AI governance

What is ISO 42001?

ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence, an AI Management System (AIMS). It gives organizations a certifiable way to govern the responsible development and use of AI, using the same management-system structure as ISO 27001.

Definition

ISO/IEC 42001 is an international standard, published in 2023, that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within an organization.

Background

Published in 2023, ISO/IEC 42001 is the first management-system standard dedicated to AI. Like ISO 27001 (for information security), it follows the harmonized management-system structure: clauses 4 to 10 cover organizational context, leadership, planning, support, operation, performance evaluation, and improvement. Its Annex A provides reference controls organized into nine control objectives, spanning areas such as AI policy, internal organization and roles, resources and data for AI, and the AI system lifecycle.

Why it matters

As AI scrutiny and regulation grow, buyers and partners increasingly ask how you govern AI, not just how you secure data. ISO 42001 gives organizations a recognized, auditable answer, and because it shares ISO 27001’s structure, teams with a mature security program have a head start on it.

Step by step

  1. Define the scope of your AI management system and the context it operates in.
  2. Set AI policy, roles, and objectives with leadership ownership.
  3. Assess AI-related risks and impacts, including to affected individuals.
  4. Implement the relevant Annex A controls (data governance, transparency, human oversight, lifecycle).
  5. Monitor, audit, and improve the system on a defined cadence.

Examples

  • An AI company adopts ISO 42001 to show enterprise buyers it governs model development, data, and oversight systematically.
  • A team with ISO 27001 reuses its management-system structure to stand up an AIMS with less duplicated effort.

Common mistakes

  • Treating ISO 42001 as a security standard; it governs AI management specifically, and is separate from ISO 27001.
  • Assuming it replaces the EU AI Act; it is a voluntary certifiable standard, while the AI Act is law.
  • Skipping AI-specific concerns such as transparency, human oversight, and impact on affected people.

FAQ

Is ISO 42001 the same as ISO 27001?

No. ISO 27001 manages information security; ISO/IEC 42001 manages AI. They share the same management-system structure, so they pair well, but they address different risks and are certified separately.

How does ISO 42001 relate to the EU AI Act and NIST AI RMF?

ISO 42001 is a certifiable management standard, the NIST AI Risk Management Framework is a voluntary framework, and the EU AI Act is law (Regulation (EU) 2024/1689). ISO 42001 is a practical way to operationalize responsible-AI practices that also support the others.

Related

ISO 42001 for AI companies → What is AI governance? → What is the EU AI Act? → AI governance in Keel →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free