In healthcare and life sciences, ISO 42001 does one of two jobs depending on which AI you point it at. For clinical AI that meets the definition of a medical device, FDA's device rules and ISO 13485 already govern design, validation and change control, and 42001 adds what they do not ask about: where the training data came from, how the model performs across patient subgroups, what it does to the people on the receiving end, and what happens after deployment. For administrative AI (scheduling, coding, ambient documentation, patient messaging), no regulation governs the system itself. HIPAA governs the data and FDA does not reach it. ISO 42001 is the only certifiable management-system standard that covers these tools, and in our experience that is where most of a healthcare organisation's AI exposure sits. If you already run a 13485 or GMP quality system, most of the management-system clauses exist and the work is adding an AI layer.
Two kinds of AI, two different gaps
| Clinical AI | Administrative AI | |
|---|---|---|
| Typical tools | Imaging analysis, sepsis and deterioration alerts, dosing support, remote monitoring, EHR features that drive care decisions | Scheduling models, coding assistants, ambient scribes, portal reply drafting, chatbots, prior authorisation automation |
| What already governs it | FDA device rules, the Quality Management System Regulation incorporating ISO 13485, ISO 14971, IEC 62304 | HIPAA for the data; a patchwork of state laws; payer contract terms |
| Who those rules bind | The manufacturer, not the hospital that uses the tool | Nobody, as far as the model's behaviour is concerned |
| What ISO 42001 adds | Data governance, subgroup performance, impact on affected people, post-deployment monitoring, a system for the deployer | The entire governance layer |
Clinical AI: what FDA and ISO 13485 cover, and what they leave out
If you make the device
Since February 2026, FDA's Quality Management System Regulation incorporates ISO 13485 by reference, so a US device maker's quality system is now effectively a 13485 system. ISO 14971 handles risk, IEC 62304 the software lifecycle, and FDA's guidance on predetermined change control plans (finalised December 2024) lets you update a model without a new submission each time.
The overlap with ISO 42001 is real, but so is the gap. ISO 13485 asks whether the device meets its specification and whether the process that built it was controlled. It does not ask:
- Where the training and validation data came from, whether you had the right to use it, and whether it represents the population the device will serve.
- How the model performs by patient subgroup. A 14971 file lists a hazard called "incorrect output." It rarely asks whether that output is three times more likely for patients over 80.
- What the device does to the people it affects beyond the hazard chain. The AI system impact assessment (clause 6.1.4, Annex A area A.5) covers individuals, groups and the clinicians who use the tool, including fairness and autonomy.
- What happens after release. Post-market surveillance under 13485 is complaint-driven. 42001 treats operation and monitoring as a lifecycle stage, with drift and retraining decisions recorded.
For a device maker, 42001 replaces nothing. It answers the questions your FDA reviewer, your notified body and your hospital customers are starting to ask that 13485 was never written to answer.
If you deploy the device
This is the side that gets missed. FDA regulates the manufacturer. Once a sepsis model or an imaging algorithm is cleared and sold, the hospital's use of it is the practice of medicine, which FDA does not regulate. No federal rule requires a hospital to monitor how the model performs on its own patients, define when a clinician may override it, train the people who see its output, or notice when a vendor update changes its behaviour.
Two things have started to change that. The 2024 revision of the Section 1557 nondiscrimination rule obliges covered providers to make reasonable efforts to identify patient care decision support tools that use race, colour, national origin, sex, age or disability as inputs, and to mitigate the discrimination risk. That obligation sits on the hospital, whether or not the tool is an FDA device. And in 2025 The Joint Commission, with the Coalition for Health AI, published guidance on responsible use of AI in healthcare, which shows where accreditation is heading.
Neither gives a hospital a management system. ISO 42001 does. For a deployer, the relevant Annex A areas are the use of AI systems (intended use, human oversight), third-party relationships and the impact assessment. The AI inventory alone is worth the exercise: in our experience most health systems cannot list every AI feature switched on inside their EHR, because the vendor enabled several during a routine upgrade.
Administrative AI: the tools nothing else governs
Most administrative tools are outside FDA's reach on purpose. The 21st Century Cures Act carved several categories of clinical decision support out of the device definition, and documentation, scheduling and billing tools were never devices. HIPAA applies, but HIPAA governs protected health information: who can see it, how it is secured, what the business associate agreement says. It has nothing to say about whether the scheduling model quietly gives worse slots to patients with a history of no-shows, whether the coding assistant upcodes, or whether the drafted reply to a patient who mentioned chest pain missed the urgency.
