ISO 42001 explained: the AI management system from standard to certificate

Compliance10 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

ISO/IEC 42001 is the first international standard for an artificial intelligence management system, published in December 2023. Where ISO 27001 covers information security, 42001 covers whether your organisation controls its AI systems: from the decision to deploy AI through to the moment a model leaves production. The standard is certifiable, which explains the growing demand. Customers and regulators want evidence, not a statement of intent.

What an AI management system is

An AI management system, abbreviated to AIMS in the standard, is the combination of policy, processes, roles and controls through which you manage AI risk. It is not a tool and not a technical product. Structurally it resembles an ISMS under ISO 27001, but the subject matter is specific to AI: the quality and provenance of training data, the impact of automated decisions on people, explainability, and the question of who intervenes when a model does something nobody anticipated.

How the standard is built

The standard follows the common structure shared by all ISO management system standards. Clauses 4 through 10 hold the requirements for the system itself. Annex A holds the controls, grouped into domains. Annex B gives implementation guidance per control, Annex C lists potential AI-related objectives and risk sources, and Annex D describes applying the AIMS across different domains and sectors.

Anyone who knows ISO 27001 will recognise the pattern immediately. That is also why organisations with an existing ISMS get there faster: leadership, competence, internal audit and management review are largely the same processes with different content.

What the clauses require

Clause 4 covers context and scope: which AI systems fall inside the system, which organisational units participate, and in which role you act for each system. Clause 5 requires top management involvement, an AI policy and a clear allocation of roles and authorities.

Clause 6 is the substantive core. You perform an AI risk assessment (6.1.2), treat those risks and produce a Statement of Applicability justifying for each Annex A control whether you apply it (6.1.3). You also assess the impact of your AI systems on individuals and groups, and where relevant on society (6.1.4). On top of that you set objectives (6.2) and carry out changes to the system in a planned way (6.3).

Clause 7 covers the preconditions: resources, competence, awareness, communication and documented information. Clause 8 covers operational planning and control, including changes to models and data. Clause 9 requires monitoring, internal audits and a management review. Clause 10 covers nonconformities, corrective action and continual improvement.

The Annex A domains

Annex A groups the controls into nine domains: policies related to AI (A.2), internal organisation and responsibilities (A.3), resources such as data, tooling, compute and human expertise (A.4), impact assessment of AI systems (A.5), the AI system life cycle (A.6), data for AI systems (A.7), information for interested parties (A.8), responsible use of AI (A.9) and third party and customer relationships (A.10).

You do not apply every control. Which ones apply follows from your risk assessment and your scope, and you record that in the Statement of Applicability. An organisation that only uses supplier AI has a different profile from one that trains its own models.

What sets ISO 42001 apart from ISO 27001

Three things. First, 42001 looks beyond the organisation to the people affected by AI outcomes. An impact assessment concerns consequences for those individuals, not consequences for your business operations. Second, data is an explicit subject: provenance, quality, representativeness and bias in training data are part of the control environment. Third, the standard asks for human oversight that works in practice rather than existing only on paper.

The question of role comes on top of that. The standard distinguishes the provider, developer and user of an AI system. Many organisations are all three depending on the system, and each role carries different obligations.

How certification works

Certification is performed by an accredited certification body, for example DigiTrust (www.digitrust.nl). The engagement runs in two stages: a documentation review followed by an audit of how the system operates in the organisation. Before that audit starts you need to demonstrate at least one completed internal audit and one management review. Certification is followed by annual surveillance audits and a recertification after three years.

Practice shows that most findings have nothing to do with technology. They concern a scope that is too vague, risk assessments not updated after a change, and policy that nobody in the delivery organisation knows.

Relationship with the EU AI Act

An ISO 42001 certificate does not mean you comply with the EU AI Act. The standard is voluntary and the regulation is law, with its own definitions and obligations per risk category. They do overlap in the subjects both address: risk management, technical documentation, logging, human oversight and information for users. An AIMS is therefore a useful foundation rather than a free pass. To see where your organisation stands against the regulation, take the self assessment at /ai-act-check.

Who the standard is for

Organisations that ship AI functionality to customers, organisations using AI in decisions that affect people, and suppliers who increasingly receive AI governance questionnaires during procurement. Even without certification ambitions the standard works as a checklist: it makes visible which subjects you have not yet arranged.

Where to start

With an inventory, not with policy. As long as you do not know which AI is used across the organisation, including the tools departments bought themselves, every scope is an assumption. Scope, risk assessment and a gap analysis against the requirements follow after that. For most organisations this is a matter of months rather than weeks.

Further reading in the knowledge base

Getting practical: the implementation roadmap and taking inventory of shadow AI. On the audit: what we see in certification engagements. On how it relates to other frameworks: the relationship with the EU AI Act, ISO 42001 next to the NIST AI RMF and integrated implementation with ISO 27001. On impact assessment: ISO 42005 and the AI system impact assessment.

To find out what an AIMS means in your situation, see our compliance services or put your question to us.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us