Resources · 26 June 2026
ISO 42001 explained: does your UK business need the AI management standard?
By the Operating Bench Team · Last reviewed 26 June 2026
ISO/IEC 42001 is the first international standard for managing artificial intelligence, published at the end of 2023. If you have started to see it mentioned in tenders, client questionnaires or LinkedIn posts and wondered whether you need it, the honest answer for most UK businesses is: not the certificate, not yet, but you do need the discipline behind it. Here is what it is and what to actually do about it.
What ISO 42001 actually is
It is a management system standard, in the same family as ISO 27001 for information security and ISO 9001 for quality. It does not tell you which AI tools to use or what your policy should say word for word. It sets out how an organisation should govern its use of AI: define a policy, assign roles and responsibilities, assess the risks of your AI uses, put controls in place, monitor how it is working, and improve it over time. An accredited body can audit you against it and issue a certificate, much as they do for ISO 27001.
In plain terms, it is a recognised way to show, with evidence, that your AI use is managed rather than accidental.
Who actually needs certification
Certification earns its cost in specific situations:
- You build or sell AI as part of your product or service.
- You deploy AI at meaningful scale, or in high-stakes areas.
- A large client or public-sector tender asks for it as a condition of doing business.
If that is you, ISO 42001 is worth planning for. For the much larger group of UK businesses that simply use AI tools, such as ChatGPT, Copilot or an AI notetaker, full certification right now is usually premature and expensive. You would be paying to certify a management system you have not built yet.
The discipline matters even if the certificate does not
Strip away the audit and the standard is asking the questions any sensible business should answer anyway:
- Do you know where AI is used across the organisation?
- Have you assessed the risks of those uses?
- Is there a policy, and does someone own it?
- Are there controls, and do you keep records?
You can adopt the substance without the certificate. Doing so makes you defensible now, and gives you a running start if you ever decide to certify.
What to do first
For a UK business that uses AI, this is the practical order:
- Write a short AI policy that sets out what is allowed, what is not, and who is accountable.
- Decide your approved tools, and which data may go into each.
- Classify your data so staff can tell in seconds what is safe to put into an AI tool.
- Keep a risk register that names your real AI risks, with owners and controls.
- Name an owner for AI use, even if it is one person wearing several hats.
- Keep records, so you can show your reasoning if a client or regulator asks.
That is a defensible baseline in its own right, and it maps directly onto what ISO 42001 expects from a management system. If certification becomes a requirement later, you are building the foundation now rather than starting cold.
When to revisit it
Put ISO 42001 back on the agenda when a tender or major client asks for it, when you start embedding AI into what you sell, or when your use grows enough that “we manage it sensibly” needs to become “here is the certificate”. Until then, the foundation is the priority.
That foundation is exactly what our AI Safe-Use Pack gives you: the policy, the approved-tools matrix, the data-classification guide and the risk register, written for UK businesses. It will not certify you, and it does not claim to. It builds the managed, evidenced AI use that ISO 42001 is ultimately about. To dip a toe in first, the free AI Starter Kit covers the ground rules on a single page.
This article is general information, not legal or certification advice. Whether and how to pursue ISO 42001 should be decided with a qualified certification body or adviser.