State law is filling in around the edges, unevenly. California requires a disclaimer on generative-AI patient communications unless a licensed provider reviews the message first. Texas's TRAIGA took effect on 1 January 2026, and Colorado replaced its 2024 AI Act with a narrower law (SB 26-189) effective 1 January 2027. None of this is settled.
What none of it provides is a way to run these tools as a system, and the aggregate risk here is often higher than on the clinical side. Clinical tools are few, expensive, scrutinised and used by clinicians trained to doubt them. Administrative tools are numerous, cheap, invisible to leadership and used by staff under time pressure with no clinician in the loop. A widely cited 2019 study in Science found a commercial care-management algorithm underestimated the needs of Black patients because it used past healthcare spending as its proxy for need. That was an administrative tool, and no device regulation would have caught it.
For these tools, ISO 42001 is doing the whole job, because nothing else requires an inventory, a policy, an impact assessment, human-oversight design, transparency to patients or monitoring. That is why the administrative list usually decides the scope of a healthcare 42001 project: the clinical list is short and already documented, while the administrative list is long and nobody owns it.
How ISO 42001 layers onto ISO 13485 and a GMP quality system
ISO 42001 is an Annex SL standard, so its clauses 4 to 10 follow the same structure as ISO 13485, ISO 9001 and ISO 27001. If you hold 13485, or run a pharmaceutical or supplement plant under 21 CFR 210/211 with a mature quality system, the following already exist and get extended rather than duplicated:
| Existing element | What 42001 needs from it |
|---|---|
| Document and record control | Add the AI policy, AI inventory, impact assessments and Statement of Applicability |
| Management review | Add AI performance, incidents and impact assessment results as inputs |
| Internal audit | Add the AI management system to the programme; one integrated audit is fine |
| CAPA / nonconformity | Route AI incidents (wrong outputs, drift, override failures, complaints) through the existing process |
| Supplier controls | Extend qualification to AI vendors: model versioning, change notification, data handling, performance evidence |
| Risk management (ISO 14971; quality risk management for GMP) | Keep the method; add AI-specific hazards and, separately, the impact assessment |
| Computer system validation / software assurance | Extend to AI tools in the quality system, allowing for non-deterministic output |
What is genuinely new is smaller than most people expect:
- The AI policy and roles (clauses 5.2 and 5.3), including who is accountable for each AI system.
- AI risk assessment and treatment (clauses 6.1.2 and 6.1.3), which reuse your method but look at different hazards.
- The AI system impact assessment (clause 6.1.4), which has no equivalent in 13485 or GMP and is described below.
- The Statement of Applicability, stating which of Annex A's nine control areas apply and justifying the ones that do not; our article on which controls apply walks through that decision.
- Data governance for AI: in a GMP plant, usually the first honest inventory of which datasets the AI reads and whether they are the validated ones.
For GMP manufacturers there is now a concrete reason that did not exist a year ago. In April 2026 FDA issued a warning letter to Purolea citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c): AI-written specifications, procedures and master production records released without qualified review. It is the first FDA citation for AI-generated quality records, and it tells you what an investigator will ask next: which records did AI touch, who reviewed them, against what, and where is the evidence. ISO 42001's controls on human oversight and the use of AI systems answer those questions in a form an investigator recognises. We built a fixed-fee AI-in-the-quality-system review ($5,000) for this situation, and our page for GMP manufacturers covers the Part 211 and Part 11 angles.
What an impact assessment looks like for a patient-facing tool
The impact assessment is the document an auditor, an FDA investigator and a plaintiff's lawyer will all ask to see, and the one healthcare organisations most often get wrong, either by treating it as a 14971 risk analysis with "AI" added or by writing a two-page ethics statement with no content. Here is what one looks like for a language model that drafts replies to patient portal messages, which a nurse or physician edits and sends.
-
System description and intended use. What the model is, who supplies it, which version, and what it is for. Just as important, what it is not for: it sends nothing unreviewed and it does not answer excluded categories (medication changes, abnormal results, anything flagged urgent).
-
Who is affected. Patients receiving replies and the clinicians whose names go on the messages. Then the subgroups that matter: patients writing in a language other than English, older patients, patients with cognitive or visual impairment.
-
Intended benefits, stated concretely. Faster reply times, less after-hours documentation, more consistent tone. If you cannot state the benefit in measurable terms you cannot later show whether the tool earned its risk.
-
Foreseeable harms, by category. Clinically wrong content the reviewer does not catch. A missed red flag, where the patient mentions symptoms that should have triggered a call and the draft answers the question they asked instead. Automation bias, where reviewers stop reading closely because the drafts are usually fine. Worse performance in other languages. Patients not knowing they are reading machine-drafted text.
-
Data. What the model receives (the message, chart context, prior messages), where it goes, whether the vendor retains or trains on it, and what the business associate agreement says about each. This is where HIPAA and 42001 meet.
