ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS). It requires organisations to define the context and scope of their AI activities, establish accountable governance, assess AI risks and impacts, operate documented controls, and continually measure and improve the system.
ISO 42001 does not prescribe a single product checklist. It requires a repeatable management system that identifies AI risks, assigns ownership, retains evidence, applies proportional controls, and improves over time.
ISO/IEC 42001:2023 is the world's first international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organisations. Published on 18 December 2023 by the International Organization for Standardization and the International Electrotechnical Commission, it provides a structured framework for managing AI-related risks and opportunities.
The standard follows the Harmonised Structure (HS) common to all ISO management system standards (like ISO 27001, ISO 9001), making it familiar to organisations already certified to other ISO standards and enabling straightforward integration into existing management systems.
ISO 42001 is designed to be applicable to any organisation that provides or uses AI-based products or services, regardless of size, type, or industry sector. It addresses the unique challenges of AI systems, including ethical considerations, transparency, accountability, and the dynamic nature of AI technology.
The standard requires organisations to consider the AI-specific context of their operations, including the societal impact of AI systems, regulatory requirements, and stakeholder expectations. It mandates a systematic approach to AI risk management that goes beyond traditional IT risk frameworks to encompass fairness, transparency, explainability, and human oversight.
The standard's requirements are organised across Clauses 4 to 10 of the main document: context of the organisation (Clause 4), leadership and the AI policy (Clause 5), planning including AI risk assessment, AI risk treatment and AI system impact assessment (Clause 6), support covering resources, competence, awareness, communication and documented information (Clause 7), operation and life cycle control of AI systems (Clause 8), performance evaluation with monitoring, internal audit and management review (Clause 9), and improvement, including nonconformity and corrective action (Clause 10). Annex A then provides the reference control objectives and controls that an organisation selects and tailors based on its AI risk assessment, with Annex B offering implementation guidance and Annex C listing common AI-related objectives and risk sources.
ISO 42001 is particularly valuable as a compliance tool because it provides a certifiable framework that can demonstrate due diligence across multiple regulatory regimes. Organisations seeking to comply with the EU AI Act, for instance, can use ISO 42001 certification as evidence of a robust AI governance framework, although certification alone does not guarantee regulatory compliance.
The standard also addresses the AI system lifecycle, from conception and design through development, testing, deployment, operation, and retirement. This lifecycle approach ensures that AI governance is not an afterthought but is embedded into every stage of AI system development and use.
Annexes to the standard provide detailed guidance on AI-specific controls, including controls for data management, AI system impact assessment, AI system development processes, third-party and customer relationships, and system operation monitoring. These controls can be selected and tailored based on the organisation's specific AI risk assessment.
Define the AIMS scope and boundaries (Clause 4.3)
Establish an AI policy approved by top management (Clause 5.2)
Assign roles, responsibilities and authorities for AI governance (Clause 5.3)
Perform AI risk assessment covering safety, fairness, transparency and accountability (Clauses 6.1.2 and 8.2)
Treat AI risks with controls selected from Annex A (Clauses 6.1.3 and 8.3)
Conduct AI system impact assessments on individuals, groups and society (Clauses 6.1.4 and 8.4)
Ensure competence and awareness of personnel involved in AI systems (Clauses 7.2 and 7.3)
Maintain documented information for the AIMS (Clause 7.5)
Plan and control the AI system life cycle end to end (Clause 8.1)
Monitor, measure, analyse and evaluate AIMS performance (Clause 9.1)
Run internal audits of the AIMS (Clause 9.2)
Hold management reviews of the AIMS (Clause 9.3)
Address nonconformities and drive continual improvement (Clause 10)
Manage third-party AI providers and AI supply chain risks (Annex A.10)
ISO/IEC 42001:2023 sets the requirements for an AI management system across Clauses 4 to 10: understanding the organisation's AI context (4), leadership and an AI policy (5), planning including AI risk and impact assessments (6), support such as competence and documented information (7), operation of the AI system life cycle (8), performance evaluation and audits (9), and continual improvement (10). Annex A then lists the reference controls that an organisation selects and tailors based on its AI risk assessment.
An organisation implements the requirements of Clauses 4 to 10 and the Annex A controls it has selected, then engages an accredited certification body for a two-stage audit: a Stage 1 documentation review followed by a Stage 2 on-site assessment of the AIMS in practice. If both stages pass, the certification body issues an ISO/IEC 42001 certificate, typically valid for three years with annual surveillance audits and a recertification audit at the end of the cycle. Accreditation of certification bodies is coordinated through the International Accreditation Forum.
No, ISO 42001 certification is voluntary. However, it provides a structured framework for AI governance that can help demonstrate compliance with emerging AI regulations like the EU AI Act. Some procurement processes and industry sectors may increasingly require or prefer ISO 42001 certification.
ISO 42001 provides a management system framework that can support EU AI Act compliance. While the EU AI Act sets legal requirements, ISO 42001 offers a systematic approach to meeting many of those requirements. The European Commission may recognize certain standards as providing a presumption of conformity.
Yes. ISO 42001 follows the ISO Harmonised Structure, making it directly integrable with ISO 27001 (information security), ISO 9001 (quality), ISO 14001 (environmental), and other management system standards.
Get notified when new AI regulations are introduced or updated. Join 500+ compliance professionals.