AI governance

ISO 42001: first steps for an AI management system

ISO/IEC 42001 applies management-system discipline to AI. If you already run an ISO 27001 ISMS, most of the scaffolding exists.

Short answer

ISO/IEC 42001:2023 is a certifiable standard for an AI management system (AIMS). It uses the same clause structure as ISO 27001, so organisations with an existing ISMS can extend their context, risk assessment, internal audit and management review processes, then add AI-specific impact assessments and the Annex A AI controls.

Key takeaways

  • Same harmonised clause structure as ISO 27001.
  • Adds AI system impact assessment and AI-specific Annex A controls.
  • Reuse ISMS processes; do not build a parallel system.

What ISO 42001 requires

The standard asks you to define the AI systems in scope, your role for each (developer, provider, user), and to assess risks and impacts on individuals and society, not only on the organisation.

Starting from an existing ISMS

  • Extend the context analysis to cover AI roles and stakeholders.
  • Add an AI system impact assessment alongside the information security risk assessment.
  • Include AI objectives in management review.
  • Scope internal audits to cover both standards.

Frequently asked questions

Is ISO 42001 certifiable?

Yes. ISO/IEC 42001:2023 contains requirements an accredited certification body can audit against, like ISO/IEC 27001.

Sources

  1. ISO/IEC 42001:2023 Artificial intelligence management system, ISO