-
Performance evidence. How you tested it before go-live: a reviewed sample of drafts across message categories and the subgroups above, scored by clinicians for accuracy, missed urgency and tone. Vendor benchmarks are context, not evidence.
-
Human oversight design. How much time the reviewer has, whether the interface makes editing easier than approving, whether batch approval is possible (it should not be), and what edit rate you expect. A near-zero edit rate is a warning sign.
-
Transparency. What the patient is told and where. California's disclosure rule is a floor for organisations operating there; the standard expects you to decide for yourself.
-
Monitoring. Edit rate by reviewer and message type, missed escalations found by periodic sample audit, patient complaints mentioning replies, turnaround time, and vendor version changes. Name the person who reads the numbers.
-
Decision, residual risk and review triggers. Who approved deployment, what residual risk they accepted, and what reopens the assessment: a version change, a new message category, a vendor change, an incident, or twelve months elapsing.
Written properly this runs eight to fifteen pages, and most of it is reusable for the next tool. It differs from a device risk file in three ways: it weighs benefits alongside harms, it looks explicitly at fairness across groups, and it is revisited rather than filed. It is also the document that does most to protect the organisation when something goes wrong, because it shows the harm was foreseen and controlled.
Cost, timeline and the EU question
Typical time from gap assessment to certificate is four to twelve months, and organisations with a working 13485 or GMP system are usually at the short end because most clauses need extension rather than creation. What stretches the calendar is the administrative-AI inventory and certification body availability. Fewer than 100 organisations held a 42001 certificate in January 2026 and roughly 350 did by spring 2026, and the bodies report auditor backlogs, with some Stage 2 audits waiting six months or more. Book the audit when you start. Our realistic timeline article goes phase by phase.
On cost, 2026 market pricing for a first-year programme at a 50-to-200-person organisation is commonly quoted at $85,000 to $150,000 including internal time, tooling and the certification body; a health system with 40 AI tools and a 30-person device company are different projects. Our ISO 42001 gap assessment is a fixed $9,750 and produces the scope, the inventory and the prioritised gap list the rest of the budget depends on. The full budget guide breaks down where the money goes.
For device makers selling into Europe, one clarification. EN ISO/IEC 42001:2026 became a European standard in March 2026, but no harmonised standard for the EU AI Act has been cited in the Official Journal, so a 42001 certificate gives no presumption of conformity with the Act. That job belongs to prEN 18286, targeted for late 2026, and under the 2026 revisions the Act's high-risk obligations (which cover most medical devices) were pushed back to December 2027 and August 2028. Build on 42001, but do not tell your board it is the finish line.
Where to start
Start with the inventory, and do both columns. Ask every department head which tools produce a recommendation, a draft, a score or a decision, and ask your EHR vendor for every AI feature enabled in your instance. In my experience the administrative list surprises the leadership team every time.
Then decide what you are certifying. ISO 42001 lets you scope the management system, so a device company can start with its product line and a health system with its patient-facing tools, and expand from there. An honest, defensible scope beats an ambitious, unaudited one.
Then get the gap assessed by someone who has seen the inside of a 13485 or GMP system, because the efficiency of this project comes from extending what you have. That is the work on our ISO 42001 consulting page, and the gap assessment is the fixed-price first step. If your immediate concern is AI-written records inside a regulated quality system, the $5,000 records review is the faster answer and stands on its own.
Frequently Asked Questions
Does a hospital need ISO 42001 if its AI tools are already FDA-cleared?
FDA clearance covers the manufacturer, not the hospital that deploys the tool. Nothing in the clearance requires the hospital to monitor performance on its own patients, define override procedures or train clinicians, and ISO 42001 is the standard that puts those deployer obligations into a system.
Does ISO 42001 replace ISO 13485 for AI-enabled medical devices?
No. ISO 13485 remains the quality system for the device, and FDA's Quality Management System Regulation now incorporates it. ISO 42001 adds the AI-specific pieces 13485 does not ask for, such as data provenance, bias by patient subgroup, impact on affected people and monitoring after release.
Is an ambient AI scribe or a patient-messaging chatbot a medical device?
Usually not. Documentation, scheduling, coding and most patient-communication tools fall outside FDA's device definition, and HIPAA governs the data they handle rather than how the model behaves. That is the gap ISO 42001 fills.
How long does ISO 42001 certification take for an organisation with ISO 13485 or a GMP system?
Four to twelve months from gap assessment to certificate is typical, and organisations with a working 13485 or GMP quality system are usually at the short end because the management-system clauses already exist. Certification body backlogs can add several months, so book the Stage 2 audit early.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.