2.1 AI System Concepts & Lifecycle Stages
Key Takeaways
ISO/IEC 22989:2022 is the normative terminology reference for ISO/IEC 42001.
Organizations can develop, provide, or use AI systems and can hold several roles at once.
AI includes rule-based and machine-learning approaches; not every AI system is probabilistic.
ISO/IEC 5338 lifecycle processes include inception through retirement, with continual validation and re-evaluation after deployment.
Lifecycle controls should be proportionate to intended use, context, impacts, and risk.
AI concepts, actors, and lifecycle foundations
ISO/IEC 42001 is a management-system standard, not an algorithm-design manual. Candidates still need a stable vocabulary because the management requirements apply to AI systems with very different technologies and organizational roles. ISO/IEC 22989:2022 is the normative reference for AI concepts and terminology in ISO/IEC 42001.
What counts as an AI system
An AI system is an engineered system that generates outputs such as content, forecasts, recommendations, or decisions for stated objectives. Its techniques can include machine learning, knowledge-based methods, search, optimization, planning, or combinations of these.
Avoid two common overgeneralizations. First, AI is not synonymous with machine learning. A knowledge-based expert system can use explicitly encoded rules and may behave deterministically for the same input and state. Second, not every AI output is inherently random. Some machine-learning inference pipelines are configured deterministically, while generative systems can use stochastic sampling. Governance should follow actual characteristics, not slogans.
A useful comparison is:
| Approach | Where behavior mainly comes from | Typical concern |
|---|---|---|
| Rule or knowledge based | Human-authored rules and knowledge | Rule completeness, conflicts, maintenance |
| Supervised machine learning | Patterns learned from labelled examples | Representativeness, label quality, generalization |
| Unsupervised learning | Structure inferred from unlabelled data | Meaning of clusters, instability, validation |
| Reinforcement learning | Rewards and interaction with an environment | Reward misspecification, exploration, feedback |
| Generative AI | Learned distributions used to generate new content | Hallucination, provenance, misuse, harmful content |
These categories can overlap. An application may combine rules, retrieval, a predictive model, and a generative interface.
Organizational roles
ISO terminology describes roles across an AI value chain. Examples include an AI producer, AI provider, AI user, AI customer, and AI partner. One organization can hold more than one role. A software company might develop a model, provide it as a service, and also use it internally. A bank consuming a vendor model in underwriting is an AI user and customer; it still controls its deployment context and cannot treat the vendor relationship as a substitute for its own AIMS responsibilities.
Do not automatically replace ISO role language with the EU AI Act’s legal role labels. Terms such as provider, deployer, importer, and distributor have defined meanings in that regulation. They can be relevant applicable requirements, but a Foundation question about ISO/IEC 42001 terminology should be answered from the standard’s context.
Interested parties extend beyond organizations in the supply chain. Employees, end users, regulators, communities, individuals affected by decisions, and groups exposed to collective impacts may have relevant needs or expectations. Clause 4 requires the organization to determine which interested-party requirements matter to the AIMS.
AI system and management-system boundaries
An AI system is the technical and socio-technical system that produces outputs. An AIMS is the organization’s set of interrelated policies, objectives, roles, and processes for responsible development, provision, or use of AI systems. AIMS scope may cover an organization, business unit, service, or defined portfolio. The management system governs AI work; it is not itself the model.
That distinction is important in scenarios. A model update is a change to an AI system. It may also require changes to AIMS processes or controls. Clause 6.3 directly addresses planned changes to the AIMS, while Clause 8.1 controls planned and unintended operational changes. Annex A.6 addresses lifecycle controls for AI systems.
Lifecycle thinking
ISO/IEC 42001 does not reduce the lifecycle to one universal six-stage sequence. ISO/IEC 5338 provides AI lifecycle process guidance with stages commonly presented as:
- Inception
- Design and development
- Verification and validation
- Deployment
- Operation and monitoring
- Continual validation
- Re-evaluation
- Retirement
The point is not to memorize a waterfall. Activities can iterate, overlap, and return to earlier stages. Continual validation and re-evaluation are especially important because operational context, input distributions, suppliers, user behavior, and applicable requirements can change. A model does not “inevitably decay,” but its performance or impacts can change enough that monitoring and re-evaluation are necessary.
Inception
Define purpose, intended use, stakeholders, constraints, and whether AI is an appropriate solution. Early questions include who might benefit or be harmed, what decisions the system influences, and which requirements apply.
Design and development
Translate objectives into requirements and specifications. Address data, architecture, interfaces, security, human interaction, and control measures. Document design decisions in proportion to the system’s risk and context.
Verification and validation
Verification asks whether specified requirements were implemented; validation asks whether the resulting system is suitable for intended use and context. Exact methods depend on the system. Examples include functional tests, subgroup analysis, robustness testing, human-factors evaluation, or domain-expert review.
Deployment and operation
Use a deployment plan, confirm prerequisites, communicate needed information, and monitor technical and impact-related performance. Operation can reveal issues absent from development data.
Continual validation and re-evaluation
Review whether assumptions, requirements, controls, and impact assessments remain suitable. Significant changes can trigger renewed risk and impact assessment.
Retirement
Plan decommissioning, dependencies, records, data retention or disposal, customer communication, and migration. Retirement is a governed lifecycle stage, not simply turning off a server.
Selecting controls proportionately
ISO/IEC 42001 is risk-based and context-sensitive. A low-impact internal classifier and an AI system influencing medical treatment do not need identical evidence or oversight. The organization determines risks to its objectives, assesses potential consequences for individuals, groups, and societies, chooses necessary controls, and records applicability in the SoA.
Tip
In a scenario, identify four things before choosing an answer: the organization’s role, the lifecycle stage, the intended use, and the affected interested parties. Those cues usually point to the relevant clause or Annex A group.
Which statement best reflects the relationship between AI and machine learning?
Every AI system must learn probabilistically from training data
Rule-based systems are never considered AI
Machine learning is one family of AI techniques, while AI can also use knowledge-based or other methods
Generative AI is the only form governed by ISO/IEC 42001
A bank licenses a vendor model and integrates it into its own lending workflow. Which role statement is most accurate?
Only the vendor has an AI-related role
The bank cannot be an AI user because it did not train the model
The bank is automatically the ISO certification body
The bank is an AI user and customer and retains responsibilities for its own context of use
Why are continual validation and re-evaluation part of AI lifecycle thinking?
Operational context, data, performance, suppliers, and impacts can change after deployment
All models inevitably fail exactly one year after deployment
They replace initial verification and validation
They apply only to retired systems
Sections you finish are checked off in the contents.