South Korea AI Basic Act: ISO 42001 Compliance and Certification Guide
South Korea's AI Basic Act has applied since January 2026. This guide shows why ISO 42001, a standard that works under any national law, is a practical way to build the governance system Korean duties map onto, and what certification cannot do.
South Korea's AI Basic Act has been in force since January 22, 2026, and ISO/IEC 42001 is the international AI management system standard that lets an organisation build one governance system and then bring Korea's requirements into it. The standard applies to any organisation that provides or uses AI, regardless of size, type or nature, and it is not tied to any country's law, so organisations in different jurisdictions certify to the same standard. Certification does not by itself confer legal compliance with the Act, but it gives you the roles, risk and impact assessment processes, records and review cycle that Korean duties can be mapped onto. PECB Lead Implementer and Lead Auditor certification trains the people who build and audit that system.
Key Takeaways
In force now
The Act and its Enforcement Decree took effect on January 22, 2026. MSIT leads enforcement, and operators of high-impact and generative AI must give users advance notice.
Grace period
MSIT is deferring fact-finding investigations and administrative fines for at least a year, except where serious social harm is involved.
Foreign operators
A foreign operator with no Korean office must appoint a domestic representative if it crosses a revenue or user threshold.
One standard, any country
ISO/IEC 42001 applies to any organisation regardless of size, type or nature, and is not tied to one national law.
Law goes into the system
Clauses 4.1, 4.2, 6.3 and 9.3 make legal requirements and regulator guidance inputs to the system, so rule changes follow one process.
Limits
Certification does not confer legal compliance with the Act. It gives you the governance system that Korean duties are mapped onto.
On This Page
- What the South Korea AI Basic Act Requires
- How PIPA and Other Korean Rules Layer On Top
- Why ISO 42001 Works Under Any National AI Law
- Mapping the AI Basic Act to ISO 42001
- Benefits of ISO 42001 for Korean Enterprises
- What ISO 42001 Certification Does and Does Not Do
- Lead Implementer or Lead Auditor for a Korea Compliance Role
- Conclusion
- Frequently Asked Questions
What the South Korea AI Basic Act Requires
The South Korea AI law is formally the Framework Act on the Development of Artificial Intelligence and Establishment of Trust, known as the AI Basic Act (인공지능기본법). It passed the National Assembly on December 27, 2024. The Cabinet enacted the Enforcement Decree on January 21, 2026 after a public comment process, and both took effect on January 22, 2026.
MSIT is the lead regulator. It describes its approach as minimum regulation, and it pairs the compliance duties with industrial promotion measures, which is why the Act reads as both a support law and a trust law.
The Act separates AI development operators, who design, develop or provide AI systems, from AI utilisation operators, who deploy AI in their own products or services. It also reaches foreign entities whose AI systems affect users or markets in Korea.
Scope depends on what the system does, not where the company sits. Hiring decisions and loan approvals appear in the list of high-impact uses, so a multinational running such a system in Korea should check whether it is caught.
High-impact AI means systems that pose significant risk to human life, physical safety or fundamental rights. The listed areas include energy supply, drinking water production, healthcare and medical devices, nuclear safety, biometric data in criminal investigations, decisions that affect rights and obligations such as hiring and loans, transport, public-sector decisions on services or taxes, and student evaluation.
Generative AI means systems that produce text, images, sound or video from input data. Operators of both categories must notify users in advance that AI is in use. Guidance from the US International Trade Administration adds that AI-generated output that is hard to tell from reality may need a disclosure, and that content exported from a service is expected to carry clearer labelling than content that stays inside it. Korean-language notices are part of the operational picture.
Large-scale advanced AI systems can face additional duties on risk identification, assessment, mitigation and management. The criteria include training compute above 10²⁶ floating-point operations, use of state-of-the-art technology and potential broad impact on fundamental rights.
For comparison, the EU AI Act presumes systemic risk in general-purpose models at 10²⁵ operations, so Korea's figure sits an order of magnitude higher. In practice this category captures frontier model developers. Most enterprises will sit in the high-impact or generative categories instead.
