Reference guide

ISO/IEC 42001

The international standard for AI Management Systems — clearly explained, logically structured and usable for organisations that want to develop, procure or deploy AI responsibly.

What's not included: the ISO/IEC 42001 standard itself

This package contains implementation templates and tools only. The ISO/IEC 42001 standard is copyrighted by ISO/IEC and must be purchased separately under licence from ISO or your national standards body (in Belgium: NBN). Our documents reference the standard by clause and Annex A control number only — they do not reproduce its text.

What this standard does

ISO/IEC 42001, published in December 2023, is the world's first international standard for an AI Management System (AIMS). It helps organisations design, deploy and maintain AI systems in a responsible, transparent and controllable way — similar to how ISO 27001 does for information security. It does not tell you which algorithm to choose; it provides the structural scaffolding that separates organisations serious about AI governance from those merely performing it.

The goal is straightforward:

  • Manage risks and impact of AI systems on individuals and society.
  • Ensure responsible, transparent and explainable AI use across the organisation.
  • Build trust with clients, regulators and internal stakeholders.
  • Align with regulation such as the EU AI Act and existing management systems.

AI principles

Four core principles to make responsible AI discussable.

Principle

Accountability

Clear responsibilities for AI systems, from governance to operational roles and escalation paths.

Principle

Transparency

Understandable information about the operation, limitations and decisions of AI systems for relevant stakeholders.

Principle

Fairness

Protection against unintended bias, unfair outcomes and discriminatory effects in AI applications.

Principle

Safety & Security

Control of risks of physical, digital and organisational harm throughout the full lifecycle.

Management system clauses

The seven main clauses of the AIMS

ISO/IEC 42001 follows the Harmonized Structure (HLS) shared with ISO 9001 and ISO 27001. These clauses connect context, leadership, planning and operation with monitoring and improvement of AI activities.

Cl. 4

Context of the organization

Determine internal and external issues, interested parties and the scope of the AI Management System (AIMS).

Cl. 5

Leadership

Top management demonstrates commitment, sets the AI policy and assigns roles, responsibilities and authorities.

Cl. 6

Planning

Identify risks and opportunities, assess AI impact and set measurable objectives for responsible AI use.

Cl. 7

Support

Provide resources, competences, awareness, communication and documented information around AI activities.

Cl. 8

Operation

Plan, implement and control operational AI processes, including impact assessments and lifecycle management.

Cl. 9

Performance evaluation

Monitor, measure, analyse and evaluate AIMS performance through internal audits and management reviews.

Cl. 10

Improvement

Manage non-conformities and structurally drive continuous improvement of the AI Management System.

Annex A controls

The controls that make the AIMS concrete.

Annex A provides nine control clusters — roughly 38 individual controls — spanning the full scope of responsible AI management. Where clauses 4–10 prescribe the management-system structure, Annex A prescribes what you must have controls for. Organisations select applicable controls, justify inclusions and exclusions in a Statement of Applicability, and implement them with verifiable evidence.

AI Policies

  • AI policy
  • Alignment with the organisation
  • Periodic review

Internal Organization

  • Roles & responsibilities
  • AI governance
  • Reporting of concerns

Resources for AI

  • Data resources
  • Tools & compute
  • Human expertise

Impact Assessment

  • AI system impact
  • Effects on individuals
  • Effects on society

AI System Lifecycle

  • Design & development
  • Verification & validation
  • Deployment & maintenance

Data for AI Systems

  • Data quality
  • Data provenance
  • Data preparation

Information for Interested Parties

  • Documentation for users
  • Incident communication
  • Transparency

Use of AI Systems

  • Responsible use
  • Intended use
  • Management of third-party AI

The central document

The Statement of Applicability — your AIMS in one sheet

The SoA is the central accountability document of the AIMS and the most forensically examined document in an ISO/IEC 42001 audit. It lists all 38 Annex A controls (A.2.2–A.10.4). For each control it records whether it is included or excluded, the justification, the implementation evidence, the owner, and which risks it mitigates. A well-constructed SoA signals maturity; a poor one reveals gaps before the first audit interview. In the toolkit it lives as a dedicated tab in the AI Risk & Control Register, so risk assessment, impact assessment and control selection stay connected in one place.

