Strategy & governance

ISO/IEC 42001

AI management system standard · AIMS

The international standard that specifies how an organisation should set up, run and improve a management system for the AI it develops or uses, and against which it can be certified by an independent auditor.

Planpolicy, risk and impact assessmentDocontrols, roles, life cycleCheckmonitoring, internal audit, reviewActnonconformity, corrective actionMANAGEMENT SYSTEMcertifiableThe certificate shows that a management system is in place; it does not show that any given model is accurate or fair.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/iso-iec-42001

In plain terms

ISO 9001 does not tell a factory how to make a good product; it tells it how to run a system that keeps quality under control, and an auditor checks that the system exists and works. ISO/IEC 42001 does the same for AI. It prescribes no model and no technique. It asks whether the organisation has a policy, knows which AI it uses, assesses the risks and the effects on people, assigns responsibility, monitors results and corrects what goes wrong.

Why it matters

A certificate answers, in one page, the question that customers and procurement teams now put to every supplier of AI: how do you govern this? For companies that already hold ISO/IEC 27001 for information security, the structure is familiar and much of the groundwork is shared. Two limits should be understood. Certification shows that a management system is in place; it does not show that any particular model is accurate or fair. And it is no proof of compliance with the EU AI Act, though it covers a good part of the same ground.

Example

A software company that sells an AI assistant for HR departments loses two bids because buyers ask for evidence of AI governance and it has none to show. It spends seven months building the management system: an AI policy, an inventory of 14 systems, impact assessments for the three that affect job applicants, defined roles and an internal audit. After the external audit it holds the certificate. In the next bidding round the question is answered with one document.

Most often confused with

ISO/IEC 42001 vs. NIST AI RMF

ISO/IEC 42001A certifiable standard with auditable requirements
NIST AI RMFA voluntary framework of guidance, with no certificate

They are complementary, and many organisations use both: the NIST framework as a detailed guide to thinking about AI risk, and ISO/IEC 42001 as the management system that an outside auditor can check. Customers in Europe and Asia tend to ask for the ISO certificate; organisations working with the US public sector meet the NIST framework more often.

Under the hood

Published in December 2023 by ISO and IEC. It follows the harmonised structure of ISO management-system standards, the same as ISO 9001 and ISO/IEC 27001, with clauses on context, leadership, planning, support, operation, performance evaluation and improvement, and works on the plan-do-check-act cycle. Specific to AI: an AI policy and objectives; AI risk assessment and treatment; an AI system impact assessment covering effects on individuals and society; and a set of reference controls in Annex A, with implementation guidance in Annex B, on topics such as responsibilities, resources and data, the AI system life cycle, information for users and third-party relationships. The organisation states which controls apply in a statement of applicability. It covers both providers and users of AI and scales to any size. Certification runs in a three-year cycle with annual surveillance audits. Related standards: ISO/IEC 22989 (terminology), ISO/IEC 23894 (guidance on AI risk management), ISO/IEC 42005 (impact assessment) and ISO/IEC 42006 (requirements for certification bodies).

Written by Mehmet Erkek · Last updated: