement. An accredited body can audit you against it and issue a certificate.
Does a UK business need ISO 42001 certification?
For most UK organisations, not yet. Certification matters mainly if a client, tender or regulator specifically asks for it. What almost everyone does need now is the discipline behind it: a written AI policy, a risk view and clear ownership. Start there, and certify later if the demand appears.
Is ISO 42001 mandatory in the UK?
No. ISO 42001 is a voluntary standard, not law. UK GDPR and your sector regulator apply regardless. ISO 42001 is simply a recognised way to show, with evidence, that your AI governance is in order.

Sources & further reading

External links are provided for reference and open in a new tab. This article is general information, not legal advice.

Share this LinkedIn X

One email when it matters

A short note when the rules change or we publish something genuinely useful for UK organisations. No spam, unsubscribe in one click.