Risk & impact

The twin engines: risk assessment and impact assessment

Most organisations know risk assessment. Fewer understand why ISO/IEC 42001 adds a parallel, legally distinct instrument — the AI impact assessment. Together they drive control selection.

Risk assessment — what could go wrong

For each in-scope system: governance, legal/regulatory, privacy, data quality & bias, technical & security, operational/human, and ethical/societal risk. Scored against defined criteria; high/critical residual risks need formal top-management acceptance.

Impact assessment — who gets harmed

Where risk asks what could go wrong for the organisation, impact asks who gets harmed and how — effects on individuals, groups and society, including indirect, long-term or disproportionate effects. A new AI system always triggers one.

The AI system lifecycle

Governance at every stage — concept to decommissioning

Annex A.6 is the most operationally intensive part of the standard: nine lifecycle stages, each with a gate, evidence and an accountable owner. No system deploys without an assigned AI Owner and a register entry.

  1. 1Concept & intake
  2. 2Requirements
  3. 3Design & architecture
  4. 4Development / configuration
  5. 5Verification & validation
  6. 6Deployment
  7. 7Operation & monitoring
  8. 8Change & retraining
  9. 9Decommissioning

Governance rhythm

A working AIMS has a defined cadence

Governance that operates only when something goes wrong is incident response dressed up as policy. A real AIMS runs on a rhythm:

  • AI policy reviewAt least annually
  • Risk & impact assessmentsAt planned intervals and after significant change
  • AI system register reviewQuarterly
  • Internal auditAt least annually
  • Management reviewAt least annually

Prohibited & restricted use

A policy must also say what you will not do

Reflecting the EU AI Act, ISO/IEC 42001 requires organisations to define prohibited and restricted AI uses explicitly — legally prohibited uses, fully automated decisions with significant individual effects, AI for deception or unlawful surveillance, and high-impact applications affecting rights, safety or vulnerable persons. A published prohibited-use list is organisational protection: it sets the standard against which conduct is measured and shows regulators you considered AI harms before they occurred.

AI actors

The standard becomes concrete per type of AI actor.

Each role in the AI chain has its own responsibilities. The guide makes visible where you need to record policy, controls and evidence — depending on your position.

AI Providers

  • Model development
  • Documentation & datasheets
  • Conformity statements

AI Developers

  • Engineering practices
  • Bias & robustness testing
  • Model versioning

AI Deployers

  • Operational controls
  • Monitoring in production
  • User instructions

AI Users & Subjects

  • Awareness & training
  • Feedback channels
  • Protection of rights

Core principles

Principles that keep ISO/IEC 42001 practical in your organisation.

Risk-based approach

Measures are proportional to AI risk, with explicit impact and risk assessments.

Human oversight

Humans stay in control of critical AI decisions and can intervene or correct where needed.

Lifecycle management

Manage AI systems from concept and data through deployment, monitoring and decommissioning.

Continuous improvement

Lessons learned, audits and monitoring feed structural improvements to policy and controls.

New

AI Assistant Skill — implement the kit with AI, by the book

An installable skill for AI assistants (such as Claude). It keeps your implementation on-plan: it follows the kit's step sequence, uses the correct template for each step, completes the document-control details, completes the Statement of Applicability across all 38 Annex A controls, and — importantly — never fabricates audit evidence. It includes a self-check that flags unfilled placeholders, an incomplete SoA and broken cross-references, and it references ISO/IEC 42001 by clause and control number only (never the standard's text).

From templates to certification

Stage 1 documents your system. Stage 2 proves it operates.

The package documents your AI Management System (Stage 1 readiness). Certification Stage 2 also requires evidence that the system operates — completed risk assessment, internal audit and management review. The Master Manual explains exactly what Stage 1 and Stage 2 expect, so you know what to do after the templates are filled.

Go deeper

Related reading

From guide to evidence

Make ISO/IEC 42001 directly applicable with templates.

Use the package to capture AI policy, procedures, risk and impact assessments, lifecycle and self-assessments in documents your team can use straight away. Includes an EU AI Act mapping so you can connect ISO/IEC 42001 work to EU AI Act obligations.