2.1 ISO/IEC AI Standards Family
Key Takeaways
- ISO/IEC 42001:2023 is the certifiable requirements standard for an Artificial Intelligence Management System (AIMS), published in December 2023—auditors use it as primary audit criteria, not as optional guidance.
- ISO/IEC 22989 defines AI concepts and terminology; ISO/IEC 23053 frames machine-learning systems; ISO/IEC 23894 provides AI risk-management guidance; ISO/IEC 38507 addresses AI implications for governing bodies.
- Normative requirements (42001) create conformity obligations; guidance standards (23894, 38507, and much of 22989/23053 usage) inform judgment and evidence interpretation but are not automatic nonconformity criteria unless the organization has made them mandatory.
- ISO 19011 and ISO/IEC 17021-1 are the audit-methodology pillars for Lead Auditors: 19011 for audit principles and process, 17021-1 for management-system certification body competence and process requirements.
- An auditor who confuses a guidance document with a requirements standard will either invent nonconformities or miss real system gaps—know which document creates which obligation.
Why the AI Standards Family Matters to a Lead Auditor
A PECB ISO/IEC 42001 Lead Auditor does not audit "AI quality" in the abstract. You audit whether an organization's Artificial Intelligence Management System (AIMS) meets defined requirements and is effective for its intended outcomes. That work sits inside a deliberate family of ISO/IEC publications: one certifiable requirements standard, several concept and guidance standards, and two cross-cutting audit methodology pillars that apply whenever you plan, conduct, or report an AIMS audit.
If you cannot place each document in the right role—criteria versus vocabulary versus risk guidance versus board-level governance versus audit process—you will either cite the wrong document as a nonconformity basis or fail to use the right document when evidence is ambiguous. Exam and field competence both start with that map.
ISO/IEC 42001:2023 — The Certifiable AIMS Requirements Standard
ISO/IEC 42001:2023 is the management-system requirements standard for AI. It was published in December 2023. It follows the Annex SL high-level structure used by other modern management-system standards (context, leadership, planning, support, operation, performance evaluation, improvement), then adds AI-specific expectations—including risk and impact thinking for AI systems and a normative Annex A set of reference controls with implementation guidance in associated annexes.
What "certifiable" means in practice:
| Attribute | Auditor implication |
|---|---|
| Requirements language | "Shall" statements create conformity obligations when 42001 is the audit criterion |
| Scope of certification | Certification (when pursued) is of the AIMS, not of every model, algorithm, or vendor product in isolation |
| Primary criteria | For a 42001 audit, clauses 4–10 and applicable Annex A controls are the spine of the criteria |
| Evidence orientation | You seek system evidence: policies, roles, risk/impact processes, lifecycle controls, monitoring, internal audit, management review—not only a model accuracy report |
Scenario: A client says a high-accuracy fraud model means they are "ready for 42001." Re-center on the management system: AI accountability, inventory and scope, risk/impact processes, data and third-party controls, monitoring, and improvement. Model metrics support operational claims; they do not replace AIMS requirements.
Companion Standards: Concepts, ML Framework, Risk, and Governance
The broader ISO/IEC AI family gives auditors shared language and optional depth. These standards are not automatic substitutes for 42001 requirements.
ISO/IEC 22989 — AI Concepts and Terminology
ISO/IEC 22989 establishes AI concepts and terminology (AI system, machine learning, training data, model, lifecycle ideas). Use it to translate auditee jargon into auditable elements, clarify scope statements, and reduce ambiguity in findings. Trap: Citing 22989 as if it were a 42001 shall-requirement when it is not part of the agreed criteria.
ISO/IEC 23053 — Framework for Machine Learning Systems
ISO/IEC 23053 frames AI systems that use machine learning—data pipelines, training/evaluation, deployment, monitoring, and ML-specific behaviors (drift, re-training). Use it to design sampling for ML-heavy scopes and recognize expected artifacts. Trap: Treating 23053 as product certification of one model while ignoring whether the management system decides, resources, and improves those practices.
ISO/IEC 23894 — AI Risk Management Guidance
ISO/IEC 23894 is guidance on AI-related risk management. It complements—not replaces—42001 planning/risk and impact requirements, and helps you probe AI-specific harm pathways (bias, misuse, opacity, high-stakes automation), residual risk acceptance, and control linkage. Trap: Raising an NC only because "23894 section X" is missing when criteria are 42001 and 23894 was not made mandatory.
ISO/IEC 38507 — Governance Implications of AI for Governing Bodies
ISO/IEC 38507 addresses AI implications for governing bodies—useful when testing board/equivalent oversight of AI strategy, risk appetite, ethics constraints, and incident escalation. Shape top-management questions beyond a signed policy. Trap: Demanding a full 38507 governance program for every small operational scope while still testing real Clause 5 leadership accountability under 42001.
Normative Requirements vs Guidance — How Auditors Assign Weight
| Document role | Examples | Typical audit use |
|---|---|---|
| Requirements (normative for AIMS certification/conformity) | ISO/IEC 42001:2023 | Primary audit criteria; nonconformities must be traceable to applicable requirements |
| Concepts / terminology | ISO/IEC 22989 | Shared language; interpret evidence; reduce terminology disputes |
| Technical / ML framework | ISO/IEC 23053 | Context for ML system processes and artifacts |
| Risk guidance | ISO/IEC 23894 | Depth questions; evaluate risk approach reasonableness |
| Governing-body governance guidance | ISO/IEC 38507 | Leadership and oversight lines of inquiry |
| Audit process guidance / CB requirements | ISO 19011; ISO/IEC 17021-1 | How you audit; certification body process and competence |
Rule of thumb: If it is not in the agreed audit criteria (usually 42001 plus the organization's documented AIMS requirements and other applicable requirements it has committed to), it is not a free-standing nonconformity basis. Guidance can still support professional judgment about effectiveness and the significance of gaps against 42001.
ISO 19011 and ISO/IEC 17021-1 — Audit Methodology Pillars
ISO 19011 — Guidelines for Auditing Management Systems
ISO 19011 is the global reference for auditing management systems. For Lead Auditors it underpins:
- Audit principles (integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, risk-based approach)
- Managing an audit program
- Conducting an audit (initiation, preparation, document review, on-site/remote activities, findings, conclusions, report, follow-up)
- Competence and evaluation of auditors
Even in certification contexts that apply ISO/IEC 17021-1, 19011 thinking remains the professional language of planning, sampling, interviewing, and reporting expected of Lead Auditors.
ISO/IEC 17021-1 — Requirements for Bodies Providing Audit and Certification of Management Systems
ISO/IEC 17021-1 sets requirements for certification bodies that audit and certify management systems—impartiality, certification decisions, two-stage initial audit concepts, surveillance, and competence. Those conformity-assessment rules sit outside 42001 itself.
Practical distinction:
- 42001 answers: "What must the organization's AIMS achieve and control?"
- 19011 answers: "How should auditors plan and perform management-system audits?"
- 17021-1 answers: "How must a certification body operate when it certifies management systems?"
Putting It Together & Exam Traps
In one audit narrative: agree 42001 (plus other committed requirements) as criteria; use 22989/23053 for language and ML context; test clauses 4–10 and applicable Annex A with 19011 methods; deepen risk/governance inquiry with 23894/38507 without inventing shalls; report findings against agreed criteria only.
- Trap — "All ISO AI standards are certifiable." Only 42001 is the AIMS requirements standard for certification.
- Trap — "Audit the model, not the system." Model metrics can support operational evidence; conformity is judged at AIMS level.
- Trap — "17021-1 replaces 19011 for internal auditors." Internal auditors still apply 19011; 17021-1 is CB-oriented.
- Trap — "December 2023 means draft only." 42001:2023 is a published International Standard and the current AIMS requirements baseline unless a later edition is the criterion.
ISO/IEC 42001:2023 is best described as which of the following?
During a Stage 1 document review, an auditor finds the organization never mentions ISO/IEC 23894. Which action is most appropriate when 42001 is the sole audit criterion?
Which pairing correctly matches document to primary auditor use?
A certification body is planning an initial certification audit of an organization's AIMS against ISO/IEC 42001. Which statement best reflects the methodology pillars?