ISO/IEC 42001:2023 — AI Management System
ISO/IEC 42001:2023 is the first certifiable international standard for AI management systems. Unlike the voluntary NIST AI RMF, ISO 42001 provides auditable requirements (Clauses 4–10) and a normative control set (Annex A) for third-party certification.
Scope and Structure
| Clause | Title | Key Requirements |
|---|---|---|
| 4 | Context of the Organisation | Internal/external issues, interested parties, AI system scope |
| 5 | Leadership | AI policy, roles, commitment, organisational culture |
| 6 | Planning | Risk assessment, AI objectives, change management |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | AI risk assessment, AI system impact assessment, lifecycle management |
| 9 | Performance Evaluation | Monitoring, internal audit, management review |
| 10 | Improvement | Nonconformity, corrective action, continual improvement |
Annex A — Normative Controls (38 Controls)
Annex A organises controls into 10 domains (A.1–A.10):
| Domain | Controls | Focus |
|---|---|---|
| A.1 | A.1.1–A.1.4 | AI policy and objectives |
| A.2 | A.2.1–A.2.3 | Internal organisation and responsibilities |
| A.3 | A.3.1–A.3.3 | AI system resources and asset management |
| A.4 | A.4.1–A.4.4 | AI system lifecycle and impact assessment |
| A.5 | A.5.1–A.5.5 | Data management for AI systems |
| A.6 | A.6.1–A.6.3 | Information security for AI |
| A.7 | A.7.1–A.7.3 | AI system development and acquisition |
| A.8 | A.8.1–A.8.3 | AI system deployment and operation |
| A.9 | A.9.1–A.9.3 | Performance evaluation and monitoring |
| A.10 | A.10.1–A.10.3 | Continual improvement |
Primary source: ISO/IEC 42001:2023, Clauses 4–10 and Annex A. ISO Catalogue
Key Differences: ISO 42001 vs. NIST AI RMF
| Aspect | ISO/IEC 42001 | NIST AI RMF (AI 100-1) |
|---|---|---|
| Nature | Certifiable management system standard | Voluntary risk management framework |
| Audience | Organisations seeking certification | Any organisation managing AI risk |
| Controls | 38 normative Annex A controls | ~100 suggested actions in Playbook |
| Governance | Requires top management commitment (Clause 5) | GOVERN function suggested |
| Lifecycle | Explicit lifecycle management (Clause 8) | MAP/MANAGE functions cover lifecycle |
| Audit | Third-party certification audits | Self-assessment or peer review |
Integration with EU AI Act
ISO 42001 is not a harmonised standard under the EU AI Act (as of 2024). However:
- It provides a demonstrable governance framework for Art. 9 (Risk management) and Art. 17 (Quality management) compliance
- Notified bodies may recognise ISO 42001 certification as supporting evidence for conformity assessment
- The standard's Annex A controls map to AI Act requirements for high-risk systems
Citation
- Instrument: ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system
- Publisher: International Organization for Standardization / International Electrotechnical Commission
- Date: December 2023
- URL: https://www.iso.org/standard/81230.html
- Status: Published; certifiable via accredited certification bodies (e.g., ANAB, UKAS, DAkkS)