ISO/IEC 42001 vs ETSI EN 304 223: Choosing the Right AI Governance Standard

Two landmark standards now govern AI systems in the European and international market, and procurement teams need to understand the difference. ISO/IEC 42001 (published December 2023, amended 2025) is a management-system standard: it tells you how to run an AI management system with PDCA cycles, leadership commitment, risk assessment, and continual improvement. It is certifiable by accredited bodies and maps naturally to existing ISO 27001 and ISO 9001 programmes.

ETSI EN 304 223 (published January 2026) is a technical cybersecurity standard for AI: its 13 principles span secure design, development, deployment, maintenance, and end-of-life, with specific verifiable checks for threat modelling, SBOM, provenance, vulnerability scanning, and incident response. The Council of AI maps both: ISO 42001 provides the governance wrapper (the management-system PDCA cycle that proves you are paying attention), while ETSI EN 304 223 provides the technical teeth (the 13 verifiable checks that prove your system is actually secure). A procurement team should ask for both: ISO 42001 certification for the organisation, and an ETSI EN 304 223 verified measurement credential (DEFONEOS-SEAL) for the specific AI system being procured.

The combination answers two questions: Do you manage AI responsibly? AND Is this particular system secure? -- questions that a single standard cannot answer alone.

Standards and sources referenced

  • ISO/IEC 42001:2023/Amd 1:2025 -- AI management system standard
  • ETSI EN 304 223 V1.1.1 (2026-01) -- Cybersecurity for AI
  • Council of AI GSPC governance scoring methodology
  • CSOAI Verified Measurement Credential standard (DEFONEOS-SEAL)