AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Frameworks: NIST AI RMF and ISO/IEC 42001 · Lesson 9 of 17
ISO/IEC 42001: running an AI management system
Video lecture
ISO/IEC 42001: running an AI management system
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 ISO/IEC 42001
NIST gives you a way of thinking about AI risk. ISO slash IEC forty-two thousand and one gives you a way of running it, week after week, in a form an auditor can certify. For enterprise and public-sector buyers, a certificate or at least clear alignment is becoming a real differentiator. In this lesson, you'll learn what an AI management system is, the clause structure, how Annex A controls and the Statement of Applicability work, and whether a small business should certify.
0:36 Why a management system
Why does a management system matter when you already have policies? Because policies describe intentions, and management systems make them happen repeatedly: someone owns them, they're reviewed on schedule, problems are tracked and fixed, and improvements are recorded. For buyers, especially governments and large enterprises in the Gulf and Europe, a certificate or credible alignment with forty-two thousand and one is increasingly a shortcut for trust in tenders.
1:06 What it is
ISO slash IEC forty-two thousand and one, published in December twenty twenty-three, is the first international management system standard for AI. Think of it as the AI sibling of ISO twenty-seven thousand and one for information security. It sets requirements for establishing, running, and continually improving an AI management system. It applies to anyone who provides, develops or uses AI, of any size. And unlike NIST, you can be certified against it by accredited bodies. It doesn't decide which AI is acceptable. It makes sure you have a reliable system for deciding.
1:46 Analogy: a kitchen with inspections
An analogy: if the NIST framework is a checklist, ISO forty-two thousand and one is the operating rhythm of a well-run kitchen with regular inspections. There's a written policy, named roles, a routine for assessing risks, training records, procedures people follow, regular internal checks, a management meeting that reviews how things are going, and a habit of fixing problems at the root. An auditor doesn't just read the manual. They watch the kitchen work and check the records match reality.
2:21 The family
It sits in a family. Twenty-two nine eight nine defines AI concepts and terms. Twenty-three eight nine four gives guidance on AI risk management. Forty-two thousand and five, published in twenty twenty-five, guides AI system impact assessments. And forty-two thousand and six, also twenty twenty-five, sets requirements for the bodies that audit and certify AI management systems. Separately, European standards bodies are writing harmonized standards for the EU AI Act. Forty-two thousand and one isn't one of those, but it builds much of the organizational muscle you'll need.
2:59 Clauses 4 to 10
The standard follows the common structure of ISO management systems, clauses four to ten. Context: understand your situation, stakeholders, scope and AI roles. Leadership: top management commitment, an AI policy, and clear roles. Planning: AI risk assessment, risk treatment, AI system impact assessment and objectives. Support: resources, competence, awareness and document control. Operation: actually running the processes. Performance evaluation: monitoring, internal audit and management review. And improvement: fixing nonconformities and getting better.
3:30 Annex A and the SoA
Annex A is where the controls live, grouped into themes: AI policies, internal organization, resources, impact assessment, the AI system life cycle, data for AI, information for interested parties, use of AI, and third-party and customer relationships. You choose which controls apply based on your risk assessment, and record your choices and justifications in a Statement of Applicability. That's what makes the system proportionate. A fifteen-person agency and a bank will have very different statements.
4:03 Worked example: Karachi agency scope
Here's a scope statement for a forty-person digital agency in Karachi with UK clients. The AI management system covers using third-party generative AI tools and building AI automations for clients, for teams in Karachi and remote, serving clients in Pakistan, the UAE and the UK. It names their roles: deployer of third-party tools, and provider of client-specific chatbots and workflows. It states what's out of scope, and lists the interested parties: clients, end users, staff, vendors, regulators and the certification body. A tight, honest scope makes everything else easier.
4:42 Certify or align?
Should a small business certify? Certify if enterprise or public-sector clients ask for it, if you sell AI products or AI-heavy services, or if you already hold twenty-seven thousand and one and can integrate. Align without certifying if you mainly need internal discipline or your budget is tight. Alignment still gives most of the benefit, and you can certify later. If you already run an information security management system, reuse its document control, audits, management review and supplier management, and add the AI-specific pieces.
