1.2 The ISO/IEC Standards Family for AI (42001, 23894, 5338, 38507, 42005)
Key Takeaways
- ISO/IEC 42001:2023 is the flagship certifiable requirements standard for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS).
- ISO/IEC 23894:2023 extends the ISO 31000 risk management framework specifically to AI-related risks, guiding threat identification, impact analysis, and treatment strategies.
- ISO/IEC 5338:2023 adapts international software lifecycle standards (ISO/IEC/IEEE 12207 and 15288) to address the unique iteration, data pipeline, and model retraining cycles of AI systems.
- ISO/IEC 38507:2022 provides strategic guidance for governing bodies (Boards of Directors and executive committees) on organizational implications and oversight of AI adoption.
- ISO/IEC 42005:2025 defines methodologies for conducting comprehensive AI system impact assessments (AIAs) covering societal, ethical, individual, and environmental factors.
1.2 The ISO/IEC Standards Family for AI (42001, 23894, 5338, 38507, 42005)
As artificial intelligence technologies rapidly proliferate across global industries, international standard bodies (ISO and IEC through Joint Technical Committee ISO/IEC JTC 1/SC 42 Artificial Intelligence) have established a comprehensive suite of standards. For an ISO/IEC 42001 Lead Implementer, understanding how these standards interlock is essential for designing an integrated, audit-ready governance framework that addresses strategic oversight, system lifecycle processes, risk management, and impact assessments.
Overview of the Core ISO/IEC AI Ecosystem
The ISO/IEC AI standard series is anchored by ISO/IEC 42001:2023, supported by specialized technical specifications and guidance standards:
[ ISO/IEC 38507 ]
Governance & Executive Oversight
│
▼
[ ISO/IEC 42001 ] ◄─── (Certifiable Core AIMS)
Requirements Standard (Clauses 4-10)
│
┌───────────────────────────┼───────────────────────────┐
▼ ▼ ▼
[ ISO/IEC 23894 ] [ ISO/IEC 5338 ] [ ISO/IEC 42005 ]
AI Risk Management AI System Life Cycle AI Impact Assessment
Deep-Dive into Core Family Standards
1. ISO/IEC 42001:2023 — Artificial Intelligence Management System (AIMS) Requirements
ISO/IEC 42001 is the world's first certifiable international management system standard for AI. Built upon the ISO Harmonized Structure (formerly High-Level Structure / HLS), it enables organizations to establish management controls across two distinct parts:
- Normative Clauses 4 through 10: Mandatory management system requirements covering Organizational Context (Clause 4), Leadership (Clause 5), Planning & Risk Assessment (Clause 6), Support & Resources (Clause 7), Operation (Clause 8), Performance Evaluation (Clause 9), and Improvement (Clause 10).
- Annex A (Normative Controls): A catalog of 38 information security, safety, and responsible AI control objectives across 10 domains, including AI impact assessment, data governance, system lifecycle, third-party transparency, and organizational alignment.
- Annex B (Implementation Guidance): Guidance for implementing Annex A controls.
- Annex C (Potential AI Objectives): Practical guidance on establishing organizational AI objectives.
2. ISO/IEC 23894:2023 — Guidance on Risk Management for AI
ISO/IEC 23894 adapts the principles of ISO 31000:2018 (Risk management — Guidelines) specifically to the AI domain. It provides practical guidance on identifying, analyzing, evaluating, and treating risks unique to AI systems, such as opacity (black-box risk), autonomy runaway, statistical bias, data poisoning, and dynamic drift. It integrates directly with ISO/IEC 42001 Clause 6.1 (Actions to address risks and opportunities).
3. ISO/IEC 5338:2023 — AI System Life Cycle Processes
ISO/IEC 5338 extends established software engineering lifecycle standards (ISO/IEC/IEEE 12207 for software and 15288 for system engineering) into the AI domain. It defines process workflows tailored for machine learning and deep learning, including model re-training triggers, dataset continuous integration/continuous deployment (CI/CD), version control for data/models/code, and model decommissioning.
