365Architect

ISO/IEC 42001:2023 — AI Management System

ISO/IEC 42001:2023 is the first certifiable international standard for AI management systems. Unlike the voluntary NIST AI RMF, ISO 42001 provides auditable requirements (Clauses 4–10) and a normative control set (Annex A) for third-party certification.

Scope and Structure

Clause Title Key Requirements
4 Context of the Organisation Internal/external issues, interested parties, AI system scope
5 Leadership AI policy, roles, commitment, organisational culture
6 Planning Risk assessment, AI objectives, change management
7 Support Resources, competence, awareness, communication, documented information
8 Operation AI risk assessment, AI system impact assessment, lifecycle management
9 Performance Evaluation Monitoring, internal audit, management review
10 Improvement Nonconformity, corrective action, continual improvement

Annex A — Normative Controls (38 Controls)

Annex A organises controls into 10 domains (A.1–A.10):

Domain Controls Focus
A.1 A.1.1–A.1.4 AI policy and objectives
A.2 A.2.1–A.2.3 Internal organisation and responsibilities
A.3 A.3.1–A.3.3 AI system resources and asset management
A.4 A.4.1–A.4.4 AI system lifecycle and impact assessment
A.5 A.5.1–A.5.5 Data management for AI systems
A.6 A.6.1–A.6.3 Information security for AI
A.7 A.7.1–A.7.3 AI system development and acquisition
A.8 A.8.1–A.8.3 AI system deployment and operation
A.9 A.9.1–A.9.3 Performance evaluation and monitoring
A.10 A.10.1–A.10.3 Continual improvement

Primary source: ISO/IEC 42001:2023, Clauses 4–10 and Annex A. ISO Catalogue

Key Differences: ISO 42001 vs. NIST AI RMF

Aspect ISO/IEC 42001 NIST AI RMF (AI 100-1)
Nature Certifiable management system standard Voluntary risk management framework
Audience Organisations seeking certification Any organisation managing AI risk
Controls 38 normative Annex A controls ~100 suggested actions in Playbook
Governance Requires top management commitment (Clause 5) GOVERN function suggested
Lifecycle Explicit lifecycle management (Clause 8) MAP/MANAGE functions cover lifecycle
Audit Third-party certification audits Self-assessment or peer review

Integration with EU AI Act

ISO 42001 is not a harmonised standard under the EU AI Act (as of 2024). However:

  • It provides a demonstrable governance framework for Art. 9 (Risk management) and Art. 17 (Quality management) compliance
  • Notified bodies may recognise ISO 42001 certification as supporting evidence for conformity assessment
  • The standard's Annex A controls map to AI Act requirements for high-risk systems

Citation

  • Instrument: ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system
  • Publisher: International Organization for Standardization / International Electrotechnical Commission
  • Date: December 2023
  • URL: https://www.iso.org/standard/81230.html
  • Status: Published; certifiable via accredited certification bodies (e.g., ANAB, UKAS, DAkkS)
Share

Keyboard Shortcuts

⌘ K
Open search
/
Focus search
?
Show shortcuts
b
Toggle bookmark
Alt+←
Previous page
Alt+→
Next page
Esc
Close overlay