Skip to content

ISO/IEC 42001 – Standards for AI Management Systems

Artificial intelligence (AI) is permeating more and more products and services, creating new ethical, security, and regulatory challenges. To give organizations a structured framework, ISO/IEC 42001—the world’s first standard for Artificial Intelligence Management Systems (AIMS)—was published at the end of 2023.

The standard defines requirements for establishing, implementing, maintaining, and continually improving a management system that supports the responsible development, provision, and use of AI systems. ISO/IEC 42001 is intended for organizations of any size and sector that develop, provide, or use AI products or services.

Pro tip: An AIMS aligned with ISO 42001 builds trust in AI applications, promotes transparency and traceability, and helps organizations manage risks and opportunities systematically.


ISO 42001 follows the familiar High-Level Structure used by ISO 27001 and ISO 9001. The main clauses form a continuous improvement cycle:

Clause 4 – Context of the organization

  • Analysis of internal and external factors
  • Definition of the AIMS scope
  • Understanding stakeholder expectations

Clause 5 – Leadership

  • Top management commitment
  • Establishment of an AI policy
  • Definition of roles and responsibilities

Clause 6 – Planning

  • Identification of risks and opportunities related to AI
  • Setting objectives and planning changes
  • Notable feature: Combination of AI risk assessments and AI system impact assessments

Clause 7 – Support

  • Provision of resources and competencies
  • Awareness and communication
  • Documented information

Clause 8 – Operation

  • Operational control
  • Regular performance of risk and impact assessments
  • Implementation of selected controls

Clause 9 – Performance evaluation

  • Monitoring and measuring AIMS performance
  • Internal audits and management reviews

Clause 10 – Improvement

  • Continual improvement of the AIMS
  • Handling nonconformities and corrective actions

The annexes provide detailed guidance and controls:

Annex A – Reference control objectives and controls

  • List of AI-specific control objectives
  • Areas: policies, governance, data management, AI lifecycle, system impact controls
  • Organizations select controls to implement based on risk

Annex B – Implementation guidance

  • Practical guidance for implementing controls
  • Examples: drafting an AI policy, assigning responsibilities, conducting AI risk assessments

Annex C – AI-related organizational objectives and risk factors

  • Examples of AI-specific objectives and risks
  • Reference to ISO/IEC 23894 for detailed AI risk management

Annex D – Use of the AIMS in different sectors

  • Sector-specific application notes
  • Encourages a holistic approach

ISO 42001 distinguishes between different actors:

  • AI Provider: Provides AI systems
  • AI Producer: Designs, develops, and tests AI products
  • AI User: Uses AI products or services in their own business processes

These roles determine specific duties and controls within the AIMS.

A key differentiator from other management system standards is the combination of two assessment types:

AI Risk Assessment

  • Analyzes technical threats and vulnerabilities
  • Evaluates likelihoods affecting the AI system
  • Focuses on system security and reliability

AI System Impact Assessment

  • Evaluates potential impacts on individuals, groups, or society
  • Considers ethical and social factors
  • Supports integration of fairness, transparency, and ethics
  • Assesses discrimination risks and potential harm

Pro tip: Combining both assessments enables a holistic view of AI risks—technical and societal.


Implementation Guidance and Best Practices

Section titled “Implementation Guidance and Best Practices”

A successful AIMS requires strong leadership support:

  • Top management commitment: Adopt an AI policy and allocate resources
  • Realistic scope definition: Focus on relevant AI products, services, or departments
  • Clear governance structure: Define roles and responsibilities

Systematic evaluation

  • Combine technical risk assessments with societal impact analyses
  • Identify threats (data leaks, model manipulation)
  • Analyze ethical aspects and discrimination risks

Control selection

  • Risk-based selection of Annex A controls
  • Documentation in the Statement of Applicability (SoA)
  • Rationale for implemented and excluded controls

Policies & Governance (A.2)

  • Develop an overarching AI policy
  • Review regularly and align with existing policies
  • Integrate into corporate strategy

Roles & Responsibilities (A.3)

  • Clear responsibilities for AI development, operations, and oversight
  • Processes to report concerns and incidents
  • Cross-functional teams and escalation paths

Information for interested parties (A.8)

  • Transparent communication about AI capabilities and limitations
  • Education on risks and terms of use
  • Feedback channels for users

Third parties & customers (A.10)

  • Assign responsibilities across suppliers and customers
  • Fair risk allocation along the value chain
  • Contracts with AI-specific clauses

Comprehensive documentation

  • Policies, processes, and risk assessments
  • Impact analyses and control evidence
  • Versioning and change history

Continuous monitoring

  • Systematic monitoring of AI performance
  • Regular internal audits and management reviews
  • KPIs and trend analysis

Training and awareness

  • AI-specific training for developers and users
  • Awareness of ethical and legal aspects
  • Regular updates on new developments

ISO 42001 supports compliance with upcoming regulations:

  • Proactive risk management: Structured governance for AI risks
  • Transparency and documentation: Auditable compliance processes
  • Repeatable procedures: Scalable approaches for different AI systems

Pro tip: With ISO 42001, organizations can proactively manage risks and be better prepared for legal requirements such as the EU AI Act.


The fuentis Suite can specifically support AIMS implementation:

Risk Management module

  • Structured capture of AI risks and impact analyses
  • Automated risk register linked to assets and controls
  • Templates for AI risk and AI system impact assessments
  • Integration of different evaluation methods

Asset Management

  • Manage data sources, models, and AI systems as assets
  • Assign owners and classifications
  • Lifecycle management for AI components
  • Track dependencies and interfaces

Compliance Management

  • Prebuilt templates for ISO 42001 controls
  • Automated Statement of Applicability
  • Gap analyses and maturity assessments
  • Mapping to other standards (ISO 27001, EU AI Act)

Audit & Review modules

  • Plan and conduct internal AIMS audits
  • Track nonconformities and corrective actions
  • Automated reporting
  • Management dashboard with KPIs

Document Management

  • Central repository for AI policies and risk records
  • Versioning and approval workflows
  • Impact analyses and audit logs
  • Integrated workflow support

ISO 27001 / ISO 27701

  • Shared High-Level Structure eases integration
  • Risk management as a unifying element
  • Many controls can be combined and aligned

NIST AI Risk Management Framework (AI RMF)

  • ISO 42001 complements the NIST framework
  • Both aim at responsible AI development
  • Synergies in risk assessment and governance

EU AI Act

  • ISO 42001 provides a solid foundation for regulatory compliance
  • Likely to serve as a benchmark for AI management systems
  • Supports demonstration of “due diligence”

Industry and privacy standards

  • Combine with GDPR and ISO 27701 for privacy
  • Integrate sector-specific requirements (healthcare, finance)
  • Efficient audit strategies through shared controls

Artificial Intelligence Management System (AIMS): A management system of interrelated elements (policies, objectives, processes) for the responsible development, provision, and use of AI systems.

AI Risk Assessment: Systematic identification and evaluation of technical risks (threats, vulnerabilities, likelihoods) for AI systems.

AI System Impact Assessment: Evaluation of potential impacts from the use or misuse of an AI system on individuals, groups, or society, including ethical and social factors.

Statement of Applicability (SoA): Document describing which Annex A controls are implemented or excluded, and why.

AI Policy: Organization-wide policy for developing and using AI systems; defines principles, objectives, and responsibilities.

Control objective: The purpose of a control (e.g., ensuring transparency or assigning accountability).


  1. First AI management standard: ISO/IEC 42001 is the world’s first AIMS standard, offering a structured framework for the responsible development and use of AI systems.
  2. Holistic risk approach: Beyond classic risk assessments, the standard requires impact assessments to systematically consider societal and ethical effects of AI.
  3. Flexible control selection: Annex A lists AI-specific controls to be selected based on context and justified in the Statement of Applicability.
  4. Synergy with existing standards: ISO 42001 aligns with ISO 27001, ISO 27701, and NIST AI RMF, and provides a solid foundation for complying with the EU AI Act.
  5. Tools as a success factor: Modern platforms like the fuentis Suite accelerate AIMS deployment with dedicated modules for risk management, asset inventory, compliance, and audits.