Short answer
ISO/IEC 42001:2023 is a certifiable standard for an AI management system (AIMS). It uses the same clause structure as ISO 27001, so organisations with an existing ISMS can extend their context, risk assessment, internal audit and management review processes, then add AI-specific impact assessments and the Annex A AI controls.
Key takeaways
- Same harmonised clause structure as ISO 27001.
- Adds AI system impact assessment and AI-specific Annex A controls.
- Reuse ISMS processes; do not build a parallel system.
What ISO 42001 requires
The standard asks you to define the AI systems in scope, your role for each (developer, provider, user), and to assess risks and impacts on individuals and society, not only on the organisation.
Starting from an existing ISMS
- Extend the context analysis to cover AI roles and stakeholders.
- Add an AI system impact assessment alongside the information security risk assessment.
- Include AI objectives in management review.
- Scope internal audits to cover both standards.
Frequently asked questions
Is ISO 42001 certifiable?
Yes. ISO/IEC 42001:2023 contains requirements an accredited certification body can audit against, like ISO/IEC 27001.