GAICC AI Conference & Awards 2026 "Governing the Future – Building Responsible, Safe and Human-centric AI"

The ISO/IEC 42000 Series in 2026: What Each AI Standard Covers and Its Status

Last Updated : October 7, 2026
iso-iec-42000-series-ai-standards-status-2026

On this page

The ISO/IEC 42000 series is the informal name for the family of AI standards around ISO/IEC 42001, the certifiable AI management system standard from ISO and IEC. Three members carry 42000 numbers and are published. 42001 sets the rules (December 2023). 42005 guides AI system impact assessment (May 2025), and 42006 binds the bodies that certify an AI management system (July 2025). Implementation guidance, ISO/IEC 42003, is still an early work item. There is no ISO/IEC 42002 and no ISO/IEC 42004.

Care is needed with the name. ISO has no official block called the 42000 series. The AI standards come from one subcommittee, ISO/IEC JTC 1/SC 42. Many of them carry other numbers, such as 22989 for terms and 23894 for risk. Some nearby numbers have nothing to do with AI at all. ISO 42500 and its neighbors are sharing economy standards from ISO/TC 324, and ISO/IEC/IEEE 42010 describes software architecture. This page therefore treats the family as the SC 42 standards a 42001 implementer meets, plus the audit and certification standards beside them.

The series at a glance

The ISO/IEC 42000 series splits into four groups once you sort it by job. Only one document in it can be certified against.

GroupMembersWhat the group does
RequirementsISO/IEC 42001:2023The AI management system (AIMS) an organization certifies
Guidance for the build22989, 23053, 23894, 38507, 5338, 42005, TS 42119-2; 42003 laterTerms, risk, impact, governance, life cycle and testing help
Conformity assessment42006, 17021-1, 17024, 19011Rules for auditors, certification bodies and credential issuers
Pipeline24970, 42105, 42003, generative AI amendments, TS 42119 parts 3, 7 and 8Drafts and work items, not yet citable as published

SC 42’s output is larger than a short summary suggests. GAICC counted the SC 42 records in ISO’s open data, refreshed on 30 September 2026. The file holds 44 current SC 42 publications and about 50 projects still in drafting or ballot. Most of them never touch a 42001 audit, so the status table keeps only the ones a 42001 implementer or auditor will meet.

Status of the AI standards a 42001 implementer meets

The status table lists each standard’s ISO stage code, its publication date and the 42001 work it supports. Every row was checked against ISO’s open data file on 5 October 2026 and links to its iso.org catalogue page. The last column is GAICC editorial analysis and quotes no ISO text.

