10.2 ISO/IEC 42001 and International AI Standards

Key Takeaways

  • ISO/IEC 42001:2023 is the world's first certifiable standard for an Artificial Intelligence Management System (AIMS), utilizing the ISO Harmonized Structure (Clauses 4-10) with the Plan-Do-Check-Act (PDCA) governance cycle.
  • Annex A provides 38 reference controls grouped in nine areas (A.2 through A.10). Risk treatment is compared with Annex A in a Statement of Applicability, and the standard includes AI-system impact-assessment requirements.
  • Complementary standards provide essential technical depth: ISO/IEC 23894 adapts ISO 31000 for AI risk management, ISO/IEC 22989 standardizes terminology, and ISO/IEC 24029-1/-2 governs neural network robustness assessment via formal verification and statistical testing.
  • Accredited third-party conformity assessment requires a rigorous two-stage audit process: Stage 1 evaluates documented management system design and readiness, while Stage 2 verifies operational implementation and control effectiveness.
  • ISO/IEC 42001 is a voluntary certifiable management-system standard unless made obligatory by law or contract; certification provides evidence about the management system, not a guarantee that every AI system is safe or legally compliant.
Last updated: September 2026

10.2 ISO/IEC 42001: Artificial Intelligence Management Systems

ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). It applies to organizations that develop, provide, or use AI systems. It is a management-system standard: it governs policies, objectives, processes, responsibilities, performance evaluation, and improvement across an organization rather than certifying that a particular model is error-free.

Implementation and certification are voluntary unless law or contract makes them a requirement. ISO publishes the standard but does not certify organizations. Independent certification bodies perform certification, and accreditation bodies may attest to a certification body's competence. Certification supports assurance about the scoped management system; it does not guarantee safety, accuracy, legal compliance, or ethical outcomes for every AI system.

Harmonized structure and PDCA

Like other ISO management-system standards, ISO/IEC 42001 uses clauses 4 through 10:

  • Context (Clause 4): understand internal and external issues, interested parties, and AIMS scope.
  • Leadership (Clause 5): establish policy, commitment, roles, responsibilities, and authorities.
  • Planning (Clause 6): address risks and opportunities and establish measurable objectives.
  • Support (Clause 7): provide resources, competence, awareness, communication, and controlled documented information.
  • Operation (Clause 8): plan and control processes, assess AI risks and impacts, and implement treatment.
  • Performance evaluation (Clause 9): monitor, measure, analyze, audit, and conduct management review.
  • Improvement (Clause 10): correct nonconformities and continually improve the AIMS.

These clauses align with Plan-Do-Check-Act. Planning establishes context, risks, treatments, and objectives; operation implements them; performance evaluation checks results; improvement acts on findings. Leadership and support span the cycle.

Annex A and the Statement of Applicability

Annex A provides 38 reference controls grouped in nine areas, A.2 through A.10: AI policies; internal organization; resources; impact assessment; AI-system lifecycle; data; information for interested parties; use of AI systems; and third-party and customer relationships.

The organization begins from its risks, objectives, obligations, and context—not from blindly implementing every reference control. It compares determined controls with Annex A and prepares a Statement of Applicability (SoA) that records necessary controls, reasons for inclusion, implementation status, and reasons for excluding Annex A controls. Necessary controls can also come from other sources. An exclusion is defensible only when the organization's risk treatment and evidence support it; claiming that a control is inconvenient is not enough.

AI-system impact assessment examines potential consequences for individuals, groups, and society in the relevant context. It complements security risk assessment rather than replacing it. Evidence may include system inventories, ownership, risk and impact assessments, data provenance, supplier reviews, evaluation results, human oversight, logs, incident procedures, internal audits, management reviews, corrective actions, and retirement records.

Related standards

Do not treat every ISO/IEC AI document as interchangeable:

  • ISO/IEC 23894:2023 provides guidance on AI risk management. It supports risk work but is not itself the certifiable AIMS requirements standard.
  • ISO/IEC 22989:2022 establishes AI concepts and terminology.
  • ISO/IEC 24029-1 provides general principles for robustness assessment of neural networks, while ISO/IEC 24029-2 addresses formal-methods methodology.
  • ISO/IEC 42005:2025 provides a dedicated framework for AI-system impact assessment.
  • ISO/IEC 42006:2025 adds requirements for bodies that audit and certify AIMS.

A company may use several together: 42001 for the management system, 23894 for risk guidance, 42005 for impact-assessment method, and technical standards for system evaluation. None substitutes for applicable law.

Auditing and certification

A certification audit evaluates a defined AIMS scope. Auditors review documented design and operational evidence, sample processes and AI systems, interview responsible people, and determine whether requirements are implemented and effective. Findings can include conformity, observations, and nonconformities requiring correction. Exact audit duration, surveillance schedule, and certification cycle follow the applicable certification and accreditation arrangements; they are not proof that all risks have disappeared.

Internal audit and management review are core feedback mechanisms. Internal audit tests whether the AIMS conforms to organizational and standard requirements and operates effectively. Management review considers performance, changes, resources, audit findings, objectives, risks, opportunities, and improvement. Corrective action addresses the cause of a nonconformity and checks effectiveness rather than merely editing a document.

Worked example

A lender scopes its AIMS to AI used for credit decisions and customer explanations. It identifies applicants, regulators, staff, suppliers, and affected communities as interested parties. The risk process addresses discriminatory performance, inaccurate decisions, data leakage, model extraction, availability, explainability, and contestability.

The organization selects controls for governed data, versioned models, supplier review, access, evaluation across relevant groups, human escalation, monitoring, and incident response. It records these in the SoA without inventing exclusions based solely on whether a model is built in-house. An impact assessment documents intended and unintended effects. Independent testers evaluate the configured system, while internal audit checks approvals, evidence, and operation. Management reviews results and residual risk before release. If certification is pursued, the certification body assesses the scoped AIMS—not whether the model can never fail.

Exam distinctions

Choose ISO/IEC 42001 when a scenario asks for a certifiable organization-wide AI management system. Choose ISO/IEC 23894 when it asks for AI risk-management guidance, and ISO/IEC 22989 for terminology. The SoA explains risk-based selection and status of controls; it is not a declaration that every Annex A control must be implemented. Finally, distinguish certifiable from legally mandatory and from guaranteed safe.

Loading diagram...
ISO/IEC 42001 AIMS Architecture, PDCA Cycle, and Certification Workflow
Test Your Knowledge

During an ISO/IEC 42001 audit, an organization explains why a particular Annex A reference control is not necessary for its risk treatment. Which document records applicable controls and the justification for exclusions?

A
B
C
D
Test Your Knowledge

A safety-critical avionics contractor is designing a deep convolutional neural network for automated obstacle avoidance. To satisfy strict international safety standards, the engineering team must mathematically prove that the model's classification output will not change under any adversarial input perturbation within a bounded sphere of radius epsilon. Which international standard provides the formal methods methodology (such as SMT solvers and interval arithmetic) specifically designed for this mathematical verification?

A
B
C
D
Test Your Knowledge

An AI security director compares ISO/IEC 42001 with ISO/IEC 23894. What is the fundamental structural distinction between them?

A
B
C
D