HomeResourcesISO 42001
ISO/IEC 42001:2023

ISO 42001: The AI Management System Standard, Decoded

ISO/IEC 42001:2023 is the world's first AI management system (AIMS) standard. It gives enterprises a structured, auditable framework to manage AI risk, meet regulatory obligations, and demonstrate trustworthy AI governance — from board policy through to live control evidence.

The standard

What is ISO/IEC 42001?

Published in December 2023, ISO/IEC 42001 is the first international standard specifying requirements for an AI Management System (AIMS). Unlike sector-specific regulations such as the EU AI Act, ISO 42001 applies to any organisation that provides or uses AI-based products or services — regardless of industry, geography, or size.

The standard addresses challenges unique to AI: ethical considerations, transparency obligations, human oversight requirements, and the need for continuous learning as models evolve and operating environments change. It is intentionally designed to sit alongside existing management system standards — ISO 9001 (quality), ISO 27001 (information security) — so organisations with existing frameworks can integrate rather than rebuild.

Critically, ISO 42001 treats AI governance as an active management discipline, not a documentation exercise. It requires evidence of operating effectiveness — not just policy documents — making it a natural fit for enterprises already subject to APRA, ASIC, or Privacy Act obligations in Australia.

PublishedDecember 2023 (ISO/IEC 42001:2023)
ScopeAny organisation providing or using AI-based products or services
StructureHigh Level Structure (HLS) — compatible with ISO 9001, ISO 27001, ISO 22301
Core outputCertified AI Management System (AIMS) with auditable evidence
Annex A38 controls across 9 domains covering policy, data, operations, and oversight
AU relevanceAligned to APRA CPS 230, Privacy Act 1988, and Australia's Voluntary AI Safety Standard
ISO 42001 requirements

The seven clauses your AIMS must satisfy

ISO 42001 uses the same High Level Structure as other ISO management standards. Organisations already certified to ISO 27001 or ISO 9001 can extend their existing system rather than building a parallel framework.

04

4. Context of the organisation

Understand internal and external context, identify interested parties, define the scope of your AI Management System, and document how AI objectives align with organisational strategy.

05

5. Leadership

Board and executive accountability for the AIMS. Top management must demonstrate commitment, establish AI policy, assign roles, and ensure governance is integrated into business decision-making.

06

6. Planning

Identify risks and opportunities specific to AI systems. Set measurable AI objectives aligned to ethical, legal, and operational requirements. Plan to achieve these objectives with defined owners and timelines.

07

7. Support

Resources, competence, awareness, and communication. Organisations must ensure staff understand AI governance responsibilities and that documented information is controlled and maintained.

08

8. Operation

Operational planning and control for the full AI lifecycle — from use-case intake through development, deployment, monitoring, and decommissioning. Includes supplier and third-party AI controls.

09

9. Performance evaluation

Monitor, measure, analyse, and evaluate AI system performance and governance effectiveness. Internal audits and management reviews to maintain and improve the AIMS.

10

10. Improvement

Respond to nonconformities, correct root causes, and continually improve the AI Management System. Incidents and near misses feed into the governance improvement cycle.

Annex A controls

38 controls across 9 domains

ISO 42001 Annex A provides a reference set of controls for AI-specific risks. Organisations select controls applicable to their scope and document the rationale for inclusions and exclusions in a Statement of Applicability (SoA).

01

AI policy

Documented AI policy approved at board level covering objectives, principles, and risk appetite

02

AI risk assessment

Systematic identification and assessment of AI-specific risks across the full system lifecycle

03

AI impact assessment

Evaluation of AI system impacts on individuals, groups, and society before deployment

04

AI system controls

Technical and organisational controls governing model development, validation, and deployment

05

Data governance

Controls over training data quality, provenance, bias testing, and ongoing data integrity

06

Human oversight

Mechanisms for human review, intervention, and override of AI system decisions

07

Third-party AI

Supplier assessment and ongoing oversight for externally sourced AI systems and models

08

Transparency and explainability

Documentation and communication of how AI systems make decisions and their limitations

ISO 42001 compliance software

How Wahid AI operationalises ISO 42001

Every Wahid AI module maps to specific ISO 42001 clauses. Obligations derive from intake answers — never re-keyed. Evidence moves from Open to Met inside the same workflow.

Use-Case Intake

Clause 8 — Operational planning. Every AI initiative classified against ISO 42001 impact tiers at intake, before deployment decisions are made.

Risk Register

Clause 6 — Planning. Risks identified, rated, and owned with treatment plans traceable to specific ISO 42001 Annex A controls.

Compliance Mapping

Clause 9 — Performance evaluation. All 38 ISO 42001 Annex A controls mapped to obligations with live evidence status: Open, In Progress, Evidenced, Met.

Third-Party Oversight

Annex A — Supplier controls. Vendors tiered and assessed against AI-specific due diligence criteria with automated monitoring.

Maturity Assessment

Clause 9 — Management review. Governance maturity scored 0–4 across ten domains with an ISO 42001 add-on module and certification-readiness gap report.

Board Reporting

Clause 5 — Leadership. Six live executive lenses feeding recurring board AI governance agenda items with exportable audit-ready evidence packs.

FAQ

ISO 42001 — common questions

01

What is ISO 42001?

ISO/IEC 42001:2023 is the world's first AI management system (AIMS) standard. It specifies requirements to establish, implement, maintain, and continually improve an AI Management System across any organisation providing or using AI-based products or services.

02

Who does ISO 42001 apply to?

ISO 42001 applies to any organisation that provides or uses AI-based products or services — regardless of sector or size. Financial services, healthcare, government, telco, logistics, and technology organisations in Australia and globally are all in scope.

03

How long does ISO 42001 certification take?

Certification typically takes 6–18 months depending on organisational size, existing governance maturity, and the scope of AI systems in scope. Wahid AI accelerates this by providing a pre-mapped compliance register against all 38 ISO 42001 Annex A controls.

04

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 covers information security management systems broadly. ISO 42001 is designed specifically for AI systems, addressing AI-specific risks including model risk, bias, explainability, data quality, human oversight, and the unique ethical considerations of AI deployment.

05

Does ISO 42001 certification satisfy EU AI Act requirements?

ISO 42001 provides a strong governance foundation and overlaps significantly with EU AI Act obligations — particularly for risk management, documentation, human oversight, and third-party controls. It does not fully substitute for EU AI Act compliance, which has specific conformity assessment requirements for high-risk systems.

Ready to build an ISO 42001-aligned AI governance program?

Wahid AI maps all 38 Annex A controls to live evidence inside a single governed workflow. See it in a 30-minute demo on your AI systems.

ISO/IEC 42001EU AI ActNIST AI RMFAPRA CPS 230