AI Policy Wiki
Dashboard

ISO/IEC 42001 — AI Management System

high confidence · updated 2026-06-06

International standard for establishing, implementing, maintaining, and continually improving an AI management system within an organization. Published 2023.

ISO/IEC 42001 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organization that provides or uses AI-based products or services. It was published in December 2023 by ISO/IEC Joint Technical Committee 1, SC 42 (Artificial intelligence), and is the first international AI-specific management system standard against which organizations can be certified.

PublishedDecember 2023
PublisherISO/IEC Joint Technical Committee 1, SC 42 (Artificial intelligence)
TypeInternational management system standard (certifiable)

Scope

The standard specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within organizations that provide or use AI-based products or services. It is modeled on the ISO management-system family (ISO 9001, ISO 27001, ISO 14001) and follows the same Plan-Do-Check-Act structure.

Structure

Mandatory clauses (4–10)

ISO/IEC 42001 uses the standard Annex SL management-system structure across clauses 4 through 10:

  • Clause 4 — Context of the organization
  • Clause 5 — Leadership (AI policy, roles, responsibilities)
  • Clause 6 — Planning (AI risk assessment, AI impact assessment, AI objectives)
  • Clause 7 — Support (resources, competence, awareness, documentation)
  • Clause 8 — Operation (AI life cycle, data management, third-party documentation)
  • Clause 9 — Performance evaluation (monitoring, internal audit, management review)
  • Clause 10 — Improvement (nonconformities, corrective actions, continual improvement)

Annex A — control objectives and controls

Annex A defines 39 controls grouped as follows:

  • A.2–A.3 — AI policies, internal organization
  • A.4 — Resources (data, tooling, system, human)
  • A.5 — Impact assessment
  • A.6 — AI life cycle (requirements, design, V&V, deployment, operation, monitoring)
  • A.7 — Data management (acquisition, quality, provenance, preparation)
  • A.8 — Information for interested parties (users, regulators, third parties)
  • A.9 — Use of AI (responsible use, human oversight)
  • A.10 — Third parties and customers

Annex B — implementation guidance

Annex B provides guidance notes for each Annex A control. Key subsections are:

  • B.4 — Resource documentation (data provenance, labeling, retention, tooling, computing, human resources)
  • B.5 — Impact assessment requirements and process
  • B.6 — AI life cycle documentation (from requirements through operation and monitoring)
  • B.7 — Data management (provenance, quality, preparation methods)
  • B.8 — Third-party and user documentation, incident communication plans
  • B.9 — Responsible-use documentation (human oversight objectives)

Key requirements for compliance

AI policy (5.2). The AI policy must include the organization's purpose, a framework for AI objectives, a commitment to requirements, a commitment to continual improvement, legal requirements, the risk environment, and principles for all AI activities.

AI risk assessment (6.1.2). The risk assessment must align with the AI policy, be consistent and comparable, assess consequences and likelihood, produce risk levels against criteria, and be repeatable.

AI impact assessment (6.1.4). The impact assessment must cover effects on individuals (fairness, accountability, transparency, security, privacy, safety, human rights) and effects on society (environmental sustainability, economic, health, norms/culture/values).

Documentation requirements span the full management system. Organizations must document the AI policy and objectives; AI risk criteria and risk tolerance; the risk assessment process and results; the risk treatment plan and residual risks; the impact assessment process, results, and reporting; AI resource documentation (data, tools, compute, people); AI life cycle documentation (requirements, design, V&V, deployment, operation); technical documentation for each interested-party category; event logs during all AI-use phases; nonconformities and corrective actions; and internal audit and management review results.

Certification

ISO/IEC 42001 is certifiable: organizations can undergo third-party audit and receive ISO 42001 certification. It is the first international AI-specific certifiable management system standard.

Relation to other frameworks

FrameworkComparison to 42001
NIST AI RMF (NIST AI Risk Management Framework (AI RMF 1.0))Voluntary US-only framework; complementary but not certifiable
EU AI Act (EU AI Act (Regulation 2024/1689))Regulatory; 42001 compliance may satisfy some but not all EU AI Act requirements
ISO/IEC 42005 (ISO/IEC 42005 — AI Impact Assessment)Companion standard specifically for AI impact assessment process
Anthropic RSP (Anthropic's Responsible Scaling Policy (Version 3.1))Lab-specific; 42001 is organization-universal
OpenAI Preparedness (OpenAI Preparedness Framework V.2)Capability-threshold-specific; 42001 is management-system-wide

ISO/IEC 42001 is the first certifiable international AI standard, and it is already cited in Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) and EU AI Act (Regulation 2024/1689) as a compliance-pathway reference. It provides documentation and process requirements for organizations building AI governance programs across regulatory regimes, and the 39-control structure in Annex A is used by AI governance practitioners as a compliance checklist.

FPF's 2026 analysis documents two pathways by which ISO 42001 compliance is moving from voluntary practice into legal obligation. The first is safe-harbor provisions: Texas TRAIGA conditions liability immunity on maintaining an ISO 42001-compliant AI risk management program. The second is judicial standards-of-care: New York courts are adopting ISO 42001's impact assessment and documentation controls as the benchmark for what a reasonable AI deployer does. Per the analysis, organizations that treated ISO 42001 certification as a marketing credential now face it as a threshold for legal protection.

Relationships

Sources