ISO/IEC 42001
The international standard for AI Management Systems — clearly explained, logically structured and usable for organisations that want to develop, procure or deploy AI responsibly.
What's not included: the ISO/IEC 42001 standard itself
This package contains implementation templates and tools only. The ISO/IEC 42001 standard is copyrighted by ISO/IEC and must be purchased separately under licence from ISO or your national standards body (in Belgium: NBN). Our documents reference the standard by clause and Annex A control number only — they do not reproduce its text.
What this standard does
ISO/IEC 42001, published in December 2023, is the world's first international standard for an AI Management System (AIMS). It helps organisations design, deploy and maintain AI systems in a responsible, transparent and controllable way — similar to how ISO 27001 does for information security. It does not tell you which algorithm to choose; it provides the structural scaffolding that separates organisations serious about AI governance from those merely performing it.
The goal is straightforward:
- Manage risks and impact of AI systems on individuals and society.
- Ensure responsible, transparent and explainable AI use across the organisation.
- Build trust with clients, regulators and internal stakeholders.
- Align with regulation such as the EU AI Act and existing management systems.
AI principles
Four core principles to make responsible AI discussable.
Accountability
Clear responsibilities for AI systems, from governance to operational roles and escalation paths.
Transparency
Understandable information about the operation, limitations and decisions of AI systems for relevant stakeholders.
Fairness
Protection against unintended bias, unfair outcomes and discriminatory effects in AI applications.
Safety & Security
Control of risks of physical, digital and organisational harm throughout the full lifecycle.
Management system clauses
The seven main clauses of the AIMS
ISO/IEC 42001 follows the Harmonized Structure (HLS) shared with ISO 9001 and ISO 27001. These clauses connect context, leadership, planning and operation with monitoring and improvement of AI activities.
Context of the organization
Determine internal and external issues, interested parties and the scope of the AI Management System (AIMS).
Leadership
Top management demonstrates commitment, sets the AI policy and assigns roles, responsibilities and authorities.
Planning
Identify risks and opportunities, assess AI impact and set measurable objectives for responsible AI use.
Support
Provide resources, competences, awareness, communication and documented information around AI activities.
Operation
Plan, implement and control operational AI processes, including impact assessments and lifecycle management.
Performance evaluation
Monitor, measure, analyse and evaluate AIMS performance through internal audits and management reviews.
Improvement
Manage non-conformities and structurally drive continuous improvement of the AI Management System.
Annex A controls
The controls that make the AIMS concrete.
Annex A provides nine control clusters — roughly 38 individual controls — spanning the full scope of responsible AI management. Where clauses 4–10 prescribe the management-system structure, Annex A prescribes what you must have controls for. Organisations select applicable controls, justify inclusions and exclusions in a Statement of Applicability, and implement them with verifiable evidence.
AI Policies
- AI policy
- Alignment with the organisation
- Periodic review
Internal Organization
- Roles & responsibilities
- AI governance
- Reporting of concerns
Resources for AI
- Data resources
- Tools & compute
- Human expertise
Impact Assessment
- AI system impact
- Effects on individuals
- Effects on society
AI System Lifecycle
- Design & development
- Verification & validation
- Deployment & maintenance
Data for AI Systems
- Data quality
- Data provenance
- Data preparation
Information for Interested Parties
- Documentation for users
- Incident communication
- Transparency
Use of AI Systems
- Responsible use
- Intended use
- Management of third-party AI
The central document
The Statement of Applicability — your AIMS in one sheet
The SoA is the central accountability document of the AIMS and the most forensically examined document in an ISO/IEC 42001 audit. It lists all 38 Annex A controls (A.2.2–A.10.4). For each control it records whether it is included or excluded, the justification, the implementation evidence, the owner, and which risks it mitigates. A well-constructed SoA signals maturity; a poor one reveals gaps before the first audit interview. In the toolkit it lives as a dedicated tab in the AI Risk & Control Register, so risk assessment, impact assessment and control selection stay connected in one place.
