3.1 The AIMS Landscape & Complementary Standards

Key Takeaways

  • ISO/IEC 42001:2023 is the certifiable requirements standard for an AIMS and uses the PDCA management-system model.

  • ISO/IEC 22989:2022 is a normative reference supplying AI concepts and terminology.

  • ISO/IEC 23894, ISO/IEC 5338, and ISO/IEC 38507 provide complementary risk, lifecycle, and governance guidance.

  • ISO/IEC 27001 and 27701 can integrate security and privacy management with an AIMS but do not replace AI-specific requirements.

  • ISO/IEC 42001 can support legal compliance; it does not certify compliance with every law or make adoption universally mandatory.

Last updated: October 2026

The ISO/IEC 42001 standards landscape

ISO/IEC 42001:2023 is an International Standard specifying requirements and providing guidance for establishing, implementing, maintaining, and continually improving an AI management system. It applies to organizations that develop, provide, or use products or services involving AI systems, regardless of size or sector.

It is a management-system standard. It governs organizational processes and responsibilities rather than certifying that one model is error-free or ethically perfect. An organization may seek third-party certification of its AIMS, but ISO itself does not perform certification.

Core standard and annexes

The standard’s architecture is:

  • Clauses 1–3: scope, normative references, and terms;
  • Clauses 4–10: AIMS requirements using the harmonized management-system structure;
  • Annex A, normative: reference control objectives and controls;
  • Annex B, normative: implementation guidance for the Annex A controls;
  • Annex C, informative: potential AI-related organizational objectives and risk sources; and
  • Annex D, informative: use of the AIMS across domains or sectors.

The normative reference in Clause 2 is ISO/IEC 22989:2022. This means its terminology is incorporated as required for applying ISO/IEC 42001. Calling it merely an optional glossary understates its role.

ISO/IEC 22989: concepts and terminology

ISO/IEC 22989 supplies a shared vocabulary for AI concepts and actors. It helps distinguish systems, models, stakeholders, lifecycle roles, and learning approaches. ISO/IEC 42001 then uses that vocabulary in a management-system context.

Use role terminology carefully. ISO concepts such as AI producer, provider, user, customer, and partner should not be casually replaced with legal role labels from a jurisdiction-specific law. An organization can occupy several roles at once.

ISO/IEC 23894: AI risk-management guidance

ISO/IEC 23894 provides guidance on managing AI-related risk. It complements the mandatory risk processes in ISO/IEC 42001 by offering broader risk-management concepts and considerations. It is not a replacement for Clauses 6.1.2, 6.1.3, 8.2, and 8.3.

A practical integration uses ISO/IEC 42001 to define the AIMS requirements and ISO/IEC 23894 to inform risk techniques, vocabulary, and implementation depth.

ISO/IEC 5338: AI lifecycle processes

ISO/IEC 5338 describes AI system lifecycle processes. Lifecycle activities include inception, design and development, verification and validation, deployment, operation and monitoring, continual validation, re-evaluation, and retirement. Annex A.6 of ISO/IEC 42001 contains related lifecycle controls, while ISO/IEC 5338 provides more detailed lifecycle process guidance.

Do not attribute the lifecycle model solely to ISO/IEC 22989. That standard is primarily concepts and terminology; ISO/IEC 5338 is the lifecycle-process reference.

ISO/IEC 38507: governance implications

ISO/IEC 38507 is an International Standard on governance implications of the use of AI by organizations. It addresses governing-body concerns and complements the management focus of ISO/IEC 42001. Governance directs and oversees; management plans and operates within that direction. It is inaccurate to call ISO/IEC 38507 a Technical Report.

Security and privacy standards

ISO/IEC 27001:2022 specifies requirements for an information security management system. The current ISO/IEC 27701:2025 specifies requirements and guidance for a privacy information management system and can be used as an independent management-system standard; it remains aligned for integration with ISO/IEC 27001. Their compatible structures make integration with an AIMS practical.

The relationship is complementary:

StandardPrimary focusWhy it matters to an AIMS
ISO/IEC 27001Information securityProtects data, models, systems, access, and operations
ISO/IEC 27701:2025Standalone privacy information management systemGoverns personally identifiable information and supports integration with an ISMS and AIMS
ISO/IEC 42001Responsible AI managementAdds AI-specific risk, impact, lifecycle, data, use, and value-chain controls

An existing ISMS can supply useful controls, but it does not automatically satisfy impact assessment, responsible-use objectives, AI lifecycle, or interested-party information requirements.

ISO/IEC 42005: impact-assessment guidance

ISO/IEC 42005:2025 provides guidance for AI system impact assessment. It can help organizations implement the impact-assessment requirements of ISO/IEC 42001. The later guidance standard does not change the Foundation exam’s core requirement: Clause 6.1.4 defines the process and Clause 8.4 performs assessments at planned intervals or when significant changes are proposed.

Laws and regulatory frameworks

Laws such as the EU AI Act can be applicable external requirements depending on role, system, and jurisdiction. ISO/IEC 42001 can help an organization build governance, evidence, risk processes, monitoring, and accountability that support compliance. It does not grant blanket legal compliance.

The EU AI Act uses its own role and risk-classification structure, including prohibited practices and obligations for certain high-risk systems. Precise classification is use-case-specific: for example, some workplace emotion-recognition uses are prohibited rather than merely “high risk.” A Foundation guide should not compress the regulation into a universal four-tier diagram and imply every example fits cleanly.

Certification and conformity

Organizations can implement ISO/IEC 42001 with or without seeking certification. If certification is sought, an independent certification body assesses the defined AIMS scope against applicable requirements. ISO publishes standards but does not certify organizations.

A person’s PECB Foundation certificate is different again. It demonstrates that the individual met PECB’s certificate requirements; it is not an ISO-issued credential and does not certify the individual’s employer.

How to answer relationship questions

Use this sequence:

  1. Identify whether the question asks about requirements, guidance, terminology, or law.
  2. Select ISO/IEC 42001 for AIMS requirements.
  3. Select ISO/IEC 22989 for terminology, 23894 for risk guidance, 5338 for lifecycle processes, and 38507 for governance implications.
  4. Treat 27001 and 27701 as complementary security/privacy systems.
  5. Treat laws as applicable requirements, not as interchangeable with voluntary standards.

Tip

Standards can be integrated, but passing one certification never proves automatic conformity with every other standard or law.

Test Your Knowledge

Which document is the normative terminology reference for ISO/IEC 42001?

A

ISO/IEC 23894

B

ISO/IEC 38507

C

ISO/IEC 27001

D

ISO/IEC 22989:2022

Test Your Knowledge

Which standard most directly provides AI system lifecycle process guidance?

A

ISO/IEC 5338

B

ISO 9001

C

ISO/IEC 27701

D

ISO/IEC 17021-1

Test Your Knowledge

What does ISO/IEC 42001 certification establish about laws such as the EU AI Act?

A

It automatically certifies compliance with every AI law

B

It can support compliance processes but does not guarantee blanket legal compliance

C

It replaces jurisdiction-specific obligations

D

It makes legal analysis unnecessary

Sections you finish are checked off in the contents.