GlossaryCompliance operations

ISO 42001

Short answer

ISO 42001 is the international standard for an artificial intelligence management system (AIMS). It sets out how an organisation governs the development, provision or use of AI responsibly, managing risks such as bias, lack of transparency and security, and it can be certified by an accredited body.

What it requires

ISO 42001, published in December 2023, follows the same management system structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. Specific to AI are the AI risk assessment, the AI system impact assessment, which looks at effects on individuals and society, and controls covering the AI lifecycle, data, transparency, human oversight and the use of third party AI.

Who it is for

Both companies that build AI systems and companies that use AI in their products or operations. Customers increasingly ask for it when they want assurance about how a supplier uses AI with their data.

ISO 42001 and the EU AI Act

The EU AI Act is a law; ISO 42001 is a voluntary standard. Certification does not on its own prove compliance with the AI Act, but it provides the governance, risk management, documentation and oversight processes the regulation expects, especially for high risk systems.

Integration with other systems

Because it shares its structure with ISO 27001 and ISO 27701, many companies extend their existing information security management system to cover AI rather than building a separate one. The standard is available from ISO.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub