There is no legitimate free PDF of ISO/IEC 42001. The standard is copyrighted and sold by ISO and its national member bodies, which in India means the Bureau of Indian Standards. What you can read without paying is the scope and the table of contents on the ISO website, and that is usually enough to decide whether the standard applies to you. This page sets out what the document actually contains, what it asks an organisation to produce, and what you still need after you have bought it.
“ISO 42001 pdf” is one of the most common searches in AI governance, and the reason is easy to understand. Before committing to a management system, people want to see what they are committing to. The difficulty is that the standard is not published free, and the copies circulating on file sharing sites are unlawful, often incomplete, and sometimes out of date.
What you can read without buying it
- The official ISO page for ISO/IEC 42001:2023 shows the abstract, the scope and the full table of contents, including the titles of every clause and annex.
- National member bodies, including the Bureau of Indian Standards, sell the adopted text and list its contents.
- Certification bodies and consultancies publish summaries. Ours is below.
Anything offering the complete text as a free download is republishing copyrighted material without a licence. Using it in a certification programme is also a poor idea, because auditors work from the current text.
What is inside the standard
ISO/IEC 42001:2023 follows the same harmonised structure as ISO 27001 and ISO 9001, so anyone who has run a management system will recognise the shape of it. The requirements sit in clauses 4 to 10, and the controls sit in Annex A.
| Clause | What it requires |
|---|---|
| 4. Context | Identify the organisation’s role, whether it develops, provides or uses AI systems, and set the scope of the management system |
| 5. Leadership | An AI policy, assigned responsibilities, and management commitment |
| 6. Planning | AI risk assessment and treatment, the AI system impact assessment, and objectives for the system |
| 7. Support | Resources, competence, awareness, communication and documented information |
| 8. Operation | Running the risk treatment, the impact assessments and the AI system life cycle in practice |
| 9. Performance evaluation | Monitoring, internal audit and management review |
| 10. Improvement | Nonconformity, corrective action and continual improvement |
Annex A holds the controls, grouped into nine areas: policies for AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third party and customer relationships. Annex B explains how to implement each control, Annex C lists objectives and risk sources to consider, and Annex D covers using the management system across domains and sectors.
The two annexes that consume most of the effort in practice are the life cycle and the data controls, because they ask for evidence rather than documents. Our guide to ISO 42001 certification cost and timeline in India explains why that distinction drives both the fee and the schedule.
What the standard does not tell you
The text sets out what must exist, not what good looks like in your organisation. Three things people expect to find in it, and do not:
- Thresholds. There is no size or risk threshold that decides whether you need an AI management system. It is a business decision as much as a commercial one. Organisations reach it when they cannot say what AI they are running, who governs it, or what it could do to the people it affects, and they reach it again when a customer asks for proof.
- Templates. The standard describes required outcomes. The registers, system cards and assessment formats are yours to design.
- Legal compliance. Certification is not compliance with the EU AI Act or with any Indian requirement. It is evidence of governance, which regulators and customers may find persuasive.
How ISO 42001 fits India’s sector by sector approach
India has decided not to pass a single AI law. The India AI Governance Guidelines, issued by MeitY on 5 November 2025, set seven principles and six pillars, and leave the rules themselves to each sector’s regulator, supported by targeted amendments to existing law. For an Indian organisation, that means AI obligations arrive from your regulator rather than from a central statute, and they are arriving quickly.
ISO 42001 is not a substitute for any of them. What it does is give you one management system that produces most of the evidence they ask for, instead of a separate programme for each.
| Where the expectation comes from | What it asks for | Where ISO 42001 answers it |
|---|---|---|
| MeitY, India AI Governance Guidelines, November 2025 | Accountability, transparency, human oversight, grievance redress, and governance proportionate to risk | The AI policy and roles in Clause 5, risk and impact assessment in Clause 6, information for interested parties and use of AI systems in Annex A |
| RBI, FREE-AI framework, August 2025, with draft model risk management guidance following | A board approved AI policy, an inventory of models, life cycle governance from approval through change control, independent validation, periodic audit, AI incident reporting, and accountability for vendor supplied models | Clause 5 for the policy, the AI system life cycle and resource register controls, Clause 9 for internal audit and management review, and the third party controls in Annex A |
| SEBI, AI and ML reporting circulars since 2019, Regulation 16C from 2025, and the 2025 consultation on responsible AI use | Quarterly reporting of AI and ML systems, sole responsibility for AI tools whether built or bought, senior management oversight, model validation and documentation, bias testing, and independent audit | The same inventory and life cycle controls, verification and validation records, the data controls, and audits run independently of the delivery team |
| CDSCO, final guidance on medical device software, July 2026 | Risk classification of software as a medical device, technical documentation, an algorithm change protocol for models that keep learning, a software bill of materials, usability validation, and risk management covering cybersecurity and bias | Life cycle evidence, data quality and provenance records, and impact assessment. Note that ISO 42001 sits alongside the Medical Devices Rules and ISO 13485, and replaces neither |
| ICMR and telemedicine guidance | Human responsibility for clinical decisions, informed consent, and AI as an assistive tool rather than a decision maker | The human oversight and use of AI controls in Annex A, and the impact assessment that records where a person must remain in the decision |
| DPDP Act and Rules | Lawful processing, notice and consent, security safeguards, breach reporting and erasure for any personal data your AI systems touch | Nothing in ISO 42001 replaces this. The two programmes share the inventory, which is why we usually build it once. See our guide to data fiduciary duties |
Insurers should expect the same pattern from IRDAI, since the sectoral approach makes each regulator responsible for its own sector.
What this means in practice
- Banks, NBFCs and payment firms. FREE-AI already expects a board approved AI policy, a model inventory and independent validation. An AI management system produces those as ordinary outputs, and gives the auditor one place to look.
- Securities market participants. The liability for bought AI tools sits with you, whoever built them. The supplier and third party controls, plus your own validation before deployment, are what evidence that.
- Health technology. Certification does not license a product. What it does is make the licensing file easier to defend, because the life cycle and data records the regulator wants already exist.
- Everyone else. No regulator is asking yet, so the honest reason to certify is that a customer, an investor or an overseas client is.
Because these instruments are recent and some are still in consultation, check the current position with your regulator before building a programme around any one of them.
What to read while you decide
If you are still working out whether ISO 42001 is the right step, these are more useful than the standard itself:
- Our AIMS explainer (PDF), which walks through what an AI management system looks like in practice.
- What ISO 42001 certification costs in India, and how long it takes, with the figures from our engagements.
- ISO 42001 training, if you want the standard taught rather than read.
When you are ready to build the system, our ISO 42001 consulting page sets out how we run an implementation.
Frequently asked questions
No. ISO/IEC 42001:2023 is sold by ISO and its national member bodies. You can read the scope and table of contents free on the ISO website, but the full text is copyrighted, and copies offered free elsewhere are unauthorised.
From the ISO website, or from the Bureau of Indian Standards, which sells the adopted text. Certification bodies do not supply the standard.
Annex A groups its controls into nine areas, covering policies, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third party relationships.
No. ISO 42001 is a voluntary management system standard. The EU AI Act is law in the European Union. Certification can support an AI Act programme, but it does not satisfy it.
No, though it helps. The management system structure is shared, so an organisation already running ISO 27001 can extend procedures such as incident, supplier and change management rather than write new ones.
Rarely. The standard states required outcomes, not formats. Most of the work is building the AI system inventory and the records for each system, which the text does not prescribe.
Not automatically. FREE-AI is a set of recommendations for RBI regulated entities, and ISO 42001 is a management system standard. The overlap is substantial, covering the AI policy, the model inventory, life cycle governance, independent validation and audit, so an AI management system produces much of the evidence FREE-AI expects. Compliance with RBI expectations remains a matter between you and your regulator.
No single statute. MeitY’s India AI Governance Guidelines of November 2025 confirm a sectoral approach, with RBI, SEBI, CDSCO and other regulators setting rules for their own sectors, alongside existing law such as the DPDP Act.
No. Licensing under the Medical Devices Rules and a quality management system under ISO 13485 remain separate obligations. ISO 42001 governs how you develop and run AI, and the records it produces support both.
Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that implements AI management systems. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on ISO/IEC 42001:2023 and on Indian sectoral guidance as in force on 24 September 2026. It is not legal advice. Last reviewed 24 September 2026.