The ISO/IEC 42000 series is the informal name for the family of AI standards around ISO/IEC 42001, the certifiable AI management system standard from ISO and IEC. Three members carry 42000 numbers and are published. 42001 sets the rules (December 2023). 42005 guides AI system impact assessment (May 2025), and 42006 binds the bodies that certify an AI management system (July 2025). Implementation guidance, ISO/IEC 42003, is still an early work item. There is no ISO/IEC 42002 and no ISO/IEC 42004.
Care is needed with the name. ISO has no official block called the 42000 series. The AI standards come from one subcommittee, ISO/IEC JTC 1/SC 42. Many of them carry other numbers, such as 22989 for terms and 23894 for risk. Some nearby numbers have nothing to do with AI at all. ISO 42500 and its neighbors are sharing economy standards from ISO/TC 324, and ISO/IEC/IEEE 42010 describes software architecture. This page therefore treats the family as the SC 42 standards a 42001 implementer meets, plus the audit and certification standards beside them.
The series at a glance
The ISO/IEC 42000 series splits into four groups once you sort it by job. Only one document in it can be certified against.
| Group | Members | What the group does |
| Requirements | ISO/IEC 42001:2023 | The AI management system (AIMS) an organization certifies |
| Guidance for the build | 22989, 23053, 23894, 38507, 5338, 42005, TS 42119-2; 42003 later | Terms, risk, impact, governance, life cycle and testing help |
| Conformity assessment | 42006, 17021-1, 17024, 19011 | Rules for auditors, certification bodies and credential issuers |
| Pipeline | 24970, 42105, 42003, generative AI amendments, TS 42119 parts 3, 7 and 8 | Drafts and work items, not yet citable as published |
SC 42’s output is larger than a short summary suggests. GAICC counted the SC 42 records in ISO’s open data, refreshed on 30 September 2026. The file holds 44 current SC 42 publications and about 50 projects still in drafting or ballot. Most of them never touch a 42001 audit, so the status table keeps only the ones a 42001 implementer or auditor will meet.
Status of the AI standards a 42001 implementer meets
The status table lists each standard’s ISO stage code, its publication date and the 42001 work it supports. Every row was checked against ISO’s open data file on 5 October 2026 and links to its iso.org catalogue page. The last column is GAICC editorial analysis and quotes no ISO text.
| Standard | Short title | Status and stage | Published | What it governs | 42001 artifact or activity it supports |
| ISO/IEC 42001:2023 | AI management system | Published, 60.60; no amendment or revision registered | 18 Dec 2023 | Requirements for an AIMS; the only certifiable member | The whole system: scope, policy, risk, impact, SoA, audit, review |
| ISO/IEC 42005:2025 | AI system impact assessment | Published, 60.60 | 28 May 2025 | Guidance on assessing effects of AI systems on people and societies | Clause 6.1.4 and 8.4 assessments; Annex A.5 records |
| ISO/IEC 42006:2025 | Bodies auditing and certifying an AIMS | Published, 60.60 | 7 Jul 2025 | Extra rules for certification bodies on top of 17021-1, including audit time | The external certification audit |
| ISO/IEC AWI 42003 | Guidance on implementing 42001 | Preparatory, 20.00 (registered 11 Mar 2025) | Not published | Implementation guidance; ISO’s abstract adds competencies for AIMS professionals | Nothing yet; a future reference for the whole build |
| ISO/IEC 23894:2023 | Guidance on AI risk management | Published, 60.60 | 6 Feb 2023 | Risk management guidance for AI | Clause 6.1.2 risk assessment and 6.1.3 treatment method |
| ISO/IEC 22989:2022 | AI concepts and terminology | Published, 60.60 | 19 Jul 2022 | Shared vocabulary and AI stakeholder roles | Normative reference of 42001; clause 4.1 role determination |
| ISO/IEC 22989:2022/FDAmd 1 | Amendment 1: Generative AI | Approval, 50.00 | Not published | Generative AI terms | GenAI wording in scope and policy, once published |
| ISO/IEC 23053:2022 | Framework for AI systems using machine learning | Published, 60.60 | 20 Jun 2022 | Components and functions of an ML system | System descriptions in the inventory and design records |
| ISO/IEC 23053:2022/FDAmd 1 | Amendment 1: Generative AI | Approval, 50.00 | Not published | Generative AI extension of the framework | Same, for GenAI systems |
| ISO/IEC 5338:2023 | AI system life cycle processes | Published, 60.60 | 20 Dec 2023 | Life cycle processes for ML and heuristic AI systems | Annex A.6 life cycle controls |
| ISO/IEC 38507:2022 | Governance implications of AI use | Published, 60.60 | 8 Apr 2022 | Guidance for governing bodies on AI use | Clause 5 leadership, AI policy, board reporting |
| ISO/IEC FDIS 24970 | AI system logging | Approval, 50.20 (FDIS ballot) | Not published | Logging capabilities and an information model for AI events | A.6.2.8 event logs; monitoring evidence |
| ISO/IEC FDIS 42105 | Human oversight of AI systems | Approval, 50.20 (FDIS ballot) | Not published | Human control and monitoring of AI; extends ISO/IEC TS 8200 | A.9 responsible use; oversight measures |
| ISO/IEC TS 42119-2:2025 | Testing of AI, Part 2 | Published, 60.60 | 3 Nov 2025 | Applying the ISO/IEC/IEEE 29119 testing series to AI | A.6.2.4 verification and validation |
| ISO/IEC TS 42119-3 | Testing of AI, Part 3: verification and validation analysis | Publication, 60.00 | Not yet | Formal methods, simulation and evaluation for V&V | A.6.2.4 verification and validation |
| ISO/IEC AWI TS 42119-7 | Testing of AI, Part 7: Red teaming | Preparatory, 20.00 | Not published | Red teaming assessments of AI systems | Future test evidence for higher-impact systems |
| ISO/IEC AWI TS 42119-8 | Testing of AI, Part 8: prompt-based GenAI quality | Preparatory, 20.00 | Not published | Quality assessment of text-to-text GenAI systems | Future test evidence for GenAI |
| ISO/IEC 17024:2026 | Bodies certifying persons | Published, 60.60 (edition 3) | 31 Mar 2026 | Personnel certification schemes; replaces the 2012 edition | Personnel credentials offered as 7.2 competence evidence |
| ISO/IEC 17021-1:2015 | Bodies certifying management systems | Published; review closed, 90.60 | 8 Jun 2015 | Base rules for every management system certification body | The certification cycle that 42006 extends |
| ISO 19011:2026 | Guidelines for auditing management systems | Published, 60.60 (edition 4) | 27 May 2026 | Audit principles, audit programs and auditor competence | Clause 9.2 internal audit program |
| ISO/IEC 27001:2022 and Amd 1:2024 | Information security management | Published, 60.60 | 25 Oct 2022; Amd 23 Feb 2024 | Requirements for an ISMS | Integrated management system; shared clause structure |
| ISO/IEC 27701:2025 | Privacy information management | Published, 60.60 (edition 2) | 14 Oct 2025 | PIMS requirements, now a stand-alone standard | Clause 4.1 PII controller or processor roles |
Two of these rows are often misread. ISO/IEC 42006 governs the auditor and places no requirement on the audited firm. ISO/IEC 17024 covers credentials for people and never certifies a company. Its 2026 edition also adds requirements on the use of AI in certification processes, according to ISO’s catalogue page.
