What ISO 42001 actually is — and what it is not

ISO/IEC 42001:2023 is the world's first international standard for AI Management Systems. Published in December 2023 by the International Organization for Standardization, it specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System — known as an AIMS — within organizations that develop, provide, or use AI-based products or services.

Think of it as the AI equivalent of ISO 13485. Just as ISO 13485 governs your Quality Management System for medical device design and manufacturing, ISO 42001 governs your AI Management System — the governance, risk management, transparency, and lifecycle controls your organization applies to every AI system you develop or deploy.

// What ISO 42001 Is NOT

ISO 42001 is not a technical standard for how to build AI — it does not specify algorithms, architectures, or performance thresholds. It is a management system standard — it specifies how your organization governs, oversees, documents, and continuously improves its AI systems. The distinction matters: passing ISO 42001 certification means your governance processes are sound, not that any specific AI model has been validated.

ISO 42001 follows the same High Level Structure used by ISO 9001, ISO 27001, and ISO 45001 — which means organizations already certified under those standards have a familiar framework to build on. The structure covers context, leadership, planning, support, operation, performance evaluation, and improvement — the same plan-do-check-act logic that governs every modern management system standard.

The standard is applicable to any organization — regardless of size, sector, or geography — that develops, provides, or uses AI systems. For MedTech companies developing SaMD or AI-enabled devices, it is rapidly becoming a baseline expectation, not an optional certification.

Why MedTech companies need to act now — not in 2027

The EU AI Act deadline for CE-marked MDR/IVDR SaMD requiring Notified Body conformity assessment is August 2, 2027. But waiting until 2027 to start is a serious mistake — and here is why.

Notified Bodies are already asking ISO 42001-style questions in MDR audits right now. Regulatory professionals in the field are reporting that Notified Bodies are incorporating EU AI Act expectations into their MDR and IVDR assessments well ahead of the legal deadline. Companies that are not prepared are already experiencing friction in their audit cycles.

// The Documentation Reality

The documentation work required for ISO 42001 — training data governance, bias assessment, human oversight design, AI risk management — takes considerable time to complete properly. Organizations that start in 2026 will be building their AIMS while simultaneously managing their existing ISO 13485 obligations, product development, and regulatory submissions. Starting now gives you the runway to do this properly. Starting in late 2026 means doing it under pressure.

There is also a competitive dimension. Greenlight Guru — one of the leading eQMS platforms for medical device companies — achieved ISO 42001 certification in July 2026, covering both its eQMS and clinical EDC products. They described it as covering how AI is designed, trained, tested, deployed, monitored, and updated across all their products. They are the first medtech-focused quality management platform to publicly announce this dual-product scope. The signal is clear: ISO 42001 is becoming a competitive differentiator in the MedTech software space, and early movers are already using it as one.

How ISO 42001 connects to your existing ISO 13485 QMS

The most common question MedTech companies ask about ISO 42001 is whether they need to build a completely separate management system alongside their existing ISO 13485 QMS. The answer is no — but the integration requires deliberate planning.

ISO 13485 and ISO 42001 share the same fundamental logic — plan processes, implement them, review results, and improve continuously. Companies that already operate a mature ISO 13485 QMS start from a solid foundation. The risk-based thinking, documented procedures, management review cycles, and corrective action processes that ISO 13485 requires are directly transferable to ISO 42001.

Area ISO 13485 (Medical Device QMS) ISO 42001 (AI Management System)
RISK MANAGEMENT ISO 14971 risk management for devices AI-specific risk assessment including bias, transparency, and unintended outputs
DESIGN CONTROLS Design and development lifecycle controls AI system lifecycle from training data through deployment and monitoring
DOCUMENTATION Device History File, Design History File AI system technical documentation, training data records, performance monitoring logs
SUPPLIER CONTROLS Supplier qualification and monitoring Third-party AI services, foundation models, APIs, cloud-hosted AI platforms
POST-MARKET Post-market surveillance and CAPA Continuous AI performance monitoring, drift detection, revalidation triggers
AUDIT CYCLE Internal audits against ISO 13485 clauses Internal audits against ISO 42001 clauses — can be integrated into existing audit calendar

The critical difference is that ISO 13485 was not designed with AI in mind. Its supplier controls, design controls, and post-market surveillance requirements do not naturally capture the specific governance challenges of AI — training data quality, algorithmic bias, model drift, transparency of AI outputs, and the governance of continuously learning systems. ISO 42001 fills precisely those gaps.