A foreign AI operator with no registered address or business office in Korea must appoint a domestic representative if it meets any one of three thresholds: prior-year total revenue of KRW 1 trillion or more (about US$662 million), prior-year AI service revenue of KRW 10 billion or more (about US$6.6 million), or an average of one million or more daily Korean users over the three months before the end of the prior year.
The duty also applies to a foreign operator that has been fined for failing to follow a corrective order. The representative needs a Korean address or place of business and can act for the operator on safety measure submissions, high-impact AI status confirmations and related compliance support.
MSIT can investigate, issue corrective orders, impose administrative fines and order suspension where a service threatens safety. Fines of up to KRW 30 million (about US$20,000) can apply to failing to notify users of AI use, failing to appoint a domestic representative, and breaching corrective orders or refusing inspections.
MSIT has said it will run a grace period of at least one year in 2026. Fact-finding investigations and fines are generally deferred, with exceptions for serious social harm such as loss of life or human-rights violations. It has published guidelines on high-impact AI determination, operator obligations, impact assessments, generative AI transparency and advanced AI safety, and it runs an AI Basic Act Help Desk through the Korea Software Industry Association. Check current status with MSIT before relying on any date.
How PIPA and Other Korean Rules Layer On Top
The Personal Information Protection Commission (PIPC) issued its guidelines on processing personal information for generative AI development and use on August 6, 2025. They apply the Personal Information Protection Act (PIPA) across four lifecycle phases: objective setting, strategy formulation, training and development, and deployment and management.
Where publicly available personal information is used to train generative AI, the guidelines say the legitimate interests basis under Article 15(1)(vi) of PIPA may be relied on. They also stress an AI privacy governance framework that runs across the lifecycle. Separately, PIPA amendments let the PIPC request information when an AI company's algorithm leaks personal information.
The Korea Communications Commission (KCC) adopted Guidelines on the Protection of Users of Generative AI Services on February 28, 2025.
Amendments to the Act on Promotion of Information and Communications Network Utilization and Information Protection were promulgated in January 2026, with effect six months later. They require notification to the KCC when providing AI-based recommendation services and widen the definition of information and communication service provider to include those who provide or mediate information using AI.
As of White & Case's April 2026 tracker, amendments were proposed to the Fair Hiring Procedure Act (notice to candidates when AI is used in hiring), the Content Industry Promotion Act (disclosure that content was generated with AI) and the Copyright Act (limits on using copyrighted works for automated analysis).
These were proposals, not law, at that date. Treat them as a watch list and confirm their status before building a control around them.
Why ISO 42001 Works Under Any National AI Law
ISO/IEC 42001 was first published in December 2023 and sets out requirements for establishing, implementing, maintaining and continually improving an AI management system. Its scope statement says it applies to any organisation, regardless of size, type or nature, that provides or uses products or services that use AI systems, and that it is meant to help the organisation meet applicable requirements, obligations to interested parties and their expectations.
Because it is a management system standard, it does not write any one country's rules into itself. Instead it tells the organisation to work out its own context. Note 2 to clause 4.1 says the external issues can include applicable legal requirements and the policies and guidance of regulators, and that these vary with the organisation's role and jurisdiction. Clause 4.2 then asks the organisation to identify its interested parties, such as regulators and customers, to determine their requirements and to decide which of them the system will address. That is how Korean law goes in: as an input to the system, not as a replacement for it. A Korean firm, a Dubai firm and a German firm can run the same standard, and only the legal inputs differ.
The same design handles change. Clause 6.3 requires changes to the system to be carried out in a planned manner. Clause 9.3.2 requires management review to consider changes in external issues and in the needs of interested parties, and clause 9.2 requires an internal audit programme. Guidance from MSIT is still developing and several sector amendments are only proposals, so a repeatable route for logging a change, assessing it, deciding what to do and reviewing the result is worth more than a one-off gap analysis.
This is why a growing number of organisations choose ISO/IEC 42001 certification. An independent audit gives customers, partners and regulators an assessed view of how AI is governed, and one system can serve every jurisdiction the organisation operates in instead of a separate programme for each law.