Reading the stage codes
An ISO stage code is a two-part number that shows where a document sits in ISO’s development cycle. The first two digits name the stage, and the last two name the step inside it. ISO publishes the full list on its stage codes page.
| Code | ISO’s meaning | What it means for an implementer |
| 20.00 | New project registered in the work programme | An idea with a number; no text you can use |
| 30.20 | Committee draft (CD) consultation initiated | Drafts circulate among national bodies |
| 40.20 | DIS ballot initiated, 12 weeks | Public enquiry draft; content can still change |
| 50.00 | Final text received or FDIS registered for formal approval | Content is close to final |
| 50.20 | Proof sent or FDIS ballot initiated, 8 weeks | Final yes or no vote under way |
| 60.00 | International Standard under publication | Approved; being prepared for sale |
| 60.60 | International Standard published | Citable and auditable as written |
| 90.60 | Close of review | Systematic review finished; edition still current |
The prefix in front of a number tells the same story in words. AWI means an approved work item, CD a committee draft, DIS a draft International Standard and FDIS a final draft. FDAmd marks a final draft amendment. TS and TR mark Technical Specifications and Technical Reports, which carry less consensus weight than a full International Standard. No certification body can audit you against a draft. A row at 50.20 is worth reading for direction, but the evidence you show an auditor still has to meet the published text of the standard.
Checking a status yourself
ISO’s catalogue page for each standard shows its current stage and the dates of earlier stages. ISO also publishes an open data file of all deliverables, which this table was built from. Check both before an audit or a board paper. It takes minutes, and it stops a final draft from being cited in a policy or a contract as if it were the published standard. With the codes clear, the next question is which document helps with which piece of 42001 work.
Which standard governs which 42001 artifact
The artifact map below links each 42001 output to the companion standard that helps produce it. ISO/IEC 42001 alone sets the rules. The companions only guide. The mapping is GAICC editorial analysis, and control IDs come from public enumerations of Annex A, so verify control wording against your licensed copy.
| 42001 artifact or activity | Where 42001 asks for it | Companion standard | What the companion adds |
| AI roles and AIMS scope statement | Clauses 4.1 and 4.3 | ISO/IEC 22989 | Definitions of the six AI stakeholder role families |
| AI policy and leadership evidence | Clauses 5.1 and 5.2; A.2 | ISO/IEC 38507 | How a governing body directs and oversees AI use |
| AI risk assessment and risk treatment plan | Clauses 6.1.2, 6.1.3, 8.2, 8.3 | ISO/IEC 23894; DTS 25568 (draft) | A risk process built for AI, with AI risk sources |
| Statement of Applicability | Clause 6.1.3 | None; Annex A and Annex B of 42001 itself | No companion standard governs the SoA |
| AI system impact assessment | Clauses 6.1.4 and 8.4; A.5 | ISO/IEC 42005 | Process steps, documentation fields and an example template |
| Competence evidence | Clause 7.2 | ISO/IEC 17024 (credentials); 42003 (future) | How personnel credentials are issued and kept |
| Life cycle, verification and validation records | A.6 | ISO/IEC 5338; 23053; TS 42119-2 | Life cycle processes, system description and test practice |
| Event logs | A.6.2.8 | FDIS 24970 | What to log and how to structure log records |
| Data quality and provenance | A.7 | ISO/IEC 5259 series | Data quality measures, management and governance |
| Information for users and interested parties | A.8 | ISO/IEC 12792:2025 | A transparency taxonomy for describing AI systems |
| Responsible use and human oversight | A.9 | FDIS 42105 | Guidance on human control and monitoring |
| Privacy roles | Clause 4.1 note | ISO/IEC 27701:2025 | PII controller and processor obligations |
| Internal audit program | Clause 9.2 | ISO 19011:2026 | Audit principles, program management, auditor competence |
| Certification audit | Outside 42001 | ISO/IEC 17021-1 plus 42006 | The rules your certification body must follow |
One row has no companion at all. The Statement of Applicability comes straight from clause 6.1.3 and Annex A. No outside standard tells you how to justify a control. For the full list of what each clause asks you to produce, see the clause outputs, clause by clause. For the controls themselves, see the Annex A control set.
Which of these 42001 itself cites
ISO/IEC 42001 names exactly one normative reference, ISO/IEC 22989:2022. So the terms in 22989 apply when you read the rules in 42001. Every other SC 42 document, from 23894 to 5338, sits outside clause 2. Reading one adds context. It adds no requirement. ISO/IEC 42005 and 42006 were both published after 42001, so neither can be a normative reference of the 2023 text. Some online standards maps label 42005 as “required for 42001”. The published text does not support that label.
42001, 42005 and 42006: three jobs
ISO/IEC 42001, 42005 and 42006 share a number range but serve three different readers. Mixing them up is a frequent error in online summaries, so the contrast below sets out type, reader, certifiability and output side by side.
| Attribute | ISO/IEC 42001 | ISO/IEC 42005 | ISO/IEC 42006 |
| Type | Requirements | Guidance | Requirements |
| Reader | Any organization that develops, provides or uses AI | Teams running AI system impact assessments | Certification bodies and their auditors |
| Can an organization be certified to it? | Yes | No | No; bodies are accredited against it with 17021-1 |
| Main output | A working AIMS | Impact assessment records | Audit programs, audit time, certification decisions |
| Link to 42001 | Itself | Supports clause 6.1.4; its Annex A covers use with 42001 | Defines how 42001 audits are run |
For clause 6.1.4, ISO/IEC 42005 is the practical companion. Its clauses set out the steps and the facts to record. Its informative annexes add a harms and benefits taxonomy, guidance for use with 42001 and 23894, and an example template. GAICC’s guide to ISO/IEC 42005 covers the standard, and the requirement it serves sits in clause 6.1.4.
On the other side of the table sits ISO/IEC 42006. According to ISO’s abstract, it “specifies additional requirements to ISO/IEC 17021-1” for bodies certifying an AIMS. Its normative Annex A sets audit time. The published text also bars certification bodies from consulting for the clients they certify and from running their internal audits. The firm that helps you build an AIMS therefore cannot also certify it, and both points shape who you hire. What happens in the certification audit itself has its own guide.
ISO/IEC 42002 and 42004 do not exist
ISO/IEC 42002 and ISO/IEC 42004 are not ISO standards. ISO’s open data, refreshed on 30 September 2026, holds no record under either number, published or in development. You may see these numbers online anyway, attached to vocabulary or implementation guidance. Treat any page that describes their contents as describing something else.
The real documents behind those claims are easy to name. AI vocabulary lives in ISO/IEC 22989:2022, whose generative AI amendment is still a final draft. Implementation guidance is ISO/IEC 42003, registered as a work item on 11 March 2025 and still at stage 20.00. ISO’s abstract for 42003 says it will also cover competencies for AIMS professionals. Anyone who trains or hires implementers should watch it.
| Claim you may see | What ISO’s data shows (5 Oct 2026) |
| ISO/IEC 42002 defines AI governance vocabulary | No such standard; vocabulary is ISO/IEC 22989:2022 |
| ISO/IEC 42004 is the implementation guide for 42001 | No such standard; ISO/IEC 42003 is an early work item |
| ISO/IEC 42005 covers auditing and conformity assessment | 42005 is impact assessment guidance; auditing bodies follow 42006 |
| The 22989 generative AI amendment is published | Final draft amendment at stage 50.00 |
| ISO/IEC 42001 has been revised or amended | Still the 2023 edition; no amendment or revision record |
| ISO/IEC 42007 is part of the published series | Draft International Standard at 40.20, on schemes for AI systems |
[TRAINER INSIGHT NEEDED: Which of these numbering mix-ups do GAICC Lead Implementer candidates bring into class most often, and how does the course correct them?]
EN ISO/IEC 42001:2026 and the EU AI Act
EN ISO/IEC 42001:2026 is the European adoption of ISO/IEC 42001:2023, approved by CEN on 13 March 2026. Its endorsement notice says CEN-CENELEC approved the ISO text “without any modification”. The technical committee that took it over is CEN-CENELEC JTC 21, Artificial Intelligence. National standards bodies had to give it national status, and withdraw conflicting standards, by September 2026.
The “2026” in the European name marks the year of adoption; the edition is unchanged. The text is word for word the 2023 ISO text. A certificate issued against either name rests on the same clauses. CEN had already adopted ISO/IEC 22989 as a European Standard on 26 June 2023.
What the European adoption does not do
The European adoption does not make 42001 a harmonised standard under the EU AI Act. Under Article 40(1) of Regulation (EU) 2024/1689, the presumption of conformity a standard can give comes from harmonised standards whose references are published in the Official Journal. The European foreword to EN ISO/IEC 42001:2026 mentions no Commission standardization request and no link to the AI Act. The AI Act’s own text never mentions 42001, and a Cloud Security Alliance research note from September 2026 reached the same reading on harmonised status.
A different document was built for the Act. CEN-CENELEC announced EN 18286:2026, a quality management system standard for EU AI Act purposes, tied to the Article 17 duties of high-risk AI providers. The CSA note reported that EN 18286 was also not yet cited in the Official Journal in September 2026. An AIMS built on 42001 can still supply much of the evidence a provider needs. Any legal presumption, when it comes, will attach to harmonised standards cited in the Official Journal, and 42001 had not been cited as of September 2026. For the overlap in detail, see GAICC’s EU AI Act and ISO 42001 comparison.
AS ISO/IEC 42001:2023 in Australia
AS ISO/IEC 42001:2023 is Australia’s national adoption of 42001. Standards Australia says it was “adopted as an identical Australian Standard in February 2024” (Standards Australia, September 2025). Its mirror committee is IT-043. Identical means the same clauses and the same Annex A as the ISO text.
Australia’s 2024 Voluntary AI Safety Standard named AS ISO/IEC 42001:2023 as the leading AI management system standard, but the government has since replaced that document with its Guidance for AI Adoption, published in October 2025. Readers in Australia can cite the national name in local contracts and the ISO name elsewhere. Regional versions settle which text applies today. The pipeline shows what will change it.
What is coming next
The SC 42 pipeline holds several documents close to publication that will matter for the evidence a 42001 implementer builds once each one is published. ISO promises no publication date for any of them.
| Document | Stage on 5 Oct 2026 | What will change for an implementer |
| ISO/IEC FDIS 42105, human oversight | 50.20; ISO’s page shows the FDIS ballot opening on 26 Aug 2026 | A reference for designing and evidencing oversight under A.9 |
| ISO/IEC FDIS 24970, AI system logging | 50.20; ballot opened on 28 Aug 2026 | A model for what event logs under A.6.2.8 should hold |
| ISO/IEC 22989 Amd 1, generative AI | 50.00; final text registered 18 Sep 2026 | Official GenAI terms for scope statements and policies |
| ISO/IEC 23053 Amd 1, generative AI | 50.00 | A GenAI system description model |
| ISO/IEC TS 42119-3, verification and validation | 60.00, under publication | V&V methods for A.6.2.4 evidence |
| ISO/IEC DTS 25568, GenAI risks | 50.00 | Risk sources and treatments for GenAI in 6.1.2 and 6.1.3 |
| ISO/IEC DTS 22443, societal and ethical concerns | 50.20 | Input to societal impact analysis under A.5 |
| ISO/IEC DIS 42007, conformity assessment schemes | 40.20 | Schemes for certifying AI systems, separate from AIMS certification |
| ISO/IEC AWI 42003, implementation guidance | 20.00 | Official implementation guidance, years rather than months away |
| ISO/IEC TS 42119-7 and -8, red teaming and GenAI quality | 20.00 | Test methods for GenAI and adversarial testing |
In the short term, the two FDIS ballots matter most. Both 42105 and 24970 were at 50.20 when this table was checked. An eight-week ballot that opened in late August would close in late October. Publication follows the vote at a later date. Until a document reaches 60.60, cite it as a draft.
Watch one more trend. The generative AI amendments to 22989 and 23053 will change the vocabulary that scope statements and policies borrow. A policy written today can keep the 2022 terms and add a review trigger that fires when the amendment is published. The update is then planned in advance.
[TRAINER INSIGHT NEEDED: When a companion standard such as 42105 is published, how do GAICC instructors advise implementers to update existing AIMS documents, and what do certification auditors expect to see?]
How ISO 27001 and 27701 fit the family
ISO/IEC 27001 and 27701 sit outside SC 42, yet many 42001 implementers already know them from information security and privacy work. All three share the harmonized clause structure, so one integrated management system can serve all three at once. A small detail shows how they differ in age. ISO/IEC 42001 already contained a climate change consideration in clause 4.1 when it was published. ISO/IEC 27001 gained the same consideration through Amendment 1 in February 2024.
Since 2025, ISO/IEC 27701 stands alone as a privacy management standard, where the 2019 edition extended 27001. That change matters for 42001 clause 4.1, which notes that PII controller or processor roles can shape an organization’s AI roles. For integration detail, see GAICC’s comparison of ISO 42001 and ISO 27001.
Where to start, by role
Reading order across the ISO/IEC 42000 series depends on the reader’s job and on what the firm already runs.
- A Lead Implementer candidate reads 42001 and the 22989 terms first, then 23894 and 42005, because risk and impact work carry heavy weight in projects. GAICC’s Lead Implementer course built on ISO/IEC 42001:2023 works through clauses 2 to 10, with a module on risk and impact assessment under clauses 6.1.1 to 6.1.4.
- An organization starting from zero obtains 42001 and 22989 first and adds 42005 when the first impact assessment begins. The pillar guide to the AI management system standard covers scope and who needs it.
- A team that already runs ISO 27001 maps its existing ISMS clauses first, then adds 23894 for AI risk and 42005 for impact assessment.
- A firm that sells into the EU keeps 42001 for its management system and tracks EN 18286 for AI Act quality management duties.
- Anyone who audits, or plans to, reads 17021-1, 42006 and 19011:2026 alongside 42001.
GAICC’s deeper guides cover ISO/IEC 23894 for AI risk and AI concepts and terminology under 22989.
Frequently asked questions
Is any standard in the ISO 42000 series mandatory?
No standard in the family is a law, and ISO states that certification to ISO/IEC 42001, the only certifiable member, is voluntary. The European adoption, EN ISO/IEC 42001:2026, does not change that, because it had not been cited as a harmonised standard under the EU AI Act as of September 2026. Contracts can still demand certification, as GAICC’s guide to whether ISO 42001 is mandatory explains.
Are any ISO 42000 series standards free to download?
ISO’s online store listed ISO/IEC 22989:2022, the vocabulary standard that 42001 names as its normative reference, at no charge on 6 October 2026. The other family members checked that day, including ISO/IEC 42001, 42005 and 23053, were paid documents. Prices and listings change, so check each catalogue page before relying on a copy.
What is the ISO 27000 series of standards?
The ISO/IEC 27000 series is the information security family, led by ISO/IEC 27001, the certifiable ISMS standard. ISO/IEC 27002 holds the control guidance that 27001’s Annex A mirrors, and ISO/IEC 27701:2025 now stands alone as a privacy management standard. Both families share the harmonized clause structure, which is why one integrated management system can serve 27001 and 42001 together.
Do you need every standard in the family to get ISO 42001 certified?
A certification audit tests conformity with ISO/IEC 42001 itself, read with the terms of its one normative reference, ISO/IEC 22989:2022. Guidance documents such as 23894 or 42005 add no requirement, though they help a team produce evidence. The certification body, for its part, works to ISO/IEC 17021-1 and ISO/IEC 42006.
Does a newly published SC 42 standard change an existing AIMS?
Publication of a guidance standard such as ISO/IEC 42105 adds no requirement to ISO/IEC 42001, so it does not by itself make an existing AIMS nonconforming. It can still give the team a better method for related controls, such as A.9 oversight measures. A review trigger in the AI policy, set to fire when a watched document reaches stage 60.60, keeps those updates planned.
When will ISO/IEC 42001 be revised?
ISO’s open data showed no amendment or revision of ISO/IEC 42001 registered on 30 September 2026, and its catalogue page still showed the 2023 first edition on 6 October 2026. A revision would show first in the catalogue, either as a review decision to revise (stage 90.92) or as a new project (stage 20.00). Until then, the 2023 text is the one certification bodies audit.