// Integration Approach

The most effective approach is to extend your existing ISO 13485 QMS to incorporate ISO 42001 requirements rather than building a parallel system. Your AI risk management feeds into your existing ISO 14971 risk management process. Your AI training data governance extends your existing supplier and material controls. Your AI post-deployment monitoring extends your existing post-market surveillance. The governance infrastructure already exists — ISO 42001 specifies what it needs to cover for AI.

What ISO 42001 actually requires — the six critical areas

ISO 42001 covers eleven clauses following the High Level Structure. For MedTech companies, six areas represent the most significant new requirements relative to what ISO 13485 already covers:

1. AI system inventory and scope definition

Before implementing ISO 42001, your organization must identify every AI system associated with your products and services. This includes internally developed machine learning models, third-party AI services, foundation models and APIs, cloud-hosted AI platforms, and any embedded AI functionality within larger medical devices. Most MedTech companies discover they have more AI exposure than they initially realize — particularly through third-party services and platforms embedded in their workflows.

2. AI-specific risk assessment

ISO 42001 requires a structured AI risk assessment that goes beyond traditional ISO 14971 device risk management. The assessment must cover risks specific to AI — algorithmic bias, transparency failures, unintended outputs, data quality issues, and the governance risks of AI systems that update or adapt over time. For SaMD companies, this AI risk assessment must integrate with your existing ISO 14971 risk management file — they are not separate documents but complementary layers of the same risk picture.

3. Training data governance

This is the area where most MedTech companies have the largest gap. ISO 42001 requires documented governance for the data used to train, validate, and test AI systems — covering data quality, representativeness, bias examination, and provenance. For medical device AI, the EU AI Act layers additional requirements on top of this: training datasets must be examined for biases that affect health outcomes or fundamental rights, and the examination must be documented in the technical file. The AI Act's technical documentation requirements in this area exceed FDA 510(k) standards.

4. Transparency and human oversight

ISO 42001 requires documented procedures for AI transparency — how the AI system's outputs are explained to deployers and end users — and for human oversight mechanisms that allow appropriate intervention in AI decision-making. For clinical decision support AI, this maps directly to FDA's expectations around the human-in-the-loop and to EU AI Act Article 14's human oversight requirements. Companies with mature PCCP documentation are well positioned here — the change control and monitoring discipline required by PCCP is directly relevant to ISO 42001's oversight requirements.

5. Post-deployment monitoring and continual improvement

ISO 42001 requires an ongoing monitoring program for AI system performance after deployment — covering performance drift, output consistency, bias emergence, and security vulnerabilities. For MedTech companies, this connects to FDA's post-market surveillance requirements and to the PCCP's monitoring specification. Companies that have built a credible PCCP already have the monitoring infrastructure ISO 42001 requires — they need to document it explicitly against ISO 42001 clauses.

6. Supplier and third-party AI governance

Perhaps the most practically challenging requirement for most MedTech companies. ISO 42001 requires governance controls for every AI system your organization uses — not just the ones you build. This includes foundation models accessed via API, cloud AI platforms, and third-party AI components embedded in your products or workflows. For many MedTech companies, this means establishing formal governance for AI services they have been using informally — documenting their intended use, risk assessment, monitoring approach, and exit strategy.

ISO 42001 and the EU AI Act — what maps and what does not

ISO 42001 certification is increasingly described as a foundation for EU AI Act compliance. Research suggests approximately 40-50% overlap in high-level requirements between the two frameworks. But ISO 42001 certification does not automatically mean EU AI Act compliance — and MedTech companies need to understand precisely where the gaps are.

