ISO/IEC 42001
International standard specifying requirements for an AI management system (AIMS), published 2023.
ISO/IEC 42001:2023 (Information technology — Artificial intelligence — Management system) is the first international standard establishing a management-system framework specifically for organizations that develop, provide, or use AI products and services, published by ISO and IEC December 18, 2023 through Joint Technical Committee 1 Sub-committee 42 (ISO/IEC JTC 1/SC 42, AI). The standard is modeled structurally on ISO/IEC 27001 (information security management) and shares the High-Level Structure (HLS, now Harmonized Structure) common across ISO management-system standards. It specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system (AIMS), with Annex A providing nine control objectives and 38 specific controls covering policies, internal organization, AI system lifecycle, AI system impact assessment, data management, third-party and customer relationships, and information for stakeholders. ISO/IEC 42001 is certifiable through accredited certification bodies, providing organizations a third-party attestation framework parallel to ISO 27001 and ISO 9001 certification.
Core components
- Plan-Do-Check-Act (PDCA) cycle structure inherited from ISO management-system tradition
- Ten-clause structure following High-Level Structure: scope, normative references, terms and definitions, context of the organization, leadership, planning, support, operation, performance evaluation, improvement
- Annex A controls: nine control objectives covering policies (A.2), internal organization (A.3), resources (A.4), assessing impacts (A.5), AI system lifecycle (A.6), data (A.7), information for stakeholders (A.8), use of AI systems (A.9), third-party and customer relationships (A.10) — 38 specific controls in total
- AI System Impact Assessment: documented evaluation of intended use, potential adverse effects, and mitigations
- Risk-based approach: organization-level identification and treatment of AI-specific risks
- Lifecycle coverage: development, deployment, operation, monitoring, retirement
- Certifiability: third-party certification through accredited bodies, parallel to ISO 27001 and 9001 certification infrastructure
- Integration with broader ISO/IEC AI standards including ISO/IEC 22989 (AI concepts and terminology), 23053 (framework for AI systems using ML), 23894 (AI risk management), 38507 (AI governance for boards), 5259 (data quality for analytics and ML)
Primary use case
AI management system framework for organizations developing, providing, or deploying AI; third-party certification target for organizations seeking demonstrable AI governance attestation, particularly relevant for: technology vendors, financial-services firms, healthcare organizations, public-sector AI deployers, regulated-industry AI providers; compliance-mapping reference for organizations subject to AI regulation (EU AI Act, NIST AI RMF) seeking operationalization framework; integration framework for organizations with existing ISO management-system certifications (27001, 9001, 14001, 45001) extending to AI-specific governance; academic and professional reference in AI governance, responsible AI, and management-system literature; early-adopter implementation through Microsoft, Tinkov, and other technology providers, with growing adoption through 2024-2025.
Common criticisms
- ISO/IEC 42001's relationship to existing AI governance frameworks produces ongoing implementation questions — the standard provides management-system structure but does not specify substantive AI-ethics positions, leaving implementing organizations to source ethical commitments from elsewhere (EU AI Act, NIST AI RMF, OECD AI Principles), with potential gaps where the management system is implemented without rigorous substantive content
- the certifiability of management systems has been criticized across the broader ISO management-system tradition for producing 'paper compliance' where documentation exists but substantive practice is weak (the longstanding ISO 9001 critique extends to ISO 42001 by analogy)
- the 38 Annex A controls are framed at substantial generality, requiring organizations to develop their own implementation specifics, with risk that smaller organizations under-implement or over-document
- the standard's interaction with binding regulation (EU AI Act high-risk obligations, sectoral AI rules) is not formally specified — ISO/IEC 42001 certification does not demonstrate EU AI Act compliance, though substantial overlap exists
- the certification ecosystem's commercial dynamics produce concerns about auditor-organization relationships that have surfaced in other ISO certification regimes
- cross-sector applicability is theoretically broad but practical adaptation to domain-specific contexts (financial-services model risk, medical-device safety, autonomous-vehicle safety) requires substantial supplementation
- the standard's published December 2023 means accumulated implementation experience remains limited as of mid-2026, with certification-body auditor competence still developing
- relationship to the NIST AI RMF (US) is conceptual-not-formal, with organizations sometimes implementing both with substantial duplication
- criticism from civil-society groups that voluntary management-system standards cannot substitute for binding AI regulation.
Lineage
- Siblings
- NIST AI Risk Management Framework, EU AI Act, OECD AI Principles, ISO 9001