What is it?
ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS). Published in December 2023, it follows the same harmonized structure as ISO/IEC 27001, so it integrates well with existing management systems. It focuses on how AI is managed, not on any particular technology.
Why does it matter?
As AI use grows, leaders need to show that risks are identified, responsibilities are clear and decisions are traceable. ISO/IEC 42001 provides a common language for boards, customers, regulators and partners. Organizations can choose to seek formal certification through accredited certification bodies.
Who needs it?
- Organizations using AI tools and services in their processes
- Companies providing AI-based products or services
- Organizations asked for evidence of AI governance by customers or regulators
- Banking, insurance, healthcare and other sectors handling sensitive data
Key concepts
Management system (AIMS)
Policies, roles, processes and controls that steer AI use — not a software tool.
AI risk assessment
Identifying and analysing risks AI systems pose to the organization and choosing how to treat them.
AI system impact assessment
Considering potential consequences for individuals, groups and society beyond organizational risk.
Reference controls
Control objectives and controls selected in proportion to risk, with the rationale documented.
Continual improvement
Plan–Do–Check–Act, so the system evolves with technology and risk.
Requirements
- Context, interested parties and AIMS scope
- Leadership commitment and an AI policy
- Planning for risks and opportunities, objectives and impact assessment
- Resources, competence, awareness and documented information
- Operational control of the AI lifecycle, including suppliers
- Monitoring, measurement, internal audit and management review
- Corrective action and continual improvement
Implementation
- 01Define scope and build an AI inventory
- 02Establish governance roles and responsibilities
- 03Write the AI policy and acceptable use rules
- 04Assess risk and impact for priority use cases
- 05Select and implement controls, documenting the rationale
- 06Train staff and build awareness
- 07Internal audit, management review and certification readiness
Assessment
A gap assessment shows how far the organization is from each requirement. The AI STANDARD readiness assessment is a quick starting point; a full organizational assessment maps gaps with evidence. Note: AI STANDARD does not issue ISO certification — only accredited certification bodies do.
Training
The “ISO/IEC 42001 Foundations” and “Implementing an AI Management System” courses cover concepts, requirements and a step-by-step implementation path.
Resources
This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.