5:19 Example 2: Abu Dhabi consultancy
A simple example. A twelve-person consultancy in Abu Dhabi uses AI lightly: a chat assistant, transcription and an image tool. No client has asked for certification. So they align rather than certify: a one-page scope, a signed AI policy, a short risk register, a Statement of Applicability with most Annex A controls marked applicable at a light level, a yearly internal review and a management meeting twice a year. Total effort: a few days. If a government client later asks for certification, they're already most of the way there.
5:58 Common mistakes
Three mistakes. Writing policies that describe an ideal organization rather than the real one. Auditors test what you actually do, and gaps become nonconformities. Ignoring the impact assessment requirement, when ISO forty-two thousand and one expects AI system impact assessments, and forty-two thousand and five shows how to do them. And treating certification as the finish line. Surveillance audits check continual improvement, so the system has to keep running.
6:28 Watch me do it: Statement of Applicability
Watch me do it. I open a new tab called Statement of Applicability. Columns: Control theme, Control summary, Applicable, Justification, Implementation link, Owner. First row: policies related to AI. Applicable: yes. Justification: required baseline. Implementation: link to our signed AI policy. Owner: CEO. Internal organization: yes, several teams use AI, link to the RACI. Resources for AI systems: yes, link to the register itself. Assessing impacts: yes, because client chatbots affect end users, link to the impact assessment template. AI system life cycle: yes, we build automations for clients. Data for AI systems: yes, client data feeds chatbots. Information for interested parties: yes, link to the disclosure procedure. Use of AI systems: yes, everyone uses generative AI. Third-party relationships: yes, heavy vendor reliance, link to the due diligence tab. Now the key part: the scope statement above the table. I write one paragraph naming our offices, our roles as deployer and provider of client automations, what's out of scope, and who the interested parties are. That paragraph plus this table is the backbone of an aligned management system.
7:45 Recap and next step
Recap. ISO slash IEC forty-two thousand and one is a certifiable management system for AI, built on clauses four to ten, with Annex A controls selected through a Statement of Applicability. It fits alongside NIST and the EU AI Act. Watch for two traps: policies describing an imaginary company, and treating certification as the finish line. Your next step: write a one-paragraph scope statement for your organization, then fill in the Statement of Applicability starter from the lesson text.
What ISO/IEC 42001 is
ISO/IEC 42001:2023, published in December 2023, is the first international management system standard for AI. Like ISO/IEC 27001 for information security, it specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS). Unlike NIST, organizations can be certified against it by accredited certification bodies.
It applies to any organization that provides, develops or uses AI, of any size. It does not tell you which AI is acceptable; it makes sure you have a system for deciding, controlling and improving.
The family of related standards
| Standard | What it does |
|---|---|
| ISO/IEC 22989:2022 | AI concepts and terminology |
| ISO/IEC 23894:2023 | Guidance on AI risk management (builds on ISO 31000) |
| ISO/IEC 42001:2023 | AI management system requirements (certifiable) |
| ISO/IEC 42005:2025 | Guidance on AI system impact assessment |
| ISO/IEC 42006:2025 | Requirements for bodies that audit and certify AIMS |
Separately, European standardization bodies (CEN-CENELEC JTC 21) are developing harmonized standards for the EU AI Act. Following them will give a presumption of conformity for high-risk requirements once published and cited. ISO/IEC 42001 is not itself a harmonized standard for the AI Act, but it builds much of the organizational muscle you need.
The structure: clauses 4 to 10
42001 uses the common "harmonized structure" shared by ISO management system standards:
| Clause | Requirement | Practical artifact |
|---|---|---|
| 4 Context | Understand internal/external issues, interested parties, scope of the AIMS, your AI roles | Scope statement, stakeholder register |
| 5 Leadership | Top management commitment, AI policy, roles and responsibilities | Signed AI policy, RACI |
| 6 Planning | AI risk assessment, risk treatment, AI system impact assessment, objectives | Risk register, Statement of Applicability, impact assessments |
| 7 Support | Resources, competence, awareness, communication, documented information | Training records, document control |
| 8 Operation | Run the planned processes, risk treatments and impact assessments | Operating procedures, change records |
| 9 Performance evaluation | Monitoring, measurement, internal audit, management review | KPI dashboard, audit reports, review minutes |
| 10 Improvement | Nonconformity, corrective action, continual improvement | Corrective action log |
Annex A controls
Annex A lists reference control objectives and controls grouped into themes: policies related to AI; internal organization; resources for AI systems; assessing impacts of AI systems; AI system life cycle; data for AI systems; information for interested parties; use of AI systems; and third-party and customer relationships. Annex B gives implementation guidance, Annex C lists potential AI-related objectives and risk sources, and Annex D covers use across domains and sectors.