Practitioner Note:
Start the Korean overlay with a simple register: each Korean requirement that touches your AI systems, an owner, the ISO 42001 clause or control that carries it and the evidence you hold. ISO 42001 does not require this exact document. It is a practical way to show an auditor how the law entered the system, and it is easy to review at each management review.
Mapping the AI Basic Act to ISO 42001
ISO/IEC 42001 is a management system standard for AI, so it organises an organisation's governance work rather than classifying individual AI systems under Korean law. Even so, several of the Act's expectations have a direct home in the standard. The table below is an orientation aid, and each row still needs Korean legal review before it is treated as evidence of compliance.
| Korean expectation | ISO 42001 element | What an auditor looks for |
|---|---|---|
| Advance notice to users of high-impact and generative AI | Clause 7.4 communication; Annex A.8 information for interested parties | A documented notice process and evidence that notices reach users, in Korean where users are in Korea. |
| Risk management for high-impact AI | Clauses 6.1.2 AI risk assessment and 6.1.3 AI risk treatment | A risk register per AI system, recorded treatment decisions and evidence of periodic review. |
| Safety and fundamental-rights safeguards | Clause 6.1.4 AI system impact assessment; Annex A.5.2 to A.5.5 | A defined impact assessment process, a documented result per system, and results fed back into the risk assessment. |
| Human oversight and responsible use | Annex A.9.2 processes for responsible use and A.9.3 objectives for responsible use, with Annex B guidance on human oversight | Named oversight roles, rules for when a person reviews or overrides an output, and records that this happened. |
| Documentation and recordkeeping | Clause 7.5 documented information; Annex A.6.2.6 operation and monitoring; A.6.2.8 event logs | Log retention rules, current system documentation and monitoring records. |
| Accountability and regulator contact | Annex A.3.2 AI roles and responsibilities; A.3.3 reporting of concerns; clause 5.3 | A named owner for each AI system and for regulator contact, including the domestic representative route for foreign operators. |
| Suppliers and foreign providers | Annex A.10.2 allocating responsibilities; A.10.3 suppliers; A.10.4 customers | Supplier requirements, clear allocation of duties between provider and user, and evidence that supplier claims are checked. |
Practitioner Note:
The impact assessment is where most programmes stall. An auditor will not accept a template filled in once. They look for a repeatable process, a result for each system in scope and proof that the result changed a risk decision. If the Korean classification of a system (high-impact or not) is undecided, record that decision and who made it.
Benefits of ISO 42001 for Korean Enterprises
For a Korean enterprise, the case for ISO/IEC 42001 is less about a certificate on the wall and more about what the management system does day to day. The benefits below depend on the system being run properly, and each one is a way of making Korean legal duties easier to organise, evidence and keep current.
Many Korean enterprises sell to, or use AI services from, other countries. Because ISO/IEC 42001 is not tied to one jurisdiction, the organisation can keep one policy set, one risk method and one audit cycle, and add each national law as an input under clauses 4.1 and 4.2. The alternative is a separate compliance programme for each law.
The standard is not a shortcut for other regimes. ISO/IEC 42001 is not a harmonised standard under the EU AI Act, and each law still needs its own analysis.
The AI Basic Act asks for user notice, risk management, safeguards, oversight and records. In an ISO 42001 system each of those already has a place: communication under clause 7.4 and Annex A.8, risk and impact assessment under clauses 6.1.2 to 6.1.4 and Annex A.5, responsible use under Annex A.9, and documented information under clause 7.5.
That makes compliance easier to achieve because the work is assigned and repeatable, not because the law has been ticked off. The Korean-specific parts, such as the content and form of a notice, still come from the Act and the Enforcement Decree.
MSIT has published guidelines on high-impact AI determination, operator obligations, impact assessments, generative AI transparency and advanced AI safety, and further amendments have been proposed. When a rule moves, the system already has a route: clause 6.3 planned changes, clause 9.3 management review inputs on external change, and clause 10.2 corrective action.
This is what turns a new decree into a controlled update instead of an emergency project.
Internal audit under clause 9.2 and management review under clause 9.3 produce records that show the system is checked and that leadership is involved. Those records help when a business unit, a customer or, where relevant, MSIT asks how AI is governed.
An accredited certification body adds an independent assessment of the management system. It does not assess whether an individual AI system meets Korean law.
Korean enterprises often deploy models and services built abroad. Annex A.10 covers allocating responsibilities, suppliers and customers, so the enterprise can set requirements for providers and record who does what.
This matters under the Act because duties differ between AI development operators and AI utilisation operators, and a foreign provider may need a domestic representative. The system helps you keep track of which role each party plays.
ISO/IEC 42001 follows the same clause structure as other management system standards, with context, leadership, planning, support, operation, performance evaluation and improvement. An enterprise that already runs a system such as ISO/IEC 27001 can reuse governance mechanics like internal audit, management review and document control, and add the AI-specific parts.
Reuse shortens the build but does not remove the need for AI-specific risk and impact assessment.
What ISO 42001 Certification Does and Does Not Do
The reason to build on ISO/IEC 42001 is that it gives you a governance system that is not tied to any one country's law. It is not a legal safe harbour. The AI Basic Act has its own definitions, its own regulator and its own duties, and those apply whether or not a company is certified.
A certificate from an accredited certification body shows that a management system met the standard's requirements when it was audited. It does not show that each AI system meets Korean law, for example that a notice satisfies the Enforcement Decree or that a system has been classified correctly. No source reviewed for this guide designates ISO/IEC 42001 as a route to statutory compliance under the Act.
What certification does give you is structure and evidence: a single governance process for AI risk, defined roles, documented impact assessments and a cycle of internal audit and management review. Korean law then goes into that structure, with Korean legal advice on classification, notices and representative duties.
Important:
ISO/IEC 42001 certification does not confer legal compliance with Korea's AI law. It is the governance system that Korean duties are mapped onto, and each duty still needs its own legal check.
Lead Implementer or Lead Auditor for a Korea Compliance Role
PECB ISO/IEC 42001 Lead Implementer suits compliance leads, AI governance managers and security staff who have to stand up an AI management system: scoping, policy, risk and impact assessment processes, controls and readiness for audit.
If you are the person Korean business units will ask for a notice process or an impact assessment template, this is the path that teaches you to build both.
PECB ISO/IEC 42001 Lead Auditor suits internal auditors, second-line assurance staff and consultants who assess an AI management system against the standard and report on it.
It is the better fit if your role is to check that the controls exist, work and produce evidence, and to challenge the people who built them.
Implementing and auditing are different skills, and holding both is common for consultants and for GRC leads who run a programme and then assure it. If you are building first, start with Lead Implementer. If your role is assurance, start with Lead Auditor. A bundle covers both, and bundle pricing is quoted on request.
The course runs five days. The exam is open-book with a 70% passing mark, and PECB administers it through the PECB Exams app with remote proctoring. reconn does not administer exams. Certification is a two-step process: pass the exam, then apply to PECB based on the professional experience criteria. Every package includes two exam attempts.
PECB's published ISO 42001 course languages are English, French, Spanish, German, Arabic and Brazilian Portuguese. Korean is not on that list, so Korea-based candidates should plan to study in English. Self-study starts from $799 and eLearning from $899, and both include a 1-on-1 session with Shenoy and WhatsApp access until exam clearance. Not a slide reader. A practitioner. There is no pass guarantee, and no practice questions are provided, in line with PECB policy.
Conclusion
The South Korea AI Basic Act is already binding, and the practical work it asks for is familiar to anyone who has run a management system: know which AI systems you have, classify them, assess their impact, tell users, keep humans in the loop and keep records. The grace period on fines is at least one year from January 2026, so the window for preparing without penalty exposure is narrowing.
ISO/IEC 42001 is a jurisdiction-neutral way to build the governance system that carries that work. Korean law goes in through the context and interested parties clauses, changes to it go through planned change and management review, and the same system can take in the next country's law without a rebuild. It does this without being a legal safe harbour, so Korean legal advice on classification, notices and representative duties still applies.
For the people who will do the work, the Lead Implementer and Lead Auditor credentials are the practical way to show you can build and test an AI management system. Choose by role, and take the other later if your work moves from building to assurance.
Further Reading
- ISO 42001 Overview: what the standard covers and how the management system fits together.
- ISO 42001 Implementation Guide: how to plan and run an implementation from scope to certification audit.
- ISO 42001 Lead Implementer: who the credential is for and what the course teaches.
- ISO 42001 Lead Auditor: who the credential is for and what the audit course teaches.
Frequently Asked Questions
Yes, it can. The Act applies to foreign entities whose AI systems affect users or markets in Korea. A foreign operator with no Korean address or business office must appoint a domestic representative if it meets a revenue or user threshold set in the Enforcement Decree. Smaller foreign operators may fall outside that specific duty but can still be subject to the advance notice obligation for high-impact or generative AI.
The Act and its Enforcement Decree took effect on January 22, 2026. MSIT has said it will run a grace period of at least one year in 2026 during which fact-finding investigations and administrative fines are generally deferred, except in cases of serious social harm such as loss of life or human-rights violations. Check MSIT's current position before relying on any date.
It is one of the criteria for large-scale advanced AI systems, which can face extra risk identification, assessment and mitigation duties. The other criteria are use of state-of-the-art technology and potential broad impact on fundamental rights. The EU AI Act presumes systemic risk in general-purpose models at 10²⁵ operations, so Korea's figure is an order of magnitude higher.
A foreign AI operator with no registered address or business office in Korea must appoint one if its prior-year total revenue was KRW 1 trillion or more, its prior-year AI service revenue was KRW 10 billion or more, or it averaged one million or more daily Korean users over the three months before the end of the prior year. The duty also applies to a foreign operator fined for failing to follow a corrective order.
ISO/IEC 42001 is an international management system standard that applies to any organisation, regardless of size, type or nature, that provides or uses AI. It does not encode one country's law. It asks the organisation to identify the legal requirements and regulator guidance in its context and the requirements of its interested parties, then build them into one governance system. That is why the same standard works alongside the South Korea AI law, the UAE's rules, the EU AI Act or any other regime.
It gives each Korean duty an owner, a process and a record. User notice sits under communication and Annex A.8, risk and impact assessment under clauses 6.1.2 to 6.1.4, responsible use and human oversight under Annex A.9, and documentation under clause 7.5. Changes to Korean rules go through planned change, management review and corrective action. The Korean-specific content still comes from the Act and its Enforcement Decree.
No source reviewed for this guide makes ISO/IEC 42001 certification a requirement of the Act. It is a voluntary international standard for AI management systems. Organisations choose it to build and evidence a governance system, but the Act's duties apply whether or not a company is certified.
No. Certification shows that a management system met the standard's requirements when audited. It does not show that each AI system is classified correctly or that notices, representative arrangements and safeguards meet Korean law. Take Korean legal advice on those points.
Choose by role. Lead Implementer suits people who must build the AI management system, including risk and impact assessment processes. Lead Auditor suits people who test and assure that system. Many people building a programme start with Lead Implementer, and a bundle covers both.
Yes. reconn delivers PECB-certified training remotely worldwide, and PECB administers exams through the PECB Exams app with remote proctoring. PECB's published ISO 42001 course languages are English, French, Spanish, German, Arabic and Brazilian Portuguese, so plan to study in English. Each package includes two exam attempts.

About the Author
Shenoy Sandeep
Shenoy Sandeep is the Founder of reconn, an AI-first cybersecurity firm based in Dubai, UAE. With 20+ years across cybersecurity focussing on offensive security and threat intelligence portfolio, and over 10 years in Enterprise AI, AI governance and data protection, he has assisted over 25+ startups in scaling their business in the Middle East and African region.
Training is Shenoy's passion project and reconn has associated themselves with PECB, the global leaders in personal certifications for AI, cybersecurity, data protection, privacy and business continuity professionals. He is a PECB-certified trainer and one of the world's early PECB-certified AI professionals, also specialising in ISO/IEC 27001, ISO/IEC 27701, ISO 42001, ISO 22301, and GDPR.
Via Reconn, Shenoy runs an advisory service assisting organisations in the EMEA with compliance and certification on ISO 42001, ISO 27001, ISO 27701, ISO 22301 and local data protection and privacy laws. His current interests include EU AI Act, NIS2, DORA, EU/UK GDPR, UAE PDPL and SDAIA PRPL.