ISO/IEC 42001

framework · governance and compliance · regulatory-standard

International standard specifying requirements for an AI management system (AIMS), published 2023.

ISO/IEC 42001:2023 (Information technology — Artificial intelligence — Management system) is the first international standard establishing a management-system framework specifically for organizations that develop, provide, or use AI products and services, published by ISO and IEC December 18, 2023 through Joint Technical Committee 1 Sub-committee 42 (ISO/IEC JTC 1/SC 42, AI). The standard is modeled structurally on ISO/IEC 27001 (information security management) and shares the High-Level Structure (HLS, now Harmonized Structure) common across ISO management-system standards. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system (AIMS), with Annex A providing nine control objectives and 38 specific controls covering policies, internal organization, AI system lifecycle, AI system impact assessment, data management, third-party and customer relationships, and information for stakeholders. ISO/IEC 42001 is certifiable through accredited certification bodies, providing organizations a third-party attestation framework parallel to ISO 27001 and ISO 9001 certification.

Originators

ISO/IEC JTC 1/SC 42 (Joint Technical Committee 1, Subcommittee 42 on Artificial Intelligence, established 2017); Working Group 1 (Foundational standards) leadership; intellectual antecedents in ISO/IEC 27001 (information security management, the structural model), ISO 9001 (quality management, the original management-system standard), and ISO/IEC 38507:2022 (Governance of implications for organizations of using AI); national-body input including BSI (UK), DIN (Germany), ANSI (US), JISC (Japan), SAC (China), substantial international participation high

Year / Decade

2017 (SC 42 established); 2021 (working draft); December 2023 (publication) high

Primary sources

ISO/IEC (2023). ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system, ISO/IEC (2022). ISO/IEC 38507:2022 Governance of implications for organizations of using AI, ISO/IEC (2023). ISO/IEC 23894:2023 Information technology — Artificial intelligence — Guidance on risk management, ISO/IEC JTC 1/SC 42 (ongoing). Standards portfolio documentation high

Core components

Primary use case

AI management system framework for organizations developing, providing, or deploying AI; third-party certification target for organizations seeking demonstrable AI governance attestation, particularly relevant for: technology vendors, financial-services firms, healthcare organizations, public-sector AI deployers, regulated-industry AI providers; compliance-mapping reference for organizations subject to AI regulation (EU AI Act, NIST AI RMF) seeking operationalization framework; integration framework for organizations with existing ISO management-system certifications (27001, 9001, 14001, 45001) extending to AI-specific governance; academic and professional reference in AI governance, responsible AI, and management-system literature; early-adopter implementation through Microsoft, Tinkov, and other technology providers, with growing adoption through 2024-2025.

Common criticisms

Lineage

Siblings
NIST AI Risk Management Framework, EU AI Act, OECD AI Principles, ISO 9001