Strategy 12 min read

ISO 9001 Manufacturer Adding AI: Do You Need ISO 42001?

J

October 06, 2026

Short Answer: Should an ISO 9001 Manufacturer Get ISO 42001?

Maybe, and the honest answer depends on what your AI is doing and who is asking about it. If you are using AI to draft emails or summarize meeting notes, your existing ISO 9001 system probably covers you with a few added controls. If AI is touching product quality decisions, inspection results, supplier scoring, or anything a customer or regulator will hold you accountable for, ISO/IEC 42001:2023 becomes a serious option. It is the first certifiable management system standard written specifically for AI, and for an ISO 9001 shop it is a smaller step than most people expect.

I get this question from manufacturers a lot, usually phrased some version of "we already have a QMS, why would we need another standard?" It is a fair question. In my view, the best way to answer it is to look at what your ISO 9001 system already does well, where AI breaks the assumptions it was built on, and what a customer is actually asking when they say "do you have 42001?"

What Your ISO 9001 System Already Gives You

ISO 42001 follows the same harmonized structure (Annex SL) as ISO 9001:2015, with clauses 4 through 10 covering context, leadership, planning, support, operation, performance evaluation, and improvement. That matters, because the management system machinery you already run carries over directly:

  • Document and record control (ISO 9001 clause 7.5) maps to 42001 clause 7.5.
  • Internal audit (clause 9.2) and management review (clause 9.3) use the same clause numbers in both standards.
  • Nonconformity and corrective action (ISO 9001 clause 10.2) is the same discipline in 42001 clause 10.2.
  • Competence and awareness (clauses 7.2 and 7.3) apply to people who build, buy, or use AI just as they do to operators and inspectors.
  • Control of externally provided processes, products and services (ISO 9001 clause 8.4) is the natural home for AI vendors and model providers.

If you have a functioning QMS, you are not starting from zero. You are extending a system you already know how to run to a new category of risk. That is the main reason I tell ISO 9001 companies that 42001 integration is usually less painful than a first-time certification would be.

Where AI Breaks the Assumptions Behind ISO 9001

ISO 9001 assumes that a process, once validated and controlled, behaves consistently. A torque wrench calibrated to its schedule gives you a known uncertainty. A work instruction produces a predictable output. AI does not behave that way, and this is where the gap opens up.

Three things change when AI enters your operations:

  1. The process can change without anyone changing it. A machine learning model can drift as input data changes, even if no one touched the code. ISO 9001 clause 8.5.6 (control of changes) was written for deliberate changes, not gradual statistical drift.
  2. The output is probabilistic. A vision system that flags defects will sometimes be wrong in ways that are hard to predict. Clause 7.1.5 on monitoring and measuring resources asks you to ensure resources are fit for purpose, but it does not tell you how to validate a model's behavior across the range of conditions it will meet on your line.
  3. Data becomes a controlled input. In a traditional QMS, data is mostly a record. In an AI system, data is raw material. Training data quality, provenance, and bias become quality characteristics in their own right.

ISO 42001 addresses these directly. Clause 6.1.2 requires an AI risk assessment, clause 6.1.4 requires an AI system impact assessment process, and Annex A organizes 38 controls under nine control objectives, including AI system lifecycle (A.6), data for AI systems (A.7), and third-party and customer relationships (A.10). None of those topics has a dedicated home in ISO 9001.

ISO 9001 vs ISO 42001: What Each One Covers

Topic ISO 9001:2015 ISO/IEC 42001:2023
Primary focus Consistent products and services that meet customer and regulatory requirements Responsible development, provision, and use of AI systems
Structure Annex SL, clauses 4-10 Annex SL, clauses 4-10
Risk approach Risk-based thinking (clause 6.1) Formal AI risk assessment (6.1.2) and AI system impact assessment (6.1.4)
Data Documented information and records (7.5) Data for AI systems, including quality and provenance (Annex A, A.7)
Suppliers External provider control (8.4) Third-party and customer relationships (Annex A, A.10)
Lifecycle Design and development (8.3) AI system lifecycle controls (Annex A, A.6)
Transparency Customer communication (8.2.1) Information for interested parties (Annex A, A.8)
Certifiable Yes Yes

The overlap is real, and so are the differences. ISO 42001 is not a rebranded quality manual. It asks questions your QMS never had to answer, such as whether anyone affected by your AI system has been considered, and whether you can explain what the system is doing.

Which AI Uses Trigger the Need for ISO 42001?

Not every AI use justifies a certification project. I think about it as three tiers.

Tier 1: Productivity tools. Staff using a general-purpose assistant for drafting, translation, or summarization. Your answer here is policy, training, and acceptable-use rules. A documented control inside your existing QMS is usually enough. Certification is hard to justify on this tier alone.

Tier 2: AI inside quality-relevant processes. Machine vision for inspection, predictive maintenance, demand forecasting that drives production planning, AI-assisted supplier scoring, automated document review for compliance. Here your ISO 9001 system is directly affected, and an auditor or customer may ask how you validate and control the AI. This is where an ISO 42001 gap assessment earns its cost.

Tier 3: AI in your product or in customer-facing decisions. Embedded AI in equipment you sell, AI that influences safety-relevant behavior, or AI whose outputs your customers rely on. At this tier, the question is less "should we" and more "when." Customers, and in some markets regulators, will expect formal governance. For example, Regulation (EU) 2024/1689 (the EU AI Act) requires providers of high-risk AI systems to operate a quality management system under Article 17, and a management system built to ISO 42001 is a sensible foundation for that work, though certification alone does not equal legal compliance.

If you are honestly in Tier 1, take your time. If you are in Tier 2 and growing, start planning now. If you are in Tier 3, you are probably already late.

What Does a Customer Mean When They Ask for ISO 42001?

This is the version of the question I hear most often: a customer's supplier questionnaire or vendor review lands in your inbox with a line asking whether you hold ISO 42001 certification, or have a plan to.

A few things are worth knowing before you respond.

First, find out what prompted it. Many customers are adding AI governance rows to every supplier questionnaire as a standard practice, and the question is generic. Others ask because they know you use AI in a process that touches their product. The second situation is a real requirement. The first may be satisfied with a documented AI policy, an inventory of AI systems, and evidence of risk assessment.

Second, ask what they will accept. Some customers want a certificate. Others will accept a gap assessment against 42001, a statement of applicability-style mapping, or a described roadmap with dates. It costs you nothing to ask, and the answer shapes your whole plan.

Third, do not claim conformity you cannot demonstrate. A phrase like "we align with ISO 42001" invites the follow-up request for evidence. If you say it, be ready to show the AI risk assessment, the impact assessment, and the system inventory behind it.

What Does Certification Actually Involve?

An ISO 42001 certificate is issued by a certification body after a staged audit, the same general model you already know from ISO 9001. In 2025, ISO and IEC published ISO/IEC 42006, which sets requirements for bodies that audit and certify AI management systems. That is good news for buyers of certification, because it raises the bar for auditor competence in a field where that competence is still thin.

For a manufacturer with a working QMS, the work usually breaks down like this:

  1. Define scope. Which AI systems, which sites, which roles (developer, provider, user). Many manufacturers are users and integrators of AI rather than developers, and that changes which Annex A controls will apply.
  2. Build an AI system inventory. You will be surprised what is in it. Embedded AI in machine controllers, SaaS features that quietly switched on, and shadow use by engineers all belong on the list.
  3. Run the AI risk assessment and impact assessment. Clause 6.1.2 and clause 6.1.4 are the heart of the standard. ISO/IEC 42005:2025 provides guidance on conducting AI system impact assessments.
  4. Write the Statement of Applicability. Annex A controls are selected based on your risk assessment, and you justify any exclusions, much as you would with ISO 27001.
  5. Extend your existing procedures. Add AI to supplier evaluation, change control, training, internal audit, and management review rather than building a parallel system.
  6. Audit, review, and certify. Internal audit and management review must happen before the stage 1 and stage 2 audits.

The most common mistake I see is building a separate AI governance binder that nobody in operations reads. Integrate it into the QMS you already run. If your internal auditor already audits your supplier controls, give that person an AI checklist and keep the cycle going.

Common Gaps I See in ISO 9001 Companies Starting With AI

These come up repeatedly in gap assessments:

  • No inventory of AI systems. You cannot assess what you have not listed.
  • Supplier approval ignores AI features. A vendor adds a machine learning feature in a software update and your approved-supplier file says nothing about it.
  • No validation criteria for AI outputs. The inspection model is "working," but no one has defined acceptable false-negative rates or who reviews edge cases.
  • Change control covers code but not data. A retraining event or a shift in input data should go through the same discipline as a process change under clause 8.5.6.
  • Training records cover tool use but not limits. Operators know how to use the system, but not when to override it.
  • Human oversight is assumed, not documented. If a person is supposed to review AI output before it affects a lot disposition, that review needs to be defined and evidenced.

