Auditen
Home / Frameworks / ISO 42001

ISO/IEC 42001:2023

ISO/IEC 42001:2023 is the international standard that specifies requirements for establishing, implementing, maintaining, and improving an Artificial Intelligence Management System (AIMS). It provides a structured framework to help organizations manage the risks and opportunities associated with AI responsibly.

Who it applies to

  • Organizations developing their own AI models or applications.
  • Companies deploying third-party AI systems within their business operations.
  • Providers of AI as a Service (AIaaS) who want to demonstrate trust to clients.
  • Regulated industries, such as healthcare and finance, that use AI for automated decision-making.

How it works

The standard follows the High-Level Structure (HLS) common to other ISO management standards, utilizing a "Plan-Do-Check-Act" cycle. It focuses on governance, requiring organizations to define an AI policy, establish risk management processes, and conduct impact assessments regarding ethics, safety, and transparency.

To achieve compliance, an organization must implement the mandatory requirements found in the main clauses and select applicable controls from Annex A. These selections are documented in a Statement of Applicability (SoA), which justifies why specific controls were chosen or excluded based on the organization's AI risk profile.

Certification is granted through an external audit conducted by an accredited third-party body. The auditor reviews documentation, interviews staff, and tests evidence to verify that the AIMS is functioning as described and meets all mandatory requirements of the standard.

Getting started

  1. Conduct a gap analysis to compare current AI practices against ISO 42001 requirements.
  2. Define the scope of the AIMS, specifying which AI systems, departments, or products are covered.
  3. Establish an overarching AI policy and secure formal commitment from senior leadership.
  4. Perform a comprehensive AI risk assessment and develop a corresponding risk treatment plan.
  5. Implement the technical and organizational controls identified in Annex A that apply to your scope.
  6. Execute an internal audit to identify remaining non-conformities before engaging an external certification body.

Controls & requirements

Common misconceptions

  • It is not a technical "safety" certificate for a specific piece of software; it is a management system standard for the processes surrounding AI development and use.
  • Certification does not guarantee that every single output from an AI system will be accurate or unbiased, but rather ensures there is a consistent process in place to manage those risks.