// Critical Point — Conformity Assessment

The EU AI Act requires high-risk AI systems to undergo conformity assessment before being placed on the EU market. For CE-marked MDR/IVDR SaMD with AI components requiring Notified Body assessment, EU AI Act compliance will need to be confirmed by your Notified Body — not just by ISO 42001 certification alone. ISO 42001 gives you the governance foundation. The Notified Body confirms you have met the specific EU AI Act legal obligations on top of it.

Area ISO 42001 covers EU AI Act requires additionally
RISK MANAGEMENT AI risk assessment methodology and documentation Article 9 — specific risk management system across the full AI lifecycle
DATA GOVERNANCE Training data quality and bias examination principles Article 10 — detailed data governance including bias examination for health outcomes and fundamental rights
TECHNICAL DOCUMENTATION AI system documentation framework Article 11 + Annex IV — specific documentation requirements that exceed FDA 510(k) standards
HUMAN OVERSIGHT Human oversight mechanisms and transparency Article 14 — specific human oversight measures with defined intervention capabilities
CONFORMITY ASSESSMENT Internal audit and certification by accredited body Notified Body conformity assessment — certification alone is insufficient

The most effective approach is to treat ISO 42001 as the operational foundation and layer EU AI Act specific legal obligations on top — rather than building two separate compliance programs. Start with ISO 42001 to build the governance infrastructure. Then map each EU AI Act article against your AIMS to identify gaps. The documentation effort overlaps significantly — training data governance, bias assessment, human oversight design, and monitoring programs serve both frameworks simultaneously.

What to do before your next Notified Body meeting

Given that Notified Bodies are already asking ISO 42001-style questions in MDR audits, here is what MedTech companies should have documented before their next Notified Body interaction:

// Pre-Notified Body Meeting Checklist
Complete AI system inventory — document every AI system in your products and services, including third-party APIs, foundation models, and embedded AI components
Conduct initial AI risk assessment — map each AI system against ISO 42001 risk categories and integrate with your existing ISO 14971 risk management file
Document training data governance — provenance, quality controls, bias examination, and representativeness for each AI system's training dataset
Define human oversight mechanisms — how your AI system's outputs are reviewed, challenged, and overridden by appropriate human decision-makers
Establish post-deployment monitoring — performance drift detection, revalidation triggers, and ongoing bias monitoring aligned with your PCCP if applicable
Map to EU AI Act Articles 8-17 — if your SaMD requires Notified Body MDR assessment, document your coverage of each Article ahead of the 2027 deadline
Get an independent evaluation — Notified Bodies will ask whether anyone outside your organization has assessed your AI governance. Independent third-party evaluation provides documented evidence that this question was asked and answered before the audit
// The Notified Body Reality

Notified Bodies are not waiting for 2027 to ask about AI governance. Companies that arrive at their next MDR audit with documented ISO 42001 alignment, a training data governance record, and independent third-party AI evaluation evidence will move through that audit faster than those who cannot yet answer basic questions about how their AI systems are governed. The documentation gap is the audit risk — and it is closeable now.


🎓
NR Koka — Founder, ClearanceAI
20+ years in design assurance and regulatory compliance across medical device and AI systems. ClearanceAI provides independent third-party AI model evaluation for regulated industries — evaluating against ISO 42001, FDA 2025 AI Guidance (Draft), PCCP Final Guidance, NIST AI RMF, EU AI Act Articles 8-17, and SR 26-2. Our AI Regulatory Advisor Rajeev Yadav, PhD is a certified ISO 42001 Lead Auditor and former BSI Technical Assessor.

Is your AI governance ISO 42001 ready?

ClearanceAI evaluates AI models against ISO 42001, FDA 2025 AI Guidance (Draft), PCCP Final Guidance, NIST AI RMF, and EU AI Act Articles 8-17 — delivering a formal independent assessment your Notified Body, hospital, and payer clients can rely on. Our AI Regulatory Advisor Rajeev Yadav, PhD is a certified ISO 42001 Lead Auditor. Start with the free 2-minute assessment or request a full evaluation directly.