ISO/IEC 42001:2023 / AI governance

ISO 42001 AI Management System

ISO 42001 gives organisations a management system for artificial intelligence. It is useful when AI is moving from experiments into real products, customer workflows, employee tooling, or regulated decision support.

The standard follows the same management-system rhythm as ISO 27001: understand the organisation, get leadership commitment, plan objectives and risks, support the programme, operate controls, evaluate performance, and keep improving.

This guide focuses on practical implementation: what to put in place, what evidence to keep, and how to make ISO 42001 work alongside ISO 27001, SOC 2, privacy, and EU AI Act readiness.

ISO 42001 starter pack

Make AI governance operational, not theoretical.

Use this path when AI tools, models, suppliers, and human review need owners, controls, and audit-ready evidence.

Open Markdown pack ->

Clauses 4 to 10

All requirements

AI Control Areas

All control areas
A.2

AI policies

Set direction for responsible AI use and make policy expectations clear to builders, buyers, operators, and users.

A.3

Internal organization

Assign accountability and decision rights for AI governance across leadership, product, engineering, legal, security, privacy, and operations.

A.4

Resources for AI systems

Ensure the organisation has the people, tools, data, infrastructure, and budget needed to govern AI systems properly.

A.5

AI system impact assessment

Understand who may be affected by an AI system and what harms, benefits, rights impacts, or business impacts may occur.

A.6

AI system lifecycle

Control AI systems from idea and design through data work, model selection, testing, release, operation, change, and retirement.

A.7

Data for AI systems

Govern data used for AI so it is lawful, suitable, representative enough for the purpose, protected, and traceable.

A.8

Information for interested parties

Provide appropriate transparency to users, customers, staff, regulators, auditors, and affected people.

A.9

Use of AI systems

Control how AI systems are used in practice so outputs are reviewed, limitations are understood, and misuse is detected.

A.10

Third-party and customer relationships

Manage AI risks introduced by model providers, SaaS tools, implementation partners, customers, and downstream users.

A.11

Responsible use

Make responsible AI principles operational, including fairness, accountability, transparency, privacy, security, safety, and human agency.

A.12

AI objectives and metrics

Define measurable objectives for AI performance and governance so the AIMS can be evaluated and improved.

How ISO 42001 fits with ISO 27001

ISO 27001 protects information security. ISO 42001 governs AI systems and their organisational impact. A practical programme reuses the ISMS for document control, risk treatment, audit, supplier assurance, access, logging, incidents, and continual improvement, then adds AI-specific inventory, impact assessment, lifecycle, transparency, and human oversight controls.

Map to ISO 27001 controls

Automate evidence collection

The market-leading compliance automation platform.

// Signal, not noise

AI governance, made operational

ISO 42001, EU AI Act, and security-control implementation notes. No spam.