2.1 AI System Concepts & Lifecycle Stages

Key Takeaways

  • ISO/IEC 22989:2022 is the normative terminology reference for ISO/IEC 42001.

  • Organizations can develop, provide, or use AI systems and can hold several roles at once.

  • AI includes rule-based and machine-learning approaches; not every AI system is probabilistic.

  • ISO/IEC 5338 lifecycle processes include inception through retirement, with continual validation and re-evaluation after deployment.

  • Lifecycle controls should be proportionate to intended use, context, impacts, and risk.

Last updated: October 2026

AI concepts, actors, and lifecycle foundations

ISO/IEC 42001 is a management-system standard, not an algorithm-design manual. Candidates still need a stable vocabulary because the management requirements apply to AI systems with very different technologies and organizational roles. ISO/IEC 22989:2022 is the normative reference for AI concepts and terminology in ISO/IEC 42001.

What counts as an AI system

An AI system is an engineered system that generates outputs such as content, forecasts, recommendations, or decisions for stated objectives. Its techniques can include machine learning, knowledge-based methods, search, optimization, planning, or combinations of these.

Avoid two common overgeneralizations. First, AI is not synonymous with machine learning. A knowledge-based expert system can use explicitly encoded rules and may behave deterministically for the same input and state. Second, not every AI output is inherently random. Some machine-learning inference pipelines are configured deterministically, while generative systems can use stochastic sampling. Governance should follow actual characteristics, not slogans.

A useful comparison is:

ApproachWhere behavior mainly comes fromTypical concern
Rule or knowledge basedHuman-authored rules and knowledgeRule completeness, conflicts, maintenance
Supervised machine learningPatterns learned from labelled examplesRepresentativeness, label quality, generalization
Unsupervised learningStructure inferred from unlabelled dataMeaning of clusters, instability, validation
Reinforcement learningRewards and interaction with an environmentReward misspecification, exploration, feedback
Generative AILearned distributions used to generate new contentHallucination, provenance, misuse, harmful content

These categories can overlap. An application may combine rules, retrieval, a predictive model, and a generative interface.

Organizational roles

ISO terminology describes roles across an AI value chain. Examples include an AI producer, AI provider, AI user, AI customer, and AI partner. One organization can hold more than one role. A software company might develop a model, provide it as a service, and also use it internally. A bank consuming a vendor model in underwriting is an AI user and customer; it still controls its deployment context and cannot treat the vendor relationship as a substitute for its own AIMS responsibilities.

Do not automatically replace ISO role language with the EU AI Act’s legal role labels. Terms such as provider, deployer, importer, and distributor have defined meanings in that regulation. They can be relevant applicable requirements, but a Foundation question about ISO/IEC 42001 terminology should be answered from the standard’s context.

Interested parties extend beyond organizations in the supply chain. Employees, end users, regulators, communities, individuals affected by decisions, and groups exposed to collective impacts may have relevant needs or expectations. Clause 4 requires the organization to determine which interested-party requirements matter to the AIMS.

AI system and management-system boundaries

An AI system is the technical and socio-technical system that produces outputs. An AIMS is the organization’s set of interrelated policies, objectives, roles, and processes for responsible development, provision, or use of AI systems. AIMS scope may cover an organization, business unit, service, or defined portfolio. The management system governs AI work; it is not itself the model.

That distinction is important in scenarios. A model update is a change to an AI system. It may also require changes to AIMS processes or controls. Clause 6.3 directly addresses planned changes to the AIMS, while Clause 8.1 controls planned and unintended operational changes. Annex A.6 addresses lifecycle controls for AI systems.

Lifecycle thinking

ISO/IEC 42001 does not reduce the lifecycle to one universal six-stage sequence. ISO/IEC 5338 provides AI lifecycle process guidance with stages commonly presented as:

  1. Inception
  2. Design and development
  3. Verification and validation
  4. Deployment
  5. Operation and monitoring
  6. Continual validation
  7. Re-evaluation
  8. Retirement

The point is not to memorize a waterfall. Activities can iterate, overlap, and return to earlier stages. Continual validation and re-evaluation are especially important because operational context, input distributions, suppliers, user behavior, and applicable requirements can change. A model does not “inevitably decay,” but its performance or impacts can change enough that monitoring and re-evaluation are necessary.

Inception

Define purpose, intended use, stakeholders, constraints, and whether AI is an appropriate solution. Early questions include who might benefit or be harmed, what decisions the system influences, and which requirements apply.

Design and development

Translate objectives into requirements and specifications. Address data, architecture, interfaces, security, human interaction, and control measures. Document design decisions in proportion to the system’s risk and context.

Verification and validation

Verification asks whether specified requirements were implemented; validation asks whether the resulting system is suitable for intended use and context. Exact methods depend on the system. Examples include functional tests, subgroup analysis, robustness testing, human-factors evaluation, or domain-expert review.

Deployment and operation

Use a deployment plan, confirm prerequisites, communicate needed information, and monitor technical and impact-related performance. Operation can reveal issues absent from development data.

Continual validation and re-evaluation

Review whether assumptions, requirements, controls, and impact assessments remain suitable. Significant changes can trigger renewed risk and impact assessment.

Retirement

Plan decommissioning, dependencies, records, data retention or disposal, customer communication, and migration. Retirement is a governed lifecycle stage, not simply turning off a server.

Selecting controls proportionately

ISO/IEC 42001 is risk-based and context-sensitive. A low-impact internal classifier and an AI system influencing medical treatment do not need identical evidence or oversight. The organization determines risks to its objectives, assesses potential consequences for individuals, groups, and societies, chooses necessary controls, and records applicability in the SoA.

Tip

In a scenario, identify four things before choosing an answer: the organization’s role, the lifecycle stage, the intended use, and the affected interested parties. Those cues usually point to the relevant clause or Annex A group.

Test Your Knowledge

Which statement best reflects the relationship between AI and machine learning?

A

Every AI system must learn probabilistically from training data

B

Rule-based systems are never considered AI

C

Machine learning is one family of AI techniques, while AI can also use knowledge-based or other methods

D

Generative AI is the only form governed by ISO/IEC 42001

Test Your Knowledge

A bank licenses a vendor model and integrates it into its own lending workflow. Which role statement is most accurate?

A

Only the vendor has an AI-related role

B

The bank cannot be an AI user because it did not train the model

C

The bank is automatically the ISO certification body

D

The bank is an AI user and customer and retains responsibilities for its own context of use

Test Your Knowledge

Why are continual validation and re-evaluation part of AI lifecycle thinking?

A

Operational context, data, performance, suppliers, and impacts can change after deployment

B

All models inevitably fail exactly one year after deployment

C

They replace initial verification and validation

D

They apply only to retired systems

Sections you finish are checked off in the contents.