One of the most common questions we receive at AICerty is some variation of: "We use ChatGPT / the OpenAI API / Copilot in our business. Do we need ISO 42001 certification?" It is a great question that does not have a simple yes/no answer — but by the end of this article, you will have a clear framework for deciding whether your use of AI tools triggers ISO 42001 or EU AI Act obligations.

The Short Answer

Using AI tools like ChatGPT internally for productivity purposes (drafting emails, summarizing documents, brainstorming) does not automatically require ISO 42001 certification. However, if you are integrating AI tools into customer-facing products, using AI to make decisions that affect individuals, or operating in a regulated sector where AI governance is expected, certification becomes highly relevant and may effectively be required.

The key question is not which AI tool you use — it is what you do with it and what risk that creates for others.

Understanding the ISO 42001 Scope Question

ISO 42001 applies to organizations that "develop, provide, or use AI-based products or services." This is deliberately broad. Under a strict reading, virtually any organization that uses AI tools in its operations falls within the potential scope of the standard.

However, the standard is also designed to be proportionate. The scope of your AIMS should reflect the materiality of your AI activities — the significance of the AI systems you use, the risks they pose, and the expectations of your stakeholders. An organization using ChatGPT to draft internal HR memos faces fundamentally different AI risks than one using an AI model to make credit decisions or diagnose medical conditions.

ISO 42001 is not designed to require that every company using a productivity AI tool builds a full-blown AI Management System. It is designed to ensure that organizations whose AI activities create meaningful risks for others govern those activities responsibly.

When Does Using AI Tools Trigger ISO 42001 Relevance?

Customer-Facing AI Applications

If you are using OpenAI's API, Anthropic's Claude, Google's Gemini, or similar models to power features in your own product — a chatbot, a recommendation engine, an automated decision-making feature — then you are effectively a provider of an AI system. Your customers are exposed to AI-driven outputs, and the governance of that AI is your responsibility, not OpenAI's or Anthropic's.

In this scenario, ISO 42001 is directly relevant. You need to understand and govern the AI system you have built — even if the underlying model is a third-party API. Questions you must answer include: What data is the model processing? What decisions does it influence? What happens if it produces incorrect, biased, or harmful outputs? What oversight mechanisms are in place?

AI-Assisted Decision Making About Individuals

Using AI tools to make or significantly influence decisions about individuals — hiring decisions, loan approvals, insurance pricing, content moderation outcomes, medical recommendations — creates AI governance obligations regardless of whether the underlying model is built in-house or accessed via API.

Under the EU AI Act, several of these use cases fall into the high-risk AI system category. Under GDPR, using AI for automated individual decision-making triggers specific obligations including the right to explanation and the right to human review. ISO 42001 provides the governance framework for managing these obligations systematically.

Regulated Sectors

In financial services, healthcare, insurance, legal, and other heavily regulated sectors, AI governance is increasingly expected by regulators even where not yet formally required. In the UK, the FCA's approach to AI in financial services; in the EU, the EBA and EIOPA guidelines on AI in banking and insurance; in healthcare, the FDA's AI/ML software framework — all signal that AI governance is becoming table stakes for regulated entities.

For organizations in these sectors, ISO 42001 certification provides a credible, internationally recognized demonstration of AI governance maturity.

Enterprise and Government Sales

Increasingly, enterprise and government procurement processes include AI governance requirements. RFPs (requests for proposals) for software contracts now routinely ask: Do you have an AI governance framework? What AI certifications do you hold? How do you manage AI risk in your products? ISO 42001 certification provides a clear, auditable answer to these questions and can be the difference between winning and losing significant contracts.

What About OpenAI's Own Compliance?

OpenAI and other major AI providers have pursued their own compliance programs, including ISO 27001 certification and various security audits. However, their compliance covers their own operations as a provider — not your use of their APIs or your responsibility as a deployer of AI systems built on their infrastructure.

The EU AI Act makes this particularly clear. Under the Act, when you build a product using a third-party AI model via API, you are typically classified as the "deployer" of a high-risk AI system if the use case falls within the high-risk categories — and as the deployer, you have your own obligations regardless of what the model provider does.

Internal Tools vs. Customer-Facing AI: A Practical Framework

Here is a practical way to think about whether your AI tool use triggers governance requirements:

What Regulators Look For

When regulators assess AI governance maturity, they look for evidence of:

ISO 42001 certification provides evidence of all of these elements, documented and verified by an independent third-party auditor. For organizations seeking to demonstrate AI governance maturity to regulators, customers, and investors, it is the most credible signal available.

Ready to Get Certified?

AICerty provides end-to-end ISO 42001, EU AI Act, and ISO 27001 certification services for AI companies worldwide. 100% online, 6-10 weeks, powered by BALTUM Bureau.

Visit aicerty.io
← Back to Blog