STANDARD · ISO/IEC 42001

ISO/IEC 42001: the AI management system, in practice

ISO/IEC 42001 is the international standard for an AI management system (AIMS). It requires an organisation to define scope and context, name roles, set policy and objectives, assess AI risks and impacts, apply controls, keep documented information, and run internal audit and management review. It does not prescribe a technology; it prescribes a manageable, auditable system.

What the standard asks for

The requirements follow the familiar management-system structure, applied to AI.

  • Scope and context of the AI management system.
  • Leadership commitment, policy and defined roles.
  • Objectives and planning, including risk and impact assessment of AI uses.
  • Operational controls proportional to each use.
  • Documented information kept current and retrievable.
  • Internal audit, management review and treatment of nonconformities.

Where it meets other standards

Organisations already running ISO/IEC 27001 can reuse roles, risk methodology, internal audit and management review. What is genuinely new is the AI-specific view: purpose of each use, people affected, degree of automation and the impact assessment.

Certification is optional

The management system can be implemented without pursuing certification. Certification itself is granted by an independent accredited body, never by a software vendor.

Frequently asked questions

Does ISO/IEC 42001 make us compliant with AI regulation?

No. It gives a management structure that makes compliance work feasible, but legal obligations have to be mapped as requirements in their own right.

Does the standard require software?

It requires documented information that is maintained and retrievable. With many AI uses in scope, spreadsheets tend to stop holding that up.