Risk & impact
The twin engines: risk assessment and impact assessment
Most organisations know risk assessment. Fewer understand why ISO/IEC 42001 adds a parallel, legally distinct instrument — the AI impact assessment. Together they drive control selection.
Risk assessment — what could go wrong
For each in-scope system: governance, legal/regulatory, privacy, data quality & bias, technical & security, operational/human, and ethical/societal risk. Scored against defined criteria; high/critical residual risks need formal top-management acceptance.
Impact assessment — who gets harmed
Where risk asks what could go wrong for the organisation, impact asks who gets harmed and how — effects on individuals, groups and society, including indirect, long-term or disproportionate effects. A new AI system always triggers one.
The AI system lifecycle
Governance at every stage — concept to decommissioning
Annex A.6 is the most operationally intensive part of the standard: nine lifecycle stages, each with a gate, evidence and an accountable owner. No system deploys without an assigned AI Owner and a register entry.
- 1Concept & intake
- 2Requirements
- 3Design & architecture
- 4Development / configuration
- 5Verification & validation
- 6Deployment
- 7Operation & monitoring
- 8Change & retraining
- 9Decommissioning
Governance rhythm
A working AIMS has a defined cadence
Governance that operates only when something goes wrong is incident response dressed up as policy. A real AIMS runs on a rhythm:
- AI policy reviewAt least annually
- Risk & impact assessmentsAt planned intervals and after significant change
- AI system register reviewQuarterly
- Internal auditAt least annually
- Management reviewAt least annually
Prohibited & restricted use
A policy must also say what you will not do
Reflecting the EU AI Act, ISO/IEC 42001 requires organisations to define prohibited and restricted AI uses explicitly — legally prohibited uses, fully automated decisions with significant individual effects, AI for deception or unlawful surveillance, and high-impact applications affecting rights, safety or vulnerable persons. A published prohibited-use list is organisational protection: it sets the standard against which conduct is measured and shows regulators you considered AI harms before they occurred.
AI actors
The standard becomes concrete per type of AI actor.
Each role in the AI chain has its own responsibilities. The guide makes visible where you need to record policy, controls and evidence — depending on your position.
AI Providers
- Model development
- Documentation & datasheets
- Conformity statements
AI Developers
- Engineering practices
- Bias & robustness testing
- Model versioning
AI Deployers
- Operational controls
- Monitoring in production
- User instructions
AI Users & Subjects
- Awareness & training
- Feedback channels
- Protection of rights
Core principles
Principles that keep ISO/IEC 42001 practical in your organisation.
Risk-based approach
Measures are proportional to AI risk, with explicit impact and risk assessments.
Human oversight
Humans stay in control of critical AI decisions and can intervene or correct where needed.
Lifecycle management
Manage AI systems from concept and data through deployment, monitoring and decommissioning.
Continuous improvement
Lessons learned, audits and monitoring feed structural improvements to policy and controls.
AI Assistant Skill — implement the kit with AI, by the book
An installable skill for AI assistants (such as Claude). It keeps your implementation on-plan: it follows the kit's step sequence, uses the correct template for each step, completes the document-control details, completes the Statement of Applicability across all 38 Annex A controls, and — importantly — never fabricates audit evidence. It includes a self-check that flags unfilled placeholders, an incomplete SoA and broken cross-references, and it references ISO/IEC 42001 by clause and control number only (never the standard's text).
From templates to certification
Stage 1 documents your system. Stage 2 proves it operates.
The package documents your AI Management System (Stage 1 readiness). Certification Stage 2 also requires evidence that the system operates — completed risk assessment, internal audit and management review. The Master Manual explains exactly what Stage 1 and Stage 2 expect, so you know what to do after the templates are filled.
From guide to evidence
Make ISO/IEC 42001 directly applicable with templates.
Use the package to capture AI policy, procedures, risk and impact assessments, lifecycle and self-assessments in documents your team can use straight away. Includes an EU AI Act mapping so you can connect ISO/IEC 42001 work to EU AI Act obligations.