What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the world's first AI Management System (AIMS) standard. It gives any organization that builds, provides, or uses AI a structured, risk-based way to govern it responsibly — balancing innovation with accountability, transparency and safety. It runs on the Plan-Do-Check-Act cycle and is certifiable by an accredited body.
The requirement clauses (4–10)
Clauses 1–3 are scope, references and terms. Clauses 4–10 are the auditable requirements — what your management system must actually do.
Clause 4Context of the organizationUnderstand your world, your AI, and your role in it.+
Before you can govern AI, you must understand the environment you operate in — the issues that affect you, the parties who care, and exactly which AI is in scope.
- 4.1Understanding the organization and its context. Ground the AIMS in reality — the internal and external factors that shape whether it can succeed.
- 4.2Needs and expectations of interested parties. Know everyone affected by your AI and what they require.
- 4.3Determining the scope of the AIMS. Draw a clear, defensible boundary around what the AIMS covers.
- 4.4AI management system. Build the governance system around the AI — not the AI itself.
Clause 5LeadershipTop management owns responsible AI — and proves it.+
An AIMS lives or dies on leadership. Executives must set the policy, assign authority, and visibly commit resources and culture to responsible AI.
- 5.1Leadership and commitment. Make responsible AI a leadership priority, not a side project.
- 5.2AI policy. Publish the organization's principles for developing and using AI.
- 5.3Roles, responsibilities and authorities. Everyone knows their AI responsibilities and who can act.
Clause 6PlanningTurn risks, impacts, and objectives into a concrete plan.+
Planning is where AIMS becomes rigorous: risk criteria, AI risk assessment and treatment, AI system impact assessment, measurable objectives, and controlled change.
- 6.1.1Actions to address risks and opportunities — general. Set the risk foundation and the actions that protect outcomes.
- 6.1.2AI risk assessment. A repeatable process to find and size AI risks.
- 6.1.3AI risk treatment. Decide and document how each risk is handled.
- 6.1.4AI system impact assessment. Understand how the AI could affect individuals, groups, and society.
- 6.2AI objectives and planning to achieve them. Set measurable objectives and a plan to reach them.
- 6.3Planning of changes. Change the AIMS deliberately, not accidentally.
Clause 7SupportResource it, staff it, communicate it, document it.+
Support is the machinery that keeps the AIMS running: resources, competence, awareness, communication, and controlled documented information.
- 7.1Resources. Provide what the AIMS needs to run its PDCA.
- 7.2Competence. Make sure the people doing AI work are competent.
- 7.3Awareness. Everyone understands the policy and their part in it.
- 7.4Communication. Plan internal and external AIMS communication.
- 7.5Documented information. Control the AIMS's documents and records.
Clause 8OperationRun the controls, keep risk & impact current.+
Operation is doing the AIMS day to day: operational controls across the AI lifecycle, and re-running risk and impact assessments as things change.
- 8.1Operational planning and control. Execute and control the processes and controls you planned.
- 8.2AI risk assessment (operational). Keep the risk picture current.
- 8.3AI risk treatment (operational). Implement treatments and verify they work.
- 8.4AI system impact assessment (operational). Keep impact understanding current.
Clause 9Performance evaluationMeasure it, audit it, review it.+
Performance evaluation checks whether the AIMS actually works: monitoring and measurement, internal audit, and management review.
- 9.1Monitoring, measurement, analysis and evaluation. Know whether the AIMS and the AI are performing.
- 9.2Internal audit. Independently check the AIMS against itself and the standard.
- 9.3Management review. Leadership formally reviews the AIMS and decides.
Clause 10ImprovementFix root causes; get better continually.+
Improvement closes the loop: continual improvement plus disciplined nonconformity and corrective action.
- 10.1Continual improvement. Keep making the AIMS more suitable, adequate and effective.
- 10.2Nonconformity and corrective action. React to problems and stop them recurring.
Annex A control domains
Annex A provides a reference set of 38 controls across 9 domains. You select the ones relevant to your risks in a Statement of Applicability — not every control is mandatory, but every one must be considered.
Policies related to AI
Provide management direction and support for AI in line with business requirements.
Internal organization
Establish accountability for the responsible implementation, operation and management of AI.
Resources for AI systems
Account for the resources (data, tooling, compute, human, system) needed to understand and address AI risks and impacts.
Assessing impacts of AI systems
Assess AI impacts on individuals, groups, and societies throughout the life cycle.
AI system life cycle
Define and apply responsible objectives, processes and criteria across the AI system life cycle.
Data for AI systems
Understand and manage the role and impact of data across the AI life cycle.
Information for interested parties
Ensure interested parties have the information needed to understand and assess AI risks and impacts.
Use of AI systems
Use AI systems responsibly and in accordance with organizational policies.
Third-party and customer relationships
Understand responsibilities and apportion risks when third parties are involved, while remaining accountable.
See where you stand against all of this.
The free readiness assessment scores you against every clause and control.