StandardShort titleStatus and stagePublishedWhat it governs42001 artifact or activity it supports
ISO/IEC 42001:2023AI management systemPublished, 60.60; no amendment or revision registered18 Dec 2023Requirements for an AIMS; the only certifiable memberThe whole system: scope, policy, risk, impact, SoA, audit, review
ISO/IEC 42005:2025AI system impact assessmentPublished, 60.6028 May 2025Guidance on assessing effects of AI systems on people and societiesClause 6.1.4 and 8.4 assessments; Annex A.5 records
ISO/IEC 42006:2025Bodies auditing and certifying an AIMSPublished, 60.607 Jul 2025Extra rules for certification bodies on top of 17021-1, including audit timeThe external certification audit
ISO/IEC AWI 42003Guidance on implementing 42001Preparatory, 20.00 (registered 11 Mar 2025)Not publishedImplementation guidance; ISO’s abstract adds competencies for AIMS professionalsNothing yet; a future reference for the whole build
ISO/IEC 23894:2023Guidance on AI risk managementPublished, 60.606 Feb 2023Risk management guidance for AIClause 6.1.2 risk assessment and 6.1.3 treatment method
ISO/IEC 22989:2022AI concepts and terminologyPublished, 60.6019 Jul 2022Shared vocabulary and AI stakeholder rolesNormative reference of 42001; clause 4.1 role determination
ISO/IEC 22989:2022/FDAmd 1Amendment 1: Generative AIApproval, 50.00Not publishedGenerative AI termsGenAI wording in scope and policy, once published
ISO/IEC 23053:2022Framework for AI systems using machine learningPublished, 60.6020 Jun 2022Components and functions of an ML systemSystem descriptions in the inventory and design records
ISO/IEC 23053:2022/FDAmd 1Amendment 1: Generative AIApproval, 50.00Not publishedGenerative AI extension of the frameworkSame, for GenAI systems
ISO/IEC 5338:2023AI system life cycle processesPublished, 60.6020 Dec 2023Life cycle processes for ML and heuristic AI systemsAnnex A.6 life cycle controls
ISO/IEC 38507:2022Governance implications of AI usePublished, 60.608 Apr 2022Guidance for governing bodies on AI useClause 5 leadership, AI policy, board reporting
ISO/IEC FDIS 24970AI system loggingApproval, 50.20 (FDIS ballot)Not publishedLogging capabilities and an information model for AI eventsA.6.2.8 event logs; monitoring evidence
ISO/IEC FDIS 42105Human oversight of AI systemsApproval, 50.20 (FDIS ballot)Not publishedHuman control and monitoring of AI; extends ISO/IEC TS 8200A.9 responsible use; oversight measures
ISO/IEC TS 42119-2:2025Testing of AI, Part 2Published, 60.603 Nov 2025Applying the ISO/IEC/IEEE 29119 testing series to AIA.6.2.4 verification and validation
ISO/IEC TS 42119-3Testing of AI, Part 3: verification and validation analysisPublication, 60.00Not yetFormal methods, simulation and evaluation for V&VA.6.2.4 verification and validation
ISO/IEC AWI TS 42119-7Testing of AI, Part 7: Red teamingPreparatory, 20.00Not publishedRed teaming assessments of AI systemsFuture test evidence for higher-impact systems
ISO/IEC AWI TS 42119-8Testing of AI, Part 8: prompt-based GenAI qualityPreparatory, 20.00Not publishedQuality assessment of text-to-text GenAI systemsFuture test evidence for GenAI
ISO/IEC 17024:2026Bodies certifying personsPublished, 60.60 (edition 3)31 Mar 2026Personnel certification schemes; replaces the 2012 editionPersonnel credentials offered as 7.2 competence evidence
ISO/IEC 17021-1:2015Bodies certifying management systemsPublished; review closed, 90.608 Jun 2015Base rules for every management system certification bodyThe certification cycle that 42006 extends
ISO 19011:2026Guidelines for auditing management systemsPublished, 60.60 (edition 4)27 May 2026Audit principles, audit programs and auditor competenceClause 9.2 internal audit program
ISO/IEC 27001:2022 and Amd 1:2024Information security managementPublished, 60.6025 Oct 2022; Amd 23 Feb 2024Requirements for an ISMSIntegrated management system; shared clause structure
ISO/IEC 27701:2025Privacy information managementPublished, 60.60 (edition 2)14 Oct 2025PIMS requirements, now a stand-alone standardClause 4.1 PII controller or processor roles

Two of these rows are often misread. ISO/IEC 42006 governs the auditor and places no requirement on the audited firm. ISO/IEC 17024 covers credentials for people and never certifies a company. Its 2026 edition also adds requirements on the use of AI in certification processes, according to ISO’s catalogue page.

Reading the stage codes

An ISO stage code is a two-part number that shows where a document sits in ISO’s development cycle. The first two digits name the stage, and the last two name the step inside it. ISO publishes the full list on its stage codes page.

CodeISO’s meaningWhat it means for an implementer
20.00New project registered in the work programmeAn idea with a number; no text you can use
30.20Committee draft (CD) consultation initiatedDrafts circulate among national bodies
40.20DIS ballot initiated, 12 weeksPublic enquiry draft; content can still change
50.00Final text received or FDIS registered for formal approvalContent is close to final
50.20Proof sent or FDIS ballot initiated, 8 weeksFinal yes or no vote under way
60.00International Standard under publicationApproved; being prepared for sale
60.60International Standard publishedCitable and auditable as written
90.60Close of reviewSystematic review finished; edition still current

The prefix in front of a number tells the same story in words. AWI means an approved work item, CD a committee draft, DIS a draft International Standard and FDIS a final draft. FDAmd marks a final draft amendment. TS and TR mark Technical Specifications and Technical Reports, which carry less consensus weight than a full International Standard. No certification body can audit you against a draft. A row at 50.20 is worth reading for direction, but the evidence you show an auditor still has to meet the published text of the standard.

Checking a status yourself

ISO’s catalogue page for each standard shows its current stage and the dates of earlier stages. ISO also publishes an open data file of all deliverables, which this table was built from. Check both before an audit or a board paper. It takes minutes, and it stops a final draft from being cited in a policy or a contract as if it were the published standard. With the codes clear, the next question is which document helps with which piece of 42001 work.

Which standard governs which 42001 artifact

The artifact map below links each 42001 output to the companion standard that helps produce it. ISO/IEC 42001 alone sets the rules. The companions only guide. The mapping is GAICC editorial analysis, and control IDs come from public enumerations of Annex A, so verify control wording against your licensed copy.

42001 artifact or activityWhere 42001 asks for itCompanion standardWhat the companion adds
AI roles and AIMS scope statementClauses 4.1 and 4.3ISO/IEC 22989Definitions of the six AI stakeholder role families
AI policy and leadership evidenceClauses 5.1 and 5.2; A.2ISO/IEC 38507How a governing body directs and oversees AI use
AI risk assessment and risk treatment planClauses 6.1.2, 6.1.3, 8.2, 8.3ISO/IEC 23894; DTS 25568 (draft)A risk process built for AI, with AI risk sources
Statement of ApplicabilityClause 6.1.3None; Annex A and Annex B of 42001 itselfNo companion standard governs the SoA
AI system impact assessmentClauses 6.1.4 and 8.4; A.5ISO/IEC 42005Process steps, documentation fields and an example template
Competence evidenceClause 7.2ISO/IEC 17024 (credentials); 42003 (future)How personnel credentials are issued and kept
Life cycle, verification and validation recordsA.6ISO/IEC 5338; 23053; TS 42119-2Life cycle processes, system description and test practice
Event logsA.6.2.8FDIS 24970What to log and how to structure log records
Data quality and provenanceA.7ISO/IEC 5259 seriesData quality measures, management and governance
Information for users and interested partiesA.8ISO/IEC 12792:2025A transparency taxonomy for describing AI systems
Responsible use and human oversightA.9FDIS 42105Guidance on human control and monitoring
Privacy rolesClause 4.1 noteISO/IEC 27701:2025PII controller and processor obligations
Internal audit programClause 9.2ISO 19011:2026Audit principles, program management, auditor competence
Certification auditOutside 42001ISO/IEC 17021-1 plus 42006The rules your certification body must follow

One row has no companion at all. The Statement of Applicability comes straight from clause 6.1.3 and Annex A. No outside standard tells you how to justify a control. For the full list of what each clause asks you to produce, see the clause outputs, clause by clause. For the controls themselves, see the Annex A control set.

Which of these 42001 itself cites

ISO/IEC 42001 names exactly one normative reference, ISO/IEC 22989:2022. So the terms in 22989 apply when you read the rules in 42001. Every other SC 42 document, from 23894 to 5338, sits outside clause 2. Reading one adds context. It adds no requirement. ISO/IEC 42005 and 42006 were both published after 42001, so neither can be a normative reference of the 2023 text. Some online standards maps label 42005 as “required for 42001”. The published text does not support that label.

42001, 42005 and 42006: three jobs

ISO/IEC 42001, 42005 and 42006 share a number range but serve three different readers. Mixing them up is a frequent error in online summaries, so the contrast below sets out type, reader, certifiability and output side by side.

AttributeISO/IEC 42001ISO/IEC 42005ISO/IEC 42006
TypeRequirementsGuidanceRequirements
ReaderAny organization that develops, provides or uses AITeams running AI system impact assessmentsCertification bodies and their auditors
Can an organization be certified to it?YesNoNo; bodies are accredited against it with 17021-1
Main outputA working AIMSImpact assessment recordsAudit programs, audit time, certification decisions
Link to 42001ItselfSupports clause 6.1.4; its Annex A covers use with 42001Defines how 42001 audits are run

For clause 6.1.4, ISO/IEC 42005 is the practical companion. Its clauses set out the steps and the facts to record. Its informative annexes add a harms and benefits taxonomy, guidance for use with 42001 and 23894, and an example template. GAICC’s guide to ISO/IEC 42005 covers the standard, and the requirement it serves sits in clause 6.1.4.

On the other side of the table sits ISO/IEC 42006. According to ISO’s abstract, it “specifies additional requirements to ISO/IEC 17021-1” for bodies certifying an AIMS. Its normative Annex A sets audit time. The published text also bars certification bodies from consulting for the clients they certify and from running their internal audits. The firm that helps you build an AIMS therefore cannot also certify it, and both points shape who you hire. What happens in the certification audit itself has its own guide.

ISO/IEC 42002 and 42004 do not exist

ISO/IEC 42002 and ISO/IEC 42004 are not ISO standards. ISO’s open data, refreshed on 30 September 2026, holds no record under either number, published or in development. You may see these numbers online anyway, attached to vocabulary or implementation guidance. Treat any page that describes their contents as describing something else.

The real documents behind those claims are easy to name. AI vocabulary lives in ISO/IEC 22989:2022, whose generative AI amendment is still a final draft. Implementation guidance is ISO/IEC 42003, registered as a work item on 11 March 2025 and still at stage 20.00. ISO’s abstract for 42003 says it will also cover competencies for AIMS professionals. Anyone who trains or hires implementers should watch it.

Claim you may seeWhat ISO’s data shows (5 Oct 2026)
ISO/IEC 42002 defines AI governance vocabularyNo such standard; vocabulary is ISO/IEC 22989:2022
ISO/IEC 42004 is the implementation guide for 42001No such standard; ISO/IEC 42003 is an early work item
ISO/IEC 42005 covers auditing and conformity assessment42005 is impact assessment guidance; auditing bodies follow 42006
The 22989 generative AI amendment is publishedFinal draft amendment at stage 50.00
ISO/IEC 42001 has been revised or amendedStill the 2023 edition; no amendment or revision record
ISO/IEC 42007 is part of the published seriesDraft International Standard at 40.20, on schemes for AI systems

[TRAINER INSIGHT NEEDED: Which of these numbering mix-ups do GAICC Lead Implementer candidates bring into class most often, and how does the course correct them?]

EN ISO/IEC 42001:2026 and the EU AI Act

EN ISO/IEC 42001:2026 is the European adoption of ISO/IEC 42001:2023, approved by CEN on 13 March 2026. Its endorsement notice says CEN-CENELEC approved the ISO text “without any modification”. The technical committee that took it over is CEN-CENELEC JTC 21, Artificial Intelligence. National standards bodies had to give it national status, and withdraw conflicting standards, by September 2026.

The “2026” in the European name marks the year of adoption; the edition is unchanged. The text is word for word the 2023 ISO text. A certificate issued against either name rests on the same clauses. CEN had already adopted ISO/IEC 22989 as a European Standard on 26 June 2023.

What the European adoption does not do

The European adoption does not make 42001 a harmonised standard under the EU AI Act. Under Article 40(1) of Regulation (EU) 2024/1689, the presumption of conformity a standard can give comes from harmonised standards whose references are published in the Official Journal. The European foreword to EN ISO/IEC 42001:2026 mentions no Commission standardization request and no link to the AI Act. The AI Act’s own text never mentions 42001, and a Cloud Security Alliance research note from September 2026 reached the same reading on harmonised status.

A different document was built for the Act. CEN-CENELEC announced EN 18286:2026, a quality management system standard for EU AI Act purposes, tied to the Article 17 duties of high-risk AI providers. The CSA note reported that EN 18286 was also not yet cited in the Official Journal in September 2026. An AIMS built on 42001 can still supply much of the evidence a provider needs. Any legal presumption, when it comes, will attach to harmonised standards cited in the Official Journal, and 42001 had not been cited as of September 2026. For the overlap in detail, see GAICC’s EU AI Act and ISO 42001 comparison.

AS ISO/IEC 42001:2023 in Australia

AS ISO/IEC 42001:2023 is Australia’s national adoption of 42001. Standards Australia says it was “adopted as an identical Australian Standard in February 2024” (Standards Australia, September 2025). Its mirror committee is IT-043. Identical means the same clauses and the same Annex A as the ISO text.

Australia’s 2024 Voluntary AI Safety Standard named AS ISO/IEC 42001:2023 as the leading AI management system standard, but the government has since replaced that document with its Guidance for AI Adoption, published in October 2025. Readers in Australia can cite the national name in local contracts and the ISO name elsewhere. Regional versions settle which text applies today. The pipeline shows what will change it.

What is coming next

The SC 42 pipeline holds several documents close to publication that will matter for the evidence a 42001 implementer builds once each one is published. ISO promises no publication date for any of them.

DocumentStage on 5 Oct 2026What will change for an implementer
ISO/IEC FDIS 42105, human oversight50.20; ISO’s page shows the FDIS ballot opening on 26 Aug 2026A reference for designing and evidencing oversight under A.9
ISO/IEC FDIS 24970, AI system logging50.20; ballot opened on 28 Aug 2026A model for what event logs under A.6.2.8 should hold
ISO/IEC 22989 Amd 1, generative AI50.00; final text registered 18 Sep 2026Official GenAI terms for scope statements and policies
ISO/IEC 23053 Amd 1, generative AI50.00A GenAI system description model
ISO/IEC TS 42119-3, verification and validation60.00, under publicationV&V methods for A.6.2.4 evidence
ISO/IEC DTS 25568, GenAI risks50.00Risk sources and treatments for GenAI in 6.1.2 and 6.1.3
ISO/IEC DTS 22443, societal and ethical concerns50.20Input to societal impact analysis under A.5
ISO/IEC DIS 42007, conformity assessment schemes40.20Schemes for certifying AI systems, separate from AIMS certification
ISO/IEC AWI 42003, implementation guidance20.00Official implementation guidance, years rather than months away
ISO/IEC TS 42119-7 and -8, red teaming and GenAI quality20.00Test methods for GenAI and adversarial testing

In the short term, the two FDIS ballots matter most. Both 42105 and 24970 were at 50.20 when this table was checked. An eight-week ballot that opened in late August would close in late October. Publication follows the vote at a later date. Until a document reaches 60.60, cite it as a draft.

Watch one more trend. The generative AI amendments to 22989 and 23053 will change the vocabulary that scope statements and policies borrow. A policy written today can keep the 2022 terms and add a review trigger that fires when the amendment is published. The update is then planned in advance.

[TRAINER INSIGHT NEEDED: When a companion standard such as 42105 is published, how do GAICC instructors advise implementers to update existing AIMS documents, and what do certification auditors expect to see?]

How ISO 27001 and 27701 fit the family

ISO/IEC 27001 and 27701 sit outside SC 42, yet many 42001 implementers already know them from information security and privacy work. All three share the harmonized clause structure, so one integrated management system can serve all three at once. A small detail shows how they differ in age. ISO/IEC 42001 already contained a climate change consideration in clause 4.1 when it was published. ISO/IEC 27001 gained the same consideration through Amendment 1 in February 2024.

Since 2025, ISO/IEC 27701 stands alone as a privacy management standard, where the 2019 edition extended 27001. That change matters for 42001 clause 4.1, which notes that PII controller or processor roles can shape an organization’s AI roles. For integration detail, see GAICC’s comparison of ISO 42001 and ISO 27001.

Where to start, by role

Reading order across the ISO/IEC 42000 series depends on the reader’s job and on what the firm already runs.

  • A Lead Implementer candidate reads 42001 and the 22989 terms first, then 23894 and 42005, because risk and impact work carry heavy weight in projects. GAICC’s Lead Implementer course built on ISO/IEC 42001:2023 works through clauses 2 to 10, with a module on risk and impact assessment under clauses 6.1.1 to 6.1.4.
  • An organization starting from zero obtains 42001 and 22989 first and adds 42005 when the first impact assessment begins. The pillar guide to the AI management system standard covers scope and who needs it.
  • A team that already runs ISO 27001 maps its existing ISMS clauses first, then adds 23894 for AI risk and 42005 for impact assessment.
  • A firm that sells into the EU keeps 42001 for its management system and tracks EN 18286 for AI Act quality management duties.
  • Anyone who audits, or plans to, reads 17021-1, 42006 and 19011:2026 alongside 42001.

GAICC’s deeper guides cover ISO/IEC 23894 for AI risk and AI concepts and terminology under 22989.

Frequently asked questions

Is any standard in the ISO 42000 series mandatory?

No standard in the family is a law, and ISO states that certification to ISO/IEC 42001, the only certifiable member, is voluntary. The European adoption, EN ISO/IEC 42001:2026, does not change that, because it had not been cited as a harmonised standard under the EU AI Act as of September 2026. Contracts can still demand certification, as GAICC’s guide to whether ISO 42001 is mandatory explains.

Are any ISO 42000 series standards free to download?

ISO’s online store listed ISO/IEC 22989:2022, the vocabulary standard that 42001 names as its normative reference, at no charge on 6 October 2026. The other family members checked that day, including ISO/IEC 42001, 42005 and 23053, were paid documents. Prices and listings change, so check each catalogue page before relying on a copy.

What is the ISO 27000 series of standards?

The ISO/IEC 27000 series is the information security family, led by ISO/IEC 27001, the certifiable ISMS standard. ISO/IEC 27002 holds the control guidance that 27001’s Annex A mirrors, and ISO/IEC 27701:2025 now stands alone as a privacy management standard. Both families share the harmonized clause structure, which is why one integrated management system can serve 27001 and 42001 together.

Do you need every standard in the family to get ISO 42001 certified?

A certification audit tests conformity with ISO/IEC 42001 itself, read with the terms of its one normative reference, ISO/IEC 22989:2022. Guidance documents such as 23894 or 42005 add no requirement, though they help a team produce evidence. The certification body, for its part, works to ISO/IEC 17021-1 and ISO/IEC 42006.

Does a newly published SC 42 standard change an existing AIMS?

Publication of a guidance standard such as ISO/IEC 42105 adds no requirement to ISO/IEC 42001, so it does not by itself make an existing AIMS nonconforming. It can still give the team a better method for related controls, such as A.9 oversight measures. A review trigger in the AI policy, set to fire when a watched document reaches stage 60.60, keeps those updates planned.

When will ISO/IEC 42001 be revised?

ISO’s open data showed no amendment or revision of ISO/IEC 42001 registered on 30 September 2026, and its catalogue page still showed the 2023 first edition on 6 October 2026. A revision would show first in the catalogue, either as a review decision to revise (stage 90.92) or as a new project (stage 20.00). Until then, the 2023 text is the one certification bodies audit.

Share it :
About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

About the Author

Latha Karthigaa

Head of AI Governance at the Global AI Certification Council (GAICC)

A PhD-qualified AI governance leader in Software Engineering from the University of Auckland, she brings hands-on experience founding and exiting AI companies, and leading real-world AI solutions for finance and legal firms across the USA, UK, Australia, and New Zealand, combining governance, risk, compliance, and commercial expertise.

Start Your ISO/IEC 42001 Lead Implementer Training Today

4.8 / 5.0 Rating

Related Post