A structured ISO 42001 gap assessment is a practical way to find these before a customer or an auditor does.

Should You Certify, or Just Align?

I think about this as a decision with three honest paths.

Path 1: Policy and controls inside your QMS, no certification. Appropriate for Tier 1 use and for companies that have not been asked for anything. Low cost, low risk, and it sets you up for later.

Path 2: Align to ISO 42001 and run an internal readiness assessment. Appropriate when AI is growing in Tier 2 processes and customers are starting to ask. You get most of the governance benefit and can answer questionnaires truthfully, without paying for certification before you need it.

Path 3: Certify. Appropriate when customers require it, when AI is part of your product, or when a certificate gives you a clear commercial advantage in tenders. Certification is a signal that someone independent has looked, and for some buyers that signal is the entire point.

None of these is wrong. The mistake is drifting into Path 3 because a questionnaire made you nervous, or staying on Path 1 because the project feels large. Both are decisions made by anxiety rather than by facts.

If you already hold ISO 9001, I have written more about how the two standards fit together on our page for ISO 9001 certified companies adding ISO 42001, and our ISO 42001 consultant page explains how we support the work.

A Practical First 30 Days

If you are not sure where you sit, here is what I would do in the next month, regardless of whether you eventually certify:

  1. List every AI-enabled tool and feature in use, including vendor features and anything engineers have set up on their own.
  2. Sort each into the three tiers above.
  3. For Tier 2 and Tier 3 systems, name an owner and write down what the system decides, what data it uses, and who reviews its output.
  4. Add AI to your next supplier evaluation cycle and your next management review agenda.
  5. If a customer has asked for 42001, reply with questions about what they need rather than a promise.
  6. Decide whether a formal gap assessment is warranted, based on the tier results.

That sequence costs you time rather than money, and it produces the evidence you would need for any of the three paths. It also tends to reveal something useful: most manufacturers find they have more AI than they thought and better controls than they feared.

The Honest Bottom Line

ISO 9001 gave you a habit of controlling what affects quality. ISO 42001 asks you to extend that habit to systems that learn, drift, and sometimes surprise you. For a manufacturer already comfortable with audits, corrective actions, and management review, that extension is a reasonable one. Whether it ends in a certificate depends on your customers, your products, and how far into the line AI is going to reach.

What would your last customer audit have looked like if the auditor had asked to see how you validate the AI system on your inspection line? If the answer makes you uncomfortable, you have your starting point.

Last updated: 2026-10-06

Frequently Asked Questions

Do I need ISO 42001 if I am already ISO 9001 certified?

Not automatically. ISO 9001 does not require ISO 42001, and many manufacturers can cover low-risk AI use with policies and controls inside their existing QMS. ISO 42001 becomes worth considering when AI affects quality-relevant processes, appears in your products, or when customers ask for certification in vendor reviews.

How much of ISO 42001 can I reuse from my ISO 9001 system?

A large share of the management system framework carries over, because both standards use the Annex SL structure with clauses 4 to 10. Document control, internal audit (9.2), management review (9.3), corrective action (10.2), competence, and supplier control can be extended. What is new is the AI risk assessment (6.1.2), the AI system impact assessment (6.1.4), and the Annex A AI-specific controls.

What should I say when a customer asks if we have ISO 42001?

Ask what prompted the question and what evidence they will accept. Some customers want a certificate, while others accept an AI policy, a system inventory, a risk assessment, or a dated roadmap. Avoid claiming alignment with the standard unless you can show the supporting records.

Is ISO 42001 certifiable like ISO 9001?

Yes. Organizations are audited by an accredited certification body in a staged process similar to ISO 9001. ISO/IEC 42006, published in 2025, sets requirements for bodies that audit and certify AI management systems.

Does ISO 42001 certification make us compliant with the EU AI Act?

No. Regulation (EU) 2024/1689 sets legal obligations, including a quality management system requirement for providers of high-risk AI systems under Article 17. An ISO 42001 management system can support that work, but certification alone does not demonstrate legal compliance.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.