ISO/IEC 42001: govern the AI of your organization.
The first certifiable standard for AI management systems: how your organization develops, provides or uses artificial intelligence, with evidence and human oversight.

Five key clauses.
ISO/IEC 42001:2023 sets requirements for an AI management system (AIMS). Each clause opens up what the organization has to be able to show.
Document declaring principles, scope and responsible parties. It is the anchor of the AIMS.
Organizations that develop AI products, integrate third-party models, use AI in critical decisions, or need to prepare governance evidence for regulatory and client requirements.
Measure your starting point.
Eight statements to review the scope, responsibilities, risks, and evidence of AI governance. The answers remain in the browser of the person who enters them.
An inventory of AI systems and use cases under the organization's responsibility exists.
Each AI system has a documented purpose, a responsible party, and usage limits.
Risks and impacts are assessed before introducing or changing an AI system.
There are criteria for data, suppliers, third-party models, and human oversight.
Relevant decisions, changes, incidents, and exceptions are recorded.
The people who operate or oversee AI know their responsibilities.
Performance is monitored and action is taken when deviation, harm, or unintended use appears.
Leadership reviews objectives, risks, and evidence of AI governance.
The questionnaire organizes the starting point, but does not examine evidence or know the organization's context. That reading is done by a member of the team, with the scope and AI systems in view. The questionnaire's answers are not attached on their own: the person writing decides what to share.
Human reviewThe answers stay in the browser of whoever writes them: they are not sent, not saved, and no result is published. Sharing information with G-CERTI is a separate decision, with its own form.The regulations that require it.
The European AI Regulation already applies its transparency obligations as of August 2, 2026. For an exporter, this is an indirect market requirement. The standard is mapped against that framework, not a replacement for it: it does not grant a presumption of conformity.
Training to audit ISO/IEC 42001.
Three academic paths on artificial intelligence governance: interpreting the requirements, auditing the system from the inside, and covering both in an integrated way. The path is academic and does not implement an organization's system.

Interpret the requirements of the AI management system and translate them into policy, roles, impact assessment and lifecycle.

Plan and carry out internal audits of the AIMS: evidence, findings and follow-up.

The integrated path: system design, internal audit and lead auditor, with three training certificates.
See the ISO/IEC 42001 Diploma ProgramG-CERTI Formación works on interpretation, exercises and internal audit through a common program. It does not design or implement an organization's system within this path.
An organization that later inquires about certification enters through a different file. Before quoting, scope and impartiality are reviewed; any incompatible advisory work blocks the certification path.
The policy that keeps the two files, their teams and their decisions separate is published in the Trust Center.
See the separation policyThe most frequently asked questions.
Start with the diagnosis.
The self-assessment brings together scope, responsible parties, risks, and evidence in one place. It helps decide what information to move forward with, not to declare conformity.
THE ASSESSMENT IS COMPLETED IN THE BROWSER AND ITS RESULT IS NEITHER SENT NOR SAVED. REQUESTING A HUMAN REVIEW IS A SEPARATE DECISION, WITH ITS OWN FORM AND RECEIPT.