You choose which Annex A controls apply based on your risk assessment and record the decision, with justifications for inclusions and exclusions, in a Statement of Applicability (SoA). This is the heart of a proportionate AIMS: a 15-person agency and a bank will have very different SoAs.
Should an SME certify?
| Certify if... | Align without certifying if... |
|---|---|
| Enterprise or public-sector clients ask for it in tenders | You mainly need internal discipline |
| You provide AI products or AI-heavy services | You are a light AI user |
| You already hold ISO/IEC 27001 and can integrate | Budget and staff time are tight |
Alignment without certification still gives you most of the benefit. Many organizations start aligned and certify later.
Integrating with ISO/IEC 27001 and ISO/IEC 27701
If you already run an information security management system, reuse its machinery: document control, internal audit, management review, corrective action, supplier management. Add AI-specific pieces: AI policy, AI risk and impact assessments, AI lifecycle controls, data quality for AI, and transparency to interested parties. Privacy information management (27701) links naturally to AI data handling.
Worked example: an AIMS scope for a 40-person digital agency in Karachi with UK clients
AIMS scope statement (v1.0)
The AI management system covers the use of third-party generative AI tools and the
development of AI-enabled marketing automations delivered to clients, performed by
the Karachi and remote teams, for clients in Pakistan, the UAE and the United Kingdom.
Roles: deployer of third-party AI systems; provider of client-specific AI automations
(chatbots, content workflows) placed into service under client or agency names.
Out of scope: training of foundation models; internal HR analytics (no AI used).
Interested parties: clients, end users of client chatbots, staff, AI vendors,
regulators (PDPL-equivalent guidance in PK, UAE PDPL, UK ICO), certification body.Hands-on: Statement of Applicability starter
control_theme,control_summary,applicable,justification,implementation,owner
Policies related to AI,AI policy approved by top management,yes,Required baseline,/gov/policy/ai-policy-v2.pdf,CEO
Internal organization,Roles and responsibilities for AI defined,yes,Multiple teams use AI,/gov/raci.xlsx,COO
Resources for AI systems,Inventory of data/tools/compute for AI systems,yes,Inventory needed for control,/gov/inventory.xlsx,AI lead
Assessing impacts,AI system impact assessment process,yes,Client chatbots affect end users,/gov/templates/aiia.docx,AI lead
AI system life cycle,Documented design/test/deploy/retire steps,yes,We build automations,/gov/sop/lifecycle.md,Tech lead
Data for AI systems,Data quality and provenance for AI,yes,Client data feeds chatbots,/gov/sop/data.md,Tech lead
Information for interested parties,User-facing AI information and disclosures,yes,Art. 50 and client needs,/gov/sop/disclosure.md,Head of content
Use of AI systems,Rules for responsible use of AI,yes,All staff use GenAI,/gov/policy/aup.pdf,AI lead
Third-party relationships,Supplier and customer AI responsibilities,yes,Heavy vendor reliance,/gov/vendors/,ProcurementMeasuring success
Internal audit finds the AIMS operating as documented; management review happens on schedule with decisions recorded; corrective actions close on time; and the SoA changes when your AI use changes.
Pitfalls
- Writing policies that describe an ideal organization rather than the real one. Auditors test what you do.
- Ignoring the impact assessment requirement; 42001 expects AI system impact assessments, and ISO/IEC 42005 shows how.
- Treating certification as the finish line. Surveillance audits test continual improvement.
Key takeaways
- ISO/IEC 42001:2023 is a certifiable AI management system standard for any organization that provides, develops or uses AI.
- It follows clauses 4 to 10 (context to improvement) and uses Annex A controls selected via a Statement of Applicability.
- Related standards: ISO/IEC 22989, 23894, 42005 (impact assessment) and 42006 (certification bodies).
- Certify when buyers require it or you sell AI; otherwise align first and reuse ISO 27001 machinery.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Write a one-paragraph AIMS scope statement for your organization, then complete the Statement of Applicability starter with owners and evidence links.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.