ISO/IEC 42001: the AI management system standard

Updated

ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). It gives organizations a certifiable framework to govern how they develop and use AI responsibly — using the same Plan-Do-Check-Act structure as ISO 27001, plus AI-specific Annex A controls and an AI system impact assessment.

This guide explains what an AIMS is, the management-system clauses (context, leadership, planning, support, operation, performance evaluation, improvement), the nine Annex A control areas, how ISO 42001 relates to and integrates with ISO 27001, the accredited certification cycle, and a practical sequence for preparing.

What ISO/IEC 42001 is

ISO/IEC 42001:2023 is the first international management-system standard specifically for artificial intelligence, published jointly by ISO and IEC in December 2023. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) — the governance structure an organization uses to manage AI responsibly across its lifecycle.

Like ISO 27001 for information security or ISO 9001 for quality, ISO 42001 is certifiable: an accredited certification body can audit an organization against it and issue a certificate. That is what distinguishes it from a purely advisory framework — it defines a management system that can be independently verified, not just a set of good practices to consider.

The standard is technology-neutral and sector-agnostic. It applies to any organization that provides or uses AI, whatever the model type or industry, and it is designed to be adapted to the organization's size, context, and risk profile rather than prescribing a single fixed implementation.

What an AI management system (AIMS) is

An AIMS is the set of policies, roles, processes, and controls through which an organization governs its AI. ISO 42001 structures it around the Plan-Do-Check-Act cycle, using the same harmonized high-level structure (Annex SL) shared by ISO's other management-system standards. That shared skeleton is what makes ISO 42001 straightforward to integrate with a management system an organization already runs.

The requirements live in clauses 4 to 10, each describing part of the cycle:

  • Clause 4 — Context: understand the organization, interested parties, and the scope of the AIMS.
  • Clause 5 — Leadership: top-management commitment, an AI policy, and assigned roles and responsibilities.
  • Clause 6 — Planning: address AI risks and opportunities, set objectives, and produce a Statement of Applicability for the Annex A controls.
  • Clause 7 — Support: resources, competence, awareness, communication, and documented information.
  • Clause 8 — Operation: run the AI risk assessment and the AI system impact assessment, and control the AI lifecycle.
  • Clause 9 — Performance evaluation: monitoring, measurement, internal audit, and management review.
  • Clause 10 — Improvement: corrective action and continual improvement.

Annex A controls

The heart of the standard's AI-specific content is Annex A, a reference set of controls organized into nine control areas. During planning, an organization decides which of these controls apply and records the decision — with justification for inclusions and exclusions — in a Statement of Applicability, exactly as ISO 27001 requires for its own controls. Annex B provides implementation guidance for each control, and Annex C lists potential AI-related organizational objectives and risk sources to inform the risk assessment.

The nine Annex A control areas are:

  • Policies related to AI — an overarching AI policy and supporting policies.
  • Internal organization — roles, responsibilities, and reporting for AI.
  • Resources for AI systems — data, tooling, computing, and human resources, documented and managed.
  • Assessing impacts of AI systems — the AI system impact assessment on individuals, groups, and society.
  • AI system life cycle — responsible development, from objectives and design through verification, deployment, and operation.
  • Data for AI systems — provenance, quality, and governance of data used across the lifecycle.
  • Information for interested parties — documentation and transparency for users and affected parties.
  • Use of AI systems — responsible and intended use, including operation and monitoring.
  • Third-party and customer relationships — allocating responsibilities across suppliers, partners, and customers.

How ISO 42001 relates to ISO 27001

ISO 42001 and ISO 27001 are siblings: both are ISO management-system standards built on the same Annex SL structure, both require leadership commitment, risk assessment, a Statement of Applicability, internal audit, and management review, and both are certifiable on the same audit cycle. An organization certified to ISO 27001 already has most of the management-system machinery an AIMS needs and can extend it rather than build from scratch.

The difference is subject matter and scope. ISO 27001 governs an information security management system — protecting the confidentiality, integrity, and availability of information. ISO 42001 governs an AI management system, which reaches beyond security into responsible development, transparency, data governance for AI, and impacts on people and society. The two are complementary, and many organizations run them as one integrated management system covering shared elements once.

ISO/IEC 42001 vs ISO/IEC 27001 at a glance
DimensionISO/IEC 42001ISO/IEC 27001
FocusAI management system (AIMS)Information security management system (ISMS)
Primary concernResponsible development and use of AI; impacts on people and societyConfidentiality, integrity, and availability of information
Controls referenceAnnex A control areas for AIAnnex A information-security controls
Distinctive requirementAI system impact assessmentInformation-security risk treatment
StructureAnnex SL / clauses 4-10; certifiableAnnex SL / clauses 4-10; certifiable

The certification cycle

Certification to ISO 42001 follows the same accredited process as other ISO management-system standards, carried out by a certification body operating under ISO/IEC 17021. It is not a one-time exam; it is a multi-year cycle designed to confirm the system keeps operating, not just that it existed on audit day.

The typical cycle runs in stages. A Stage 1 audit reviews the AIMS documentation and readiness. A Stage 2 audit assesses the system in operation and, if successful, leads to certification. Surveillance audits then confirm the system continues to run — commonly on an annual basis — and a recertification audit is carried out before the certificate expires, generally on a three-year cycle. Between audits, the internal audit and management review required by clause 9 keep the system honest.

How to prepare

Preparing for ISO 42001 is largely about standing up the management system and generating the evidence that it operates. A practical sequence:

  • Define the scope of the AIMS and inventory the AI systems it will cover.
  • Secure leadership commitment and set an AI policy with clear roles and responsibilities.
  • Run the AI risk assessment and the AI system impact assessment, using Annex C as a prompt for risk sources.
  • Select applicable Annex A controls and document the choices in a Statement of Applicability.
  • Operationalize the controls across the AI lifecycle — data governance, documentation, transparency, monitoring — and keep records that show they run over time.
  • Perform an internal audit and management review, close any gaps, then engage an accredited certification body for the Stage 1 and Stage 2 audits.

Frequently asked questions

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). Published by ISO and IEC in December 2023, it specifies requirements for establishing, maintaining, and continually improving a governance system for developing and using AI responsibly, and it is certifiable by an accredited certification body.

Is ISO 42001 certifiable?

Yes. Like ISO 27001 and ISO 9001, ISO 42001 defines a management system that an accredited certification body can audit and certify. Certification follows a Stage 1 and Stage 2 audit, then ongoing surveillance audits and a recertification audit, typically on a three-year cycle.

How is ISO 42001 different from ISO 27001?

Both are certifiable ISO management-system standards on the same Annex SL structure, so they share machinery like risk assessment, a Statement of Applicability, internal audit, and management review. ISO 27001 governs information security; ISO 42001 governs AI more broadly — responsible development, transparency, AI data governance, and impacts on people. Many organizations integrate the two.

Does ISO 42001 make an organization compliant with the EU AI Act?

Not automatically. ISO 42001 is a voluntary international standard, while the EU AI Act is law with its own specific obligations. A well-run AIMS can support and evidence much of what the Act expects — risk management, documentation, human oversight — but certification is not a legal presumption of conformity with the Act. The two are best treated as complementary.

What is the AI system impact assessment in ISO 42001?

It is a distinctive requirement of ISO 42001: a structured assessment of an AI system's potential impacts on individuals, groups, and society, beyond the organization's own risk. It is one of the main features that separates an AI management system from an information-security management system, and it feeds directly into how controls are selected and applied.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.