AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Frameworks: NIST AI RMF and ISO/IEC 42001 · Lesson 9 of 17

ISO/IEC 42001: running an AI management system

Article · 16 min · 8 min lecture

Video lecture

ISO/IEC 42001: running an AI management system

13 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 13

ISO/IEC 42001

  • A certifiable AI management system
  • Clauses 4 to 10
  • Annex A controls and the SoA
  • Certify or align?

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

What ISO/IEC 42001 is

ISO/IEC 42001:2023, published in December 2023, is the first international management system standard for AI. Like ISO/IEC 27001 for information security, it specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS). Unlike NIST, organizations can be certified against it by accredited certification bodies.

It applies to any organization that provides, develops or uses AI, of any size. It does not tell you which AI is acceptable; it makes sure you have a system for deciding, controlling and improving.

StandardWhat it does
ISO/IEC 22989:2022AI concepts and terminology
ISO/IEC 23894:2023Guidance on AI risk management (builds on ISO 31000)
ISO/IEC 42001:2023AI management system requirements (certifiable)
ISO/IEC 42005:2025Guidance on AI system impact assessment
ISO/IEC 42006:2025Requirements for bodies that audit and certify AIMS

Separately, European standardization bodies (CEN-CENELEC JTC 21) are developing harmonized standards for the EU AI Act. Following them will give a presumption of conformity for high-risk requirements once published and cited. ISO/IEC 42001 is not itself a harmonized standard for the AI Act, but it builds much of the organizational muscle you need.

The structure: clauses 4 to 10

42001 uses the common "harmonized structure" shared by ISO management system standards:

ClauseRequirementPractical artifact
4 ContextUnderstand internal/external issues, interested parties, scope of the AIMS, your AI rolesScope statement, stakeholder register
5 LeadershipTop management commitment, AI policy, roles and responsibilitiesSigned AI policy, RACI
6 PlanningAI risk assessment, risk treatment, AI system impact assessment, objectivesRisk register, Statement of Applicability, impact assessments
7 SupportResources, competence, awareness, communication, documented informationTraining records, document control
8 OperationRun the planned processes, risk treatments and impact assessmentsOperating procedures, change records
9 Performance evaluationMonitoring, measurement, internal audit, management reviewKPI dashboard, audit reports, review minutes
10 ImprovementNonconformity, corrective action, continual improvementCorrective action log

Annex A controls

Annex A lists reference control objectives and controls grouped into themes: policies related to AI; internal organization; resources for AI systems; assessing impacts of AI systems; AI system life cycle; data for AI systems; information for interested parties; use of AI systems; and third-party and customer relationships. Annex B gives implementation guidance, Annex C lists potential AI-related objectives and risk sources, and Annex D covers use across domains and sectors.

You choose which Annex A controls apply based on your risk assessment and record the decision, with justifications for inclusions and exclusions, in a Statement of Applicability (SoA). This is the heart of a proportionate AIMS: a 15-person agency and a bank will have very different SoAs.

Should an SME certify?

Certify if...Align without certifying if...
Enterprise or public-sector clients ask for it in tendersYou mainly need internal discipline
You provide AI products or AI-heavy servicesYou are a light AI user
You already hold ISO/IEC 27001 and can integrateBudget and staff time are tight

Alignment without certification still gives you most of the benefit. Many organizations start aligned and certify later.

Integrating with ISO/IEC 27001 and ISO/IEC 27701

If you already run an information security management system, reuse its machinery: document control, internal audit, management review, corrective action, supplier management. Add AI-specific pieces: AI policy, AI risk and impact assessments, AI lifecycle controls, data quality for AI, and transparency to interested parties. Privacy information management (27701) links naturally to AI data handling.

Worked example: an AIMS scope for a 40-person digital agency in Karachi with UK clients

AIMS scope statement (v1.0)
The AI management system covers the use of third-party generative AI tools and the
development of AI-enabled marketing automations delivered to clients, performed by
the Karachi and remote teams, for clients in Pakistan, the UAE and the United Kingdom.
Roles: deployer of third-party AI systems; provider of client-specific AI automations
(chatbots, content workflows) placed into service under client or agency names.
Out of scope: training of foundation models; internal HR analytics (no AI used).
Interested parties: clients, end users of client chatbots, staff, AI vendors,
regulators (PDPL-equivalent guidance in PK, UAE PDPL, UK ICO), certification body.

Hands-on: Statement of Applicability starter

control_theme,control_summary,applicable,justification,implementation,owner
Policies related to AI,AI policy approved by top management,yes,Required baseline,/gov/policy/ai-policy-v2.pdf,CEO
Internal organization,Roles and responsibilities for AI defined,yes,Multiple teams use AI,/gov/raci.xlsx,COO
Resources for AI systems,Inventory of data/tools/compute for AI systems,yes,Inventory needed for control,/gov/inventory.xlsx,AI lead
Assessing impacts,AI system impact assessment process,yes,Client chatbots affect end users,/gov/templates/aiia.docx,AI lead
AI system life cycle,Documented design/test/deploy/retire steps,yes,We build automations,/gov/sop/lifecycle.md,Tech lead
Data for AI systems,Data quality and provenance for AI,yes,Client data feeds chatbots,/gov/sop/data.md,Tech lead
Information for interested parties,User-facing AI information and disclosures,yes,Art. 50 and client needs,/gov/sop/disclosure.md,Head of content
Use of AI systems,Rules for responsible use of AI,yes,All staff use GenAI,/gov/policy/aup.pdf,AI lead
Third-party relationships,Supplier and customer AI responsibilities,yes,Heavy vendor reliance,/gov/vendors/,Procurement

Measuring success

Internal audit finds the AIMS operating as documented; management review happens on schedule with decisions recorded; corrective actions close on time; and the SoA changes when your AI use changes.

Pitfalls

  • Writing policies that describe an ideal organization rather than the real one. Auditors test what you do.
  • Ignoring the impact assessment requirement; 42001 expects AI system impact assessments, and ISO/IEC 42005 shows how.
  • Treating certification as the finish line. Surveillance audits test continual improvement.

Key takeaways

  • ISO/IEC 42001:2023 is a certifiable AI management system standard for any organization that provides, develops or uses AI.
  • It follows clauses 4 to 10 (context to improvement) and uses Annex A controls selected via a Statement of Applicability.
  • Related standards: ISO/IEC 22989, 23894, 42005 (impact assessment) and 42006 (certification bodies).
  • Certify when buyers require it or you sell AI; otherwise align first and reuse ISO 27001 machinery.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. What document records which Annex A controls apply and why?
  2. Which standard gives guidance specifically on AI system impact assessment?
  3. A 12-person consultancy uses AI lightly and has no client demand for certification. What is the most proportionate approach?

Put it into practice

Write a one-paragraph AIMS scope statement for your organization, then complete the Statement of Applicability starter with owners and evidence links.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.