One of the most common questions we receive at AICerty is some variation of: "We use ChatGPT / the OpenAI API / Copilot in our business. Do we need ISO 42001 certification?" It is a great question that does not have a simple yes/no answer — but by the end of this article, you will have a clear framework for deciding whether your use of AI tools triggers ISO 42001 or EU AI Act obligations.
The Short Answer
Using AI tools like ChatGPT internally for productivity purposes (drafting emails, summarizing documents, brainstorming) does not automatically require ISO 42001 certification. However, if you are integrating AI tools into customer-facing products, using AI to make decisions that affect individuals, or operating in a regulated sector where AI governance is expected, certification becomes highly relevant and may effectively be required.
The key question is not which AI tool you use — it is what you do with it and what risk that creates for others.
Understanding the ISO 42001 Scope Question
ISO 42001 applies to organizations that "develop, provide, or use AI-based products or services." This is deliberately broad. Under a strict reading, virtually any organization that uses AI tools in its operations falls within the potential scope of the standard.
However, the standard is also designed to be proportionate. The scope of your AIMS should reflect the materiality of your AI activities — the significance of the AI systems you use, the risks they pose, and the expectations of your stakeholders. An organization using ChatGPT to draft internal HR memos faces fundamentally different AI risks than one using an AI model to make credit decisions or diagnose medical conditions.
ISO 42001 is not designed to require that every company using a productivity AI tool builds a full-blown AI Management System. It is designed to ensure that organizations whose AI activities create meaningful risks for others govern those activities responsibly.
When Does Using AI Tools Trigger ISO 42001 Relevance?
Customer-Facing AI Applications
If you are using OpenAI's API, Anthropic's Claude, Google's Gemini, or similar models to power features in your own product — a chatbot, a recommendation engine, an automated decision-making feature — then you are effectively a provider of an AI system. Your customers are exposed to AI-driven outputs, and the governance of that AI is your responsibility, not OpenAI's or Anthropic's.
In this scenario, ISO 42001 is directly relevant. You need to understand and govern the AI system you have built — even if the underlying model is a third-party API. Questions you must answer include: What data is the model processing? What decisions does it influence? What happens if it produces incorrect, biased, or harmful outputs? What oversight mechanisms are in place?
AI-Assisted Decision Making About Individuals
Using AI tools to make or significantly influence decisions about individuals — hiring decisions, loan approvals, insurance pricing, content moderation outcomes, medical recommendations — creates AI governance obligations regardless of whether the underlying model is built in-house or accessed via API.
Under the EU AI Act, several of these use cases fall into the high-risk AI system category. Under GDPR, using AI for automated individual decision-making triggers specific obligations including the right to explanation and the right to human review. ISO 42001 provides the governance framework for managing these obligations systematically.
Regulated Sectors
In financial services, healthcare, insurance, legal, and other heavily regulated sectors, AI governance is increasingly expected by regulators even where not yet formally required. In the UK, the FCA's approach to AI in financial services; in the EU, the EBA and EIOPA guidelines on AI in banking and insurance; in healthcare, the FDA's AI/ML software framework — all signal that AI governance is becoming table stakes for regulated entities.
For organizations in these sectors, ISO 42001 certification provides a credible, internationally recognized demonstration of AI governance maturity.
Enterprise and Government Sales
Increasingly, enterprise and government procurement processes include AI governance requirements. RFPs (requests for proposals) for software contracts now routinely ask: Do you have an AI governance framework? What AI certifications do you hold? How do you manage AI risk in your products? ISO 42001 certification provides a clear, auditable answer to these questions and can be the difference between winning and losing significant contracts.
What About OpenAI's Own Compliance?
OpenAI and other major AI providers have pursued their own compliance programs, including ISO 27001 certification and various security audits. However, their compliance covers their own operations as a provider — not your use of their APIs or your responsibility as a deployer of AI systems built on their infrastructure.
The EU AI Act makes this particularly clear. Under the Act, when you build a product using a third-party AI model via API, you are typically classified as the "deployer" of a high-risk AI system if the use case falls within the high-risk categories — and as the deployer, you have your own obligations regardless of what the model provider does.
Internal Tools vs. Customer-Facing AI: A Practical Framework
Here is a practical way to think about whether your AI tool use triggers governance requirements:
- Internal productivity tools (low risk): Using ChatGPT to help employees write better emails, summarize documents, or generate first drafts of internal content. Minimal governance requirements — general AI use policies, data handling guidelines, and basic training are typically sufficient.
- Internal tools affecting HR or management decisions (medium risk): Using AI to help screen job applications, evaluate employee performance, or assist with promotion decisions. ISO 42001-aligned governance is recommended; EU AI Act high-risk obligations may apply.
- Customer-facing AI features (medium-high risk): AI-powered product features that users interact with directly. ISO 42001 certification is strongly recommended; governance documentation required for enterprise sales and regulated markets.
- AI making decisions about individuals (high risk): AI systems that make or significantly influence credit, insurance, employment, healthcare, or similar decisions. ISO 42001 certification expected; EU AI Act high-risk obligations likely apply.
What Regulators Look For
When regulators assess AI governance maturity, they look for evidence of:
- An AI inventory — do you know what AI you use?
- Risk assessment — have you evaluated the risks of your AI systems?
- Governance structures — who is accountable for AI decisions?
- Human oversight — can humans review, override, and take accountability for AI outputs?
- Incident management — what happens when AI systems produce harmful outputs?
- Transparency — can you explain your AI systems to affected individuals and regulators?
ISO 42001 certification provides evidence of all of these elements, documented and verified by an independent third-party auditor. For organizations seeking to demonstrate AI governance maturity to regulators, customers, and investors, it is the most credible signal available.
Ready to Get Certified?
AICerty provides end-to-end ISO 42001, EU AI Act, and ISO 27001 certification services for AI companies worldwide. 100% online, 6-10 weeks, powered by BALTUM Bureau.
Visit aicerty.io