StandardGlobal

ISO/IEC 42001

ISO / IEC · Version 2023 · December 18, 2023

The first international standard for AI Management Systems, covering governance, risk, and accountability for AI.

Overview

ISO/IEC 42001:2023 is the first international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System within organizations. Published on December 18, 2023, it applies to organizations that develop or use AI systems and want to demonstrate responsible AI governance. The standard follows the High Level Structure used by ISO 27001 and ISO 9001, which means organizations already certified under those frameworks can integrate an AIMS with reduced duplication of effort.

The standard includes Annex A, which provides organizational controls for responsible AI development and use, and Annex B, which provides controls for specific AI-related risks including bias, explainability, robustness, and data governance. The core management system requirements in Clauses 4 through 10 cover organizational context, leadership, planning, support, operation, performance evaluation, and improvement. Organizations must document an AI policy, conduct AI impact assessments for systems that may affect individuals, and maintain records of AI system objectives, data governance decisions, and testing results. Certification against ISO 42001 is available through accredited certification bodies.

Who Needs This

Organizations developing AI products or services for commercial or government markets

Enterprises deploying AI systems in high-stakes decisions affecting individuals, such as credit scoring, hiring, or healthcare

Technology companies whose customers require evidence of responsible AI governance as part of procurement

Financial institutions and regulated sectors where regulators are developing AI governance requirements

Organizations subject to the EU AI Act who want a recognized framework for compliance evidence

Structure at a Glance

Context of the organization, leadership, planning, support, operation, performance evaluation, and continual improvement. Mirrors the structure of ISO 27001.

AI policy, internal organization for AI, resources for AI systems, assessing impacts of AI systems, AI system lifecycle, and responsible AI objectives.

Controls addressing data quality, bias mitigation, transparency, explainability, robustness, safety, privacy of AI systems, and human oversight mechanisms.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

AI System Impact Assessment

Use this to conduct the impact assessment required by Annex A.6.1.4.

You are an ISO 42001:2023 AI governance specialist. I need to conduct an AI impact assessment for the following system: [DESCRIBE THE AI SYSTEM, ITS PURPOSE, TRAINING DATA, AND DECISION OUTPUTS]. Affected individuals: [DESCRIBE WHO IS AFFECTED BY DECISIONS OR OUTPUTS]. Provide: (1) an analysis of the potential impact on individuals across the categories of accuracy, fairness, transparency, and privacy, (2) identification of high-risk scenarios where the AI system could cause harm, (3) recommended controls from ISO 42001 Annex B to address each identified risk, and (4) documentation language suitable for including this assessment in an ISO 42001 AIMS records system.

AI Policy Drafting

Use this to draft the AI policy required by Clause 5.2.

Draft an AI policy for ISO 42001:2023 Clause 5.2. My organization: [DESCRIBE TYPE AND SIZE]. AI systems we develop or use: [LIST SYSTEMS AND THEIR FUNCTIONS]. The policy must: state the organization's commitment to responsible AI development and use, provide a framework for setting AI objectives, commit to satisfying applicable requirements including legal and regulatory obligations, commit to continual improvement of the AIMS, and be appropriate to the context of the organization. Write in formal policy language, suitable for sign-off by senior management.

Bias and Fairness Control Documentation

Use this to document controls for AI bias under Annex B.

I need to document AI bias and fairness controls under ISO 42001:2023 Annex B for the following AI system: [DESCRIBE SYSTEM AND ITS DECISION CONTEXT]. Protected characteristics relevant to this system: [LIST CHARACTERISTICS SUCH AS AGE, GENDER, ETHNICITY]. Current bias testing methodology: [DESCRIBE]. Provide: (1) a documentation of the bias risk profile for this system, (2) which Annex B controls apply and what implementation evidence is required, (3) a bias testing procedure appropriate for this system type, and (4) a template for recording bias assessment results that satisfies ISO 42001 record-keeping requirements.

EU AI Act Alignment Assessment

Use this to assess how ISO 42001 implementation supports EU AI Act obligations.

I need to assess how our ISO 42001:2023 AIMS implementation aligns with EU AI Act obligations. Our AI systems include: [LIST SYSTEMS WITH THEIR INTENDED USE AND SECTOR]. EU AI Act risk classification for each system: [HIGH RISK / LIMITED RISK / MINIMAL RISK]. For each high-risk system, map: (1) the EU AI Act Article requirements to the corresponding ISO 42001 Annex A and B controls, (2) gaps where EU AI Act requirements go beyond what ISO 42001 covers, (3) additional documentation required by the AI Act that is not covered by AIMS records, and (4) conformity assessment requirements under the AI Act for this system category.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Treating ISO 42001 as an IT security framework. It is an AI governance framework. The controls address data quality, bias, explainability, and human oversight of AI decisions, which require involvement from legal, ethics, product, and data science teams, not just the security function.

2

Assuming ISO 27001 certification satisfies ISO 42001. The two frameworks are complementary and share a management system structure, but ISO 42001 addresses AI-specific risks that are outside ISO 27001's scope. An integrated audit is possible but the AI-specific Annex B controls must be assessed independently.

3

AI impact assessments done once at system deployment. The standard requires ongoing assessment, particularly when the AI system changes, the training data changes, or new uses of the system are identified.

4

Ignoring the EU AI Act relationship. For organizations in or serving the EU, ISO 42001 certification does not constitute EU AI Act compliance. The Act has specific conformity assessment procedures for high-risk AI systems. ISO 42001 is a supporting framework, not a substitute.

5

Scope defined around the AI system rather than the AIMS. Organizations that scope their certification too narrowly around a single AI system may miss organizational controls that must apply across all AI development and deployment activities.

Cross-Framework Mapping

ISO 27001

ISO 42001 shares the High Level Structure with ISO 27001. Organizations can implement an integrated management system covering both ISMS and AIMS with considerable documentation overlap in clauses 4 through 10.

View Detailed Mapping ↗

GDPR

ISO 42001 Annex B controls for privacy of AI systems complement GDPR Article 22 requirements for automated decision-making. Organizations subject to both should align their AI impact assessments with GDPR DPIAs.

NIST CSF 2.0

NIST separately published an AI Risk Management Framework (AI RMF 1.0) in 2023. ISO 42001 and NIST AI RMF are complementary. NIST provides mappings between the two.

All content sourced from official issuing body documentation.

Official source ↗

Standard

ISO/IEC 42001