DoAIRight
The standard, in plain language

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the world's first AI Management System (AIMS) standard. It gives any organization that builds, provides, or uses AI a structured, risk-based way to govern it responsibly — balancing innovation with accountability, transparency and safety. It runs on the Plan-Do-Check-Act cycle and is certifiable by an accredited body.

Requirement clauses4–10Control domains9Annex A controls38

The requirement clauses (4–10)

Clauses 1–3 are scope, references and terms. Clauses 4–10 are the auditable requirements — what your management system must actually do.

Clause 4Context of the organizationUnderstand your world, your AI, and your role in it.+

Before you can govern AI, you must understand the environment you operate in — the issues that affect you, the parties who care, and exactly which AI is in scope.

  • 4.1Understanding the organization and its context. Ground the AIMS in reality — the internal and external factors that shape whether it can succeed.
  • 4.2Needs and expectations of interested parties. Know everyone affected by your AI and what they require.
  • 4.3Determining the scope of the AIMS. Draw a clear, defensible boundary around what the AIMS covers.
  • 4.4AI management system. Build the governance system around the AI — not the AI itself.
Clause 5LeadershipTop management owns responsible AI — and proves it.+

An AIMS lives or dies on leadership. Executives must set the policy, assign authority, and visibly commit resources and culture to responsible AI.

  • 5.1Leadership and commitment. Make responsible AI a leadership priority, not a side project.
  • 5.2AI policy. Publish the organization's principles for developing and using AI.
  • 5.3Roles, responsibilities and authorities. Everyone knows their AI responsibilities and who can act.
Clause 6PlanningTurn risks, impacts, and objectives into a concrete plan.+

Planning is where AIMS becomes rigorous: risk criteria, AI risk assessment and treatment, AI system impact assessment, measurable objectives, and controlled change.

  • 6.1.1Actions to address risks and opportunities — general. Set the risk foundation and the actions that protect outcomes.
  • 6.1.2AI risk assessment. A repeatable process to find and size AI risks.
  • 6.1.3AI risk treatment. Decide and document how each risk is handled.
  • 6.1.4AI system impact assessment. Understand how the AI could affect individuals, groups, and society.
  • 6.2AI objectives and planning to achieve them. Set measurable objectives and a plan to reach them.
  • 6.3Planning of changes. Change the AIMS deliberately, not accidentally.
Clause 7SupportResource it, staff it, communicate it, document it.+

Support is the machinery that keeps the AIMS running: resources, competence, awareness, communication, and controlled documented information.

  • 7.1Resources. Provide what the AIMS needs to run its PDCA.
  • 7.2Competence. Make sure the people doing AI work are competent.
  • 7.3Awareness. Everyone understands the policy and their part in it.
  • 7.4Communication. Plan internal and external AIMS communication.
  • 7.5Documented information. Control the AIMS's documents and records.
Clause 8OperationRun the controls, keep risk & impact current.+

Operation is doing the AIMS day to day: operational controls across the AI lifecycle, and re-running risk and impact assessments as things change.

  • 8.1Operational planning and control. Execute and control the processes and controls you planned.
  • 8.2AI risk assessment (operational). Keep the risk picture current.
  • 8.3AI risk treatment (operational). Implement treatments and verify they work.
  • 8.4AI system impact assessment (operational). Keep impact understanding current.
Clause 9Performance evaluationMeasure it, audit it, review it.+

Performance evaluation checks whether the AIMS actually works: monitoring and measurement, internal audit, and management review.

  • 9.1Monitoring, measurement, analysis and evaluation. Know whether the AIMS and the AI are performing.
  • 9.2Internal audit. Independently check the AIMS against itself and the standard.
  • 9.3Management review. Leadership formally reviews the AIMS and decides.
Clause 10ImprovementFix root causes; get better continually.+

Improvement closes the loop: continual improvement plus disciplined nonconformity and corrective action.

  • 10.1Continual improvement. Keep making the AIMS more suitable, adequate and effective.
  • 10.2Nonconformity and corrective action. React to problems and stop them recurring.

Annex A control domains

Annex A provides a reference set of 38 controls across 9 domains. You select the ones relevant to your risks in a Statement of Applicability — not every control is mandatory, but every one must be considered.

A.2

Policies related to AI

Provide management direction and support for AI in line with business requirements.

3 CONTROLS

A.3

Internal organization

Establish accountability for the responsible implementation, operation and management of AI.

2 CONTROLS

A.4

Resources for AI systems

Account for the resources (data, tooling, compute, human, system) needed to understand and address AI risks and impacts.

5 CONTROLS

A.5

Assessing impacts of AI systems

Assess AI impacts on individuals, groups, and societies throughout the life cycle.

4 CONTROLS

A.6

AI system life cycle

Define and apply responsible objectives, processes and criteria across the AI system life cycle.

9 CONTROLS

A.7

Data for AI systems

Understand and manage the role and impact of data across the AI life cycle.

5 CONTROLS

A.8

Information for interested parties

Ensure interested parties have the information needed to understand and assess AI risks and impacts.

4 CONTROLS

A.9

Use of AI systems

Use AI systems responsibly and in accordance with organizational policies.

3 CONTROLS

A.10

Third-party and customer relationships

Understand responsibilities and apportion risks when third parties are involved, while remaining accountable.

3 CONTROLS

See where you stand against all of this.

The free readiness assessment scores you against every clause and control.

Get your score