4. ISO/IEC 38507:2022 — Governance Implications of AI for Organizations
ISO/IEC 38507 expands the ISO/IEC 38500 corporate IT governance framework to assist governing bodies (Boards of Directors, Trustees, Executive Leadership) in assessing, directing, and monitoring AI adoption. It addresses strategic alignment, accountability, value realization, risk appetite, and societal ethics from an executive leadership perspective.
5. ISO/IEC 42005:2025 — AI System Impact Assessment (AIA)
ISO/IEC 42005 provides a standardized methodology for planning, conducting, and documenting AI Impact Assessments (AIAs). It guides organizations in evaluating potential consequences across multiple dimensions: individual rights, societal well-being, ethical fairness, health and safety, data privacy, and environmental sustainability. Conducting AIAs is a mandatory prerequisite under ISO/IEC 42001 Annex A.5.
Standards Family Comparison Matrix
| Standard | Title / Primary Focus | Certifiable? | Primary Target Audience | Role in AIMS Project |
|---|---|---|---|---|
| ISO/IEC 42001:2023 | AIMS Requirements | Yes | Lead Implementers, Auditors, Chief AI Officers | Core audit scope; defines mandatory requirements & Annex A controls. |
| ISO/IEC 23894:2023 | AI Risk Management Guidance | No | Risk Officers, Compliance Managers | Provides methodologies for Clause 6.1 risk assessment & treatment. |
| ISO/IEC 5338:2023 | AI Lifecycle Processes | No | MLOps Engineers, AI Architects, Developers | Guides technical execution of Clause 8.2 & Annex A.8 controls. |
| ISO/IEC 38507:2022 | Corporate Governance of AI | No | Board of Directors, CEOs, Executive Committees | Establishes strategic leadership directives for Clause 5.1. |
| ISO/IEC 42005:2025 | AI Impact Assessment | No | Privacy Officers, Ethicists, Lead Implementers | Provides AIA templates and evaluation methods for Annex A.5. |
Building an Integrated AIMS Architecture
A Lead Implementer must synthesize these standards into an operational, audit-ready framework:
- Executive Mandate (ISO/IEC 38507): Board approves AI risk appetite, strategic goals, and ethical boundaries.
- AIMS Core Framework (ISO/IEC 42001 Clauses 4–10): Establish organizational context, leadership commitment, policies, support infrastructure, internal audit, and management review.
- Risk Management Engine (ISO/IEC 23894): Execute AI risk assessments covering technical, operational, legal, and ethical dimensions.
- Impact Assessment Protocol (ISO/IEC 42005): Perform formal AI Impact Assessments for high-risk system deployments.
- Engineering & Lifecycle Operations (ISO/IEC 5338): Embed AIMS controls into data engineering, MLOps, model deployment, and monitoring pipelines.
Practical Implementation Scenario
Scenario: HealthGuard AI is a SaaS provider deploying diagnostic radiology models. The Chief Operations Officer (COO) wants to achieve ISO/IEC 42001 certification within 9 months but is confused about which standards are mandatory and which are optional.
Lead Implementer Guidance: The Lead Implementer clarifies that ISO/IEC 42001:2023 is the only certifiable requirements standard that external registrars will audit against. However, attempting to implement 42001 in isolation is inefficient. The Implementer leverages ISO/IEC 23894 to structure the AI risk assessment matrix required under Clause 6.1, applies ISO/IEC 42005 to build the AI Impact Assessment framework required by Annex A.5, and uses ISO/IEC 5338 to align the MLOps engineering pipeline with Annex A.8 control objectives. This integrated approach ensures thorough compliance, technical rigour, and audit readiness.
An enterprise is seeking accredited third-party certification of its AI governance controls. Against which standard in the ISO/IEC AI family will the external certification body conduct the formal audit?
Which ISO/IEC standard provides specific guidance adapted from ISO 31000 for identifying, analyzing, and treating risks unique to AI systems such as opacity, autonomy runaway, and data drift?
What is the primary focus of ISO/IEC 5338:2023 within an ISO/IEC 42001 implementation project?