ISO-42001
ISO/IEC 42001:2023 — AI Management Systems
- I. ISO/IEC 42001:2023 AI Management System Requirements
- Ch. I — Context, Leadership, and Planning (Clauses 4-6)
- Art. 4.1. Understanding the organization and its context (8)
- Art. 4.2. Understanding the needs and expectations of interested parties (4)
- Art. 4.3. Determining the scope of the AI management system (9)
- Art. 4.4. AI management system (12)
- Art. 5.1. Leadership and commitment (10)
- Art. 5.2. AI policy (8)
- Art. 5.3. Roles, responsibilities and authorities (10)
- Art. 6.1.1. General (actions to address risks and opportunities) (7)
- Art. 6.1.2. AI risk assessment (13)
- Art. 6.1.3. AI risk treatment (6)
- Art. 6.1.4. AI system impact assessment (5)
- Art. 6.2. AI objectives and planning to achieve them (12)
- Art. 6.3. Planning of changes (7)
- Ch. II — Support and Operation (Clauses 7-8)
- Art. 7.1. Resources (9)
- Art. 7.2. Competence (5)
- Art. 7.3. Awareness (6)
- Art. 7.4. Communication (3)
- Art. 7.5. Documented information (9)
- Art. 8.1. Operational planning and control (10)
- Art. 8.2. AI risk assessment (operational) (6)
- Art. 8.3. AI risk treatment (operational) (6)
- Art. 8.4. AI system impact assessment (operational) (13)
- Ch. III — Performance Evaluation and Improvement (Clauses 9-10)
- Art. 9.1. Monitoring, measurement, analysis and evaluation (4)
- Art. 9.2. Internal audit (10)
- Art. 9.3. Management review (10)
- Art. 10.1. Continual improvement (9)
- Art. 10.2. Nonconformity and corrective action (10)
- Ch. IV — Annex A Controls — Policies and Organization (A.2-A.3)
- Art. A.2.2. AI Policy (9)
- Art. A.2.3. Responsible AI Topics in AI Policy (4)
- Art. A.3.2. Roles and Responsibilities for AI (6)
- Art. A.3.3. Reporting of AI Concerns (9)
- Art. A.3.4. Impact of Organizational Changes (6)
- Ch. V — Annex A Controls — Resources and Impact Assessment (A.4-A.5)
- Art. A.4.2. Resources Related to AI Systems (5)
- Art. A.4.3. Competencies Related to AI Systems (4)
- Art. A.4.4. Awareness of Responsible Use of AI Systems (4)
- Art. A.4.5. Consultation (6)
- Art. A.4.6. Communication About the AI System (6)
- Art. A.5.2. AI System Risk Assessment (5)
- Art. A.5.3. AI System Impact Assessment (8)
- Art. