I often get the same set of questions. Is ISO 42001 like ISO 27001? What about NIST? What about the European regulation? The short answer: ISO 42001 is the management system, the one a certification body can audit. The related standards around it do not say the same thing. Some give you a vocabulary. Others give you a method for impact or risk. Others speak to your board, or only to the auditor.

If you do not yet have a list of the AI tools actually used in the company, start with ISO 42001: what you need to know before you start. This piece assumes you already know why 42001 exists. It is here so you do not buy fifteen documents to fill the same hole.

42001 is the system. The rest is the toolbox

ISO/IEC 42001:2023 sets the requirements to establish, implement, maintain and improve an AI management system. It applies to any organization that develops, provides or uses AI-based products or services.

It uses the same high-level structure as ISO 27001 (context, leadership, planning, support, operation, evaluation, improvement). That is why you can integrate them without inventing a second parallel manual. The content is not the same.

I am not restating the nine Annex A families here. I already put them in SMB language in the article on getting started. If you only use ChatGPT, Claude or Gemini as SaaS, part of those controls does not apply to you: that is this article.

ISO 27001 is not ISO 42001

ISO 27001 protects the confidentiality, integrity and availability of information. ISO 42001 asks different questions: fairness, explainability, day-to-day use, impact on people. An AI system can meet every information-security rule you have and still be biased, opaque or poorly governed.

The two complement each other. One does not replace the other. If you already have an ISMS, you are not “covered for AI.” You have a base to document, audit and improve. You still have to govern the AI itself.

The 42000 family

Three standards share the 42000 prefix. They are not written for the same people.

ISO/IEC 42001:2023: the management system

This is the one you certify. Policy, roles, risks, controls, review, improvement. When someone asks “are you ISO 42001?”, they mean this one.

ISO/IEC 42005:2025: impact assessment

Published in May 2025. It describes how to assess the impact of an AI system on people, groups and the organization, across the life cycle. It is not a second management system. It is the method for work 42001 already asks you to do on higher-risk tools.

In the getting-started article, I gave five simple criteria (a person, personal information, a decision with no human review, strategic data, operational dependence). 42005 is the structured version of that reflex, for your most sensitive projects.

ISO/IEC 42006:2025: for certification bodies, not for your SMB

Published in July 2025. It complements ISO/IEC 17021-1: extra requirements for bodies that audit and certify an AI management system against 42001.

You do not implement 42006. It helps if you choose an auditor: can the body actually audit AI, not just 27001 with a new logo on the cover page? For how audits are conducted in general, I point to ISO 19011.

Vocabulary, machine learning, risk

ISO/IEC 22989:2022: agree on the words

This is the vocabulary. “AI system,” “provider,” “user,” “training data”: if three departments use three definitions, your policy will not hold. 22989 exists for that. It is 2022, not 2023.

You do not certify it. You do stop talking about AI as if everyone meant the same thing.

ISO/IEC 23053:2022: framework for machine learning

Useful if you train a model, or if you build an application on top of a model. Less useful if employees paste text into ChatGPT and copy the answer. In that second case you are a user: see the article on controls that do not apply.

ISO/IEC 23894:2023: managing AI risk

This is guidance, not a certifiable management system. It helps identify, analyze and treat risks specific to AI. 42001 requires you to have that discipline. 23894 describes how to hold it. Many organizations use it before they ever aim at certification.

The data that feeds AI

As soon as your AI tools touch personal information, Bill 25 and ISO 42001 meet. Quality, provenance and lawfulness of data are not a technical detail for a data-science team. That is governance.

The ISO/IEC 5259 series (five parts, 2024 and 2025) covers data quality for analytics and machine learning: vocabulary, measures, management requirements, process, governance. For an SMB, you do not need to read all five. You need to know they exist the day you train, fine-tune, or drop client files into a “projects” space in an AI tool.

ISO/IEC 25012 and 25024, older, talk about data quality in general (the SQuaRE family). Related, not AI-specific. I mention them for people who already have a software-quality program. That is not the next purchase for an SMB that is just starting.

Governance at the board, not only in IT

ISO/IEC 38507:2022

Implications of AI for IT governance. Audience: executives, the board, someone with authority to decide. Not the system administrator.

ISO/IEC 38500:2024

IT governance for the organization. 2024 edition, not 2015. That is the general reference. 38507 is the AI slice. Neither replaces 42001.

If your board asks “who owns AI here?” and the answer is silence, you do not have a model problem. You have a governance problem. I published an AI acceptable-use policy template for that gap.

NIST AI RMF: voluntary, not certifiable

NIST’s AI Risk Management Framework and ISO 42001 both aim to frame AI risk. They do not replace each other.

The NIST AI RMF is voluntary. It helps you assess and treat risk. ISO 42001 is a management-system standard, auditable and certifiable. You can use them together: NIST to structure the risk analysis, 42001 so it lives in roles, reviews and evidence.

For a Quebec SMB, NIST is a requirement only if a U.S. client names it. It is not the first document to open in Laval. If your U.S. RFPs cite it, then yes, read it. Otherwise 42001 and 23894 are enough to start.

The European AI regulation

ISO 42001 can help you move closer to the EU AI Act: risk management, transparency, accountability, improvement. It is not a harmonized standard under that regulation. It is not a stamp that “proves” the AI Act.

In Quebec, Bill 25 remains the local lever as soon as personal information is in play. The AI Act matters if you sell into the European Union, or if a client who sells there asks you for it. The five risk criteria in the getting-started article remain the useful filter here. Do not copy the European grid onto a Laval SMB with no EU exposure.

The periphery: worth knowing, not this week’s work

I include these to be complete. You do not need them tomorrow morning.

  • ISO/IEC TR 24028:2020: overview of trustworthiness in AI (technical report, not a certification).
  • ISO/IEC/IEEE 29119-11:2020: testing of AI-based systems, in the software-testing family.
  • ISO/IEC 20546:2019: big-data vocabulary. Related if you have massive volumes, not if you have Copilot.
  • ISO/IEC 27001:2022: that is my field, so I will say it. Without information security, governing AI is sticking a policy on a system you do not control.

This list will move. The ISO committee on AI keeps publishing. It is not a frozen inventory of everything ISO has ever touched.

Where to start, given your seat

You do not have an inventory yet. Read what you need to know before you start. Five actions, one hour in a meeting.

You only use ChatGPT, Copilot or the equivalent. Read the controls that do not apply. Do not apply A.6 as if you were training a model.

You already have ISO 27001. Add 42001 to govern AI. Use 23894 and 42005 on tools that touch people or personal information.

You sell in Europe, or an EU client asks. 42001 helps. Then read the regulation. Not the other way around: a regulation does not replace a management system.

You audit, or you choose a certification body. 42006 for the body, 19011 for how audits are run.

In short

ISO 42001 is not alone, and it does not do everything. It is not ISO 27001, not the NIST AI RMF, not the European regulation. The related standards (42005, 22989, 23894, 5259, 38507) do different jobs. Read the ones that match your role. Leave the others on the shelf.

Does this affect you? Let’s talk.