30 Days Gen AI Risk Trial -Start Now
Skip to main content

ISO 42001 requirements: a practical guide to Clauses 4-10 and Annex A

ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS). It requires organisations to define the context and scope of their AI activities, establish accountable governance, assess AI risks and impacts, operate documented controls, and continually measure and improve the system.

International
Standard
Current
Standard published: 2023-12-18

ISO-IEC-42001-2023Source checked: Resources ↗

What are the ISO 42001 requirements?

ISO 42001 does not prescribe a single product checklist. It requires a repeatable management system that identifies AI risks, assigns ownership, retains evidence, applies proportional controls, and improves over time.

  1. Define the AIMS scope and the internal and external context.
  2. Obtain leadership commitment and assign AI governance accountabilities.
  3. Set AI objectives and plan actions for risks, opportunities, and AI impacts.
  4. Maintain competence, awareness, documented information, and communication processes.
  5. Operate lifecycle, risk, supplier, and change-management controls.
  6. Measure outcomes, audit the system, address nonconformities, and continually improve it.

Overview

ISO/IEC 42001:2023 is the world's first international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organisations. Published on 18 December 2023 by the International Organization for Standardization and the International Electrotechnical Commission, it provides a structured framework for managing AI-related risks and opportunities.

The standard follows the Harmonised Structure (HS) common to all ISO management system standards (like ISO 27001, ISO 9001), making it familiar to organisations already certified to other ISO standards and enabling straightforward integration into existing management systems.

ISO 42001 is designed to be applicable to any organisation that provides or uses AI-based products or services, regardless of size, type, or industry sector. It addresses the unique challenges of AI systems, including ethical considerations, transparency, accountability, and the dynamic nature of AI technology.

The standard requires organisations to consider the AI-specific context of their operations, including the societal impact of AI systems, regulatory requirements, and stakeholder expectations. It mandates a systematic approach to AI risk management that goes beyond traditional IT risk frameworks to encompass fairness, transparency, explainability, and human oversight.

The standard's requirements are organised across Clauses 4 to 10 of the main document: context of the organisation (Clause 4), leadership and the AI policy (Clause 5), planning including AI risk assessment, AI risk treatment and AI system impact assessment (Clause 6), support covering resources, competence, awareness, communication and documented information (Clause 7), operation and life cycle control of AI systems (Clause 8), performance evaluation with monitoring, internal audit and management review (Clause 9), and improvement, including nonconformity and corrective action (Clause 10). Annex A then provides the reference control objectives and controls that an organisation selects and tailors based on its AI risk assessment, with Annex B offering implementation guidance and Annex C listing common AI-related objectives and risk sources.

ISO 42001 is particularly valuable as a compliance tool because it provides a certifiable framework that can demonstrate due diligence across multiple regulatory regimes. Organisations seeking to comply with the EU AI Act, for instance, can use ISO 42001 certification as evidence of a robust AI governance framework, although certification alone does not guarantee regulatory compliance.

The standard also addresses the AI system lifecycle, from conception and design through development, testing, deployment, operation, and retirement. This lifecycle approach ensures that AI governance is not an afterthought but is embedded into every stage of AI system development and use.

Annexes to the standard provide detailed guidance on AI-specific controls, including controls for data management, AI system impact assessment, AI system development processes, third-party and customer relationships, and system operation monitoring. These controls can be selected and tailored based on the organisation's specific AI risk assessment.

Key Requirements

  1. Define the AIMS scope and boundaries (Clause 4.3)

  2. Establish an AI policy approved by top management (Clause 5.2)

  3. Assign roles, responsibilities and authorities for AI governance (Clause 5.3)

  4. Perform AI risk assessment covering safety, fairness, transparency and accountability (Clauses 6.1.2 and 8.2)

  5. Treat AI risks with controls selected from Annex A (Clauses 6.1.3 and 8.3)

  6. Conduct AI system impact assessments on individuals, groups and society (Clauses 6.1.4 and 8.4)

  7. Ensure competence and awareness of personnel involved in AI systems (Clauses 7.2 and 7.3)

  8. Maintain documented information for the AIMS (Clause 7.5)

  9. Plan and control the AI system life cycle end to end (Clause 8.1)

  10. Monitor, measure, analyse and evaluate AIMS performance (Clause 9.1)

  11. Run internal audits of the AIMS (Clause 9.2)

  12. Hold management reviews of the AIMS (Clause 9.3)

  13. Address nonconformities and drive continual improvement (Clause 10)

  14. Manage third-party AI providers and AI supply chain risks (Annex A.10)

Key Dates & Timeline

  1. ISO/IEC 42001:2023 published; voluntary standard, not statutory commencement

Who It Affects

  • Any organisation developing AI systems or products
  • Organisations deploying or using AI-based services
  • AI service providers and cloud AI platform operators
  • Organisations seeking to demonstrate responsible AI governance
  • Companies needing to show compliance with AI regulations (e.g., EU AI Act)
  • Public sector organisations using AI in service delivery

Frequently Asked Questions

What are the requirements of ISO 42001?

ISO/IEC 42001:2023 sets the requirements for an AI management system across Clauses 4 to 10: understanding the organisation's AI context (4), leadership and an AI policy (5), planning including AI risk and impact assessments (6), support such as competence and documented information (7), operation of the AI system life cycle (8), performance evaluation and audits (9), and continual improvement (10). Annex A then lists the reference controls that an organisation selects and tailors based on its AI risk assessment.

How does an organisation get ISO 42001 certified?

Implement the AIMS requirements and the risk treatment controls appropriate to the documented scope, then engage an independent certification body with suitable accreditation. The audit programme assesses the documented system and its operation. Confirm the certification scope, audit arrangements, surveillance and renewal conditions with that body; ISO itself does not certify your organisation.

Is ISO 42001 certification mandatory?

No, ISO 42001 certification is voluntary. However, it provides a structured framework for AI governance that can help demonstrate compliance with emerging AI regulations like the EU AI Act. Some procurement processes and industry sectors may increasingly require or prefer ISO 42001 certification.

How does ISO 42001 relate to the EU AI Act?

ISO 42001 can structure AI governance, while the EU AI Act sets separate legal obligations. A management-system certificate does not automatically demonstrate compliance with every AI Act duty or give an automatic presumption of conformity. Assess applicable requirements and any relevant harmonised standard cited in the Official Journal separately.

Can ISO 42001 be integrated with other management systems?

Yes. ISO 42001 follows the ISO Harmonised Structure, making it directly integrable with ISO 27001 (information security), ISO 9001 (quality), ISO 14001 (environmental), and other management system standards.

Regulation Updates

Stay Ahead of AI Regulations

Receive AI regulatory updates to help prepare your next review.