ISO/IEC 42001 (opens in a new tab) is the international standard for AI management systems, published in December 2023, and Canada adopted it unchanged as CSA ISO/IEC 42001:25 (opens in a new tab), a National Standard of Canada. No Canadian law requires it, so if a board member has asked whether you need to get certified, the honest answer is that no regulator is asking, though a procurement officer eventually will.
Last reviewed 29 July 2026
A management system is the internal machinery an organization runs to keep a promise: who decides, what gets written down, what gets checked, and what happens when something goes wrong. ISO/IEC 42001 applies that pattern to artificial intelligence across 51 pages that are still in their first edition (opens in a new tab), and because it shares the harmonized structure (opens in a new tab) used by ISO 9001, a company already certified to ISO 27001 finds much of the scaffolding familiar.
The requirements you get audited against sit in seven clauses: work out where AI sits in your business and who has a stake in it (context), get leadership to own an AI policy instead of delegating it to whoever is keenest (leadership), set objectives and treat the risks you find (planning), fund the work and make sure your people are competent (support), run the controls and keep records (operation), audit yourself and hold management reviews (performance evaluation), then fix what those turn up (improvement). What is AI-specific is mostly what you weigh under each heading, particularly impacts on the people a system is used on.
Annex A groups 38 reference controls under nine objectives, running A.2 through A.10 (opens in a new tab). The names in the table below are my shorthand, and so is the gloss beside them.
| Control objective | What sits under it |
|---|---|
| AI policy | A written policy, approved at the top, reviewed when things change |
| Roles and accountability | Named owners, who decides what, how a concern gets escalated |
| Resources | Knowing what you run: systems, data, compute, competent people |
| Impact assessment | Effects on individuals and society, beyond your own risk register |
| Building and retiring systems | Requirements, design, testing, release, monitoring, shutdown |
| Data handling | Provenance, quality, preparation, a record of what went in |
| Information for interested parties | What you tell users and regulators about purpose and limits |
| Day-to-day use | Rules for operators, including where a human stays in the decision |
| Suppliers and customers | Who is responsible when the model belongs to someone else |
Most people open Annex A and start ticking all 38 boxes. Clause 6.1.3 works the other way around: you determine what your own risk treatment needs, compare that against Annex A to catch anything you missed, and record the comparison in a Statement of Applicability (opens in a new tab) saying what you included, what you excluded and why. Notice how high up the standard sits: it tells you to have a use policy, and leaves what your staff check before a document goes out entirely to you.
An auditor certifies the management system, which is why no model, dataset or product can hold a 42001 certificate of its own. What trips people up is the scope statement, which can name specific services: Microsoft’s 42001 certificates are scoped to named Copilot and Foundry services (opens in a new tab) and not to the company as a whole. “Certified” alone tells you almost nothing, so the useful question is certified by whom, to what scope, valid until when.
No. Skipping it costs you nothing with any Canadian regulator, and the pressure comes from the buy side instead: bank, Crown-corporation and enterprise RFPs increasingly ask what AI governance you run, and their procurement teams write those questions by lifting headings out of whatever standard is in front of them.
CSA Group publishes the Canadian edition, which adopts ISO/IEC 42001:2023 without modification (opens in a new tab). A copy runs $280 CAD for a 71-page PDF (the ISO text plus CSA’s Canadian front matter), DRM-protected and licensed to one person, and ISO sells its own for CHF 225. Both are copyrighted (opens in a new tab), so your $280 buys one named person the right to read the standard, and the clause text stays the publisher’s.
The Standards Council of Canada runs the AI management systems accreditation scheme (opens in a new tab) here, though certificates from bodies accredited by ANAB, UKAS and other IAF signatories count too. MHM Advisory became the first SCC-accredited body (opens in a new tab) in September 2025, and three organizations now carry AIMS in their scope: Gaming Laboratories International, MHM Advisory, and PricewaterhouseCoopers LLP. Check a vendor’s certificate against the SCC directory (opens in a new tab) and IAF CertSearch (opens in a new tab).
| Where it comes from | What it requires |
|---|---|
| Ontario ESA (opens in a new tab), since 1 January 2026 | Employers with 25+ staff must disclose AI used to screen applicants in public job postings |
| Quebec, Law 25 (opens in a new tab), ss. 11 and 12.1 | Disclose exclusively automated decisions, explain them on request, keep the information a year |
| PIPEDA and OPC guidance (opens in a new tab) | Accountability, access and correction, none of it suspended because a model was involved |
| Competition Act (opens in a new tab) | Everything you say publicly about what your AI does |
| Sector regulators | OSFI on model risk, securities regulators on disclosure, and sector codes of conduct like the real estate Code of Ethics (O. Reg. 365/22 (opens in a new tab)), whose accuracy duties apply the same way whether a person or a model wrote the listing |
Employers with 25 or more employees, counted by headcount on the day a posting goes up, must state in a public job posting whether AI is used to screen, assess or select applicants. The duty covers screening a recruiting agency does for you, the statutory definition of AI is broad, and Ontario’s guide is explicit that no description of the system is needed, just the fact of its use. It landed with other new posting rules (opens in a new tab) on pay and follow-up.
Section 12.1, in force since September 2023, reaches any enterprise doing business in Quebec wherever it is based. Where a decision about someone rests exclusively on automated processing, you must say so no later than when you deliver the decision, and on request give the personal information used, the reasons and principal factors and parameters, and their right to have it corrected. The person also gets a genuine opportunity to put observations to a staff member who can review the decision, and section 11 requires keeping the information behind any decision about a person for a year.
Federal privacy law applies in full to AI systems, and the OPC’s position is that accountability does not thin out because a vendor’s model is in the loop. That regime is in motion: Bill C-36, the Protecting Privacy and Consumer Data Act (opens in a new tab), tabled 15 June 2026, would replace PIPEDA’s private-sector rules with transparency duties for significant automated decisions, a deletion right, and a new Digital Safety and Data Protection Commission. ISED is also consulting on AI transparency (opens in a new tab), including labelling of AI-generated content, until 23 September 2026.
The Act prohibits representations that are false or misleading in a material respect (opens in a new tab), judged on the general impression created rather than a literal reading, with a criminal track under s. 52 and a civil track under s. 74.01 where corporate penalties reach the greater of $10 million CAD and three times the benefit derived, or 3% of worldwide gross revenues where that benefit cannot be determined. Since June 2025 private parties can seek leave to bring these cases (opens in a new tab), so a competitor is a risk alongside the Bureau, and lawyers have a name for the AI version: AI washing (opens in a new tab).
All of which is why vendor wording repays a close read. “Certified” means an accredited body audited a management system and issued a certificate you can look up, while “aligned with ISO 42001” is unverifiable, since no register of aligned companies exists and no audit sits behind the phrase. ISO does not certify organizations, does not license its logo, and asks that its name stay out of product and service names (opens in a new tab), so a product or service marketed as “ISO-approved” is using a phrase ISO itself does not recognize.
The Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued in January 2025 (opens in a new tab), and no successor has been introduced. Ottawa appears to have chosen a multi-bill approach (opens in a new tab) instead, handling AI through privacy reform, consultation and sector rules.
The national AI strategy, AI for All (opens in a new tab), was published 4 June 2026 (opens in a new tab). Two pieces matter for governance: a promised Canada Trusted AI Certification, and renewed funding for the Standards Council’s AI work. Nothing has been issued under the certification yet, it has no published criteria or timeline, and the strategy never mentions ISO/IEC 42001. My guess, and it is only a guess, is that a domestic certification with federal procurement behind it will end up mattering more to Canadian buyers than 42001 does.
Buyers ask which of the three to follow, when a Canadian company selling into Europe is usually dealing with all three at once. Europe’s AI Act (opens in a new tab) is law: it sorts systems into risk tiers, some of its prohibitions are already in effect, and it reaches you if your system is used there. NIST’s AI Risk Management Framework (opens in a new tab) is voluntary US guidance, useful for thinking with and impossible to certify against, while ISO/IEC 42001 is the only one of the three that comes with an auditor and a certificate a buyer can check.
ISO/IEC 42005:2025 (opens in a new tab), from May 2025, covers how to run an AI system impact assessment. It sits on the guidance side of the family, so nobody gets certified to it, and for a small team it is the most usable document in the set.
Requirements for the auditors themselves live in ISO/IEC 42006:2025 (opens in a new tab), published in July 2025, and SCC has a bulletin out on transitioning certification bodies (opens in a new tab) to it. You will never read it, but it governs auditor competence, which is what makes a certificate mean anything.
Plan on four to twelve months (opens in a new tab) for a small organization: gap analysis, building the system, a stage 1 audit of your documentation, then a stage 2 audit of whether you do what you wrote. Stage 2 must follow within six months or stage 1 repeats, surveillance audits come annually, and recertification lands in year three.
Cost is harder to state honestly, since every published figure comes from someone selling implementation help and they disagree by an order of magnitude (opens in a new tab): the UK implementers quote GBP 8,000 to 15,000 all-in for an organization under 50 people, the American ones $85,000 to 150,000 USD (opens in a new tab) in first-year costs for a company of 50 to 200 people. Treat those as a wide vendor-sourced range, and note that having ISO 27001 already is the biggest single discount.
Usually not yet. Certification is proportionate when a customer, a regulator or an investor is asking, and premature when the honest reason is marketing. What suits almost everyone is the underlying discipline: a written AI policy with a named owner, a list of approved tools and what may never be typed into them, a rule about what a human verifies before anything goes out, and a quarterly review.
If you want a standard to anchor it on, CAN/DGSI 101:2025 (opens in a new tab) is a National Standard of Canada written for organizations under 500 employees, superseding CAN/CIOSC 101:2019 (R2021). It is aimed at machine-learning systems that make or drive automated decisions, it says generative tools count, and it points at the Treasury Board Directive on Automated Decision-Making, the OECD AI Principles and the NIST framework, which makes it a better first map than 42001 for a small Canadian firm.
No. There is no federal AI statute in force and no provincial rule requiring certification, so it becomes a practical requirement only when a customer’s procurement asks for it.
No. Certification covers an organization’s management system, though the certificate’s scope can name particular services. If a vendor says their model is certified, ask to read the scope.
Not on its own. The Act imposes legal obligations a management system standard does not discharge, though a working AI management system produces much of the evidence its high-risk requirements call for.
Certified means an accredited body audited the organization and issued a certificate with a defined scope, verifiable through SCC’s directory or IAF CertSearch. Aligned is self-declared, unverifiable, and potentially misleading depending on what a reader takes from it.
General information about standards and Canadian law, not legal advice. This area moves quickly, so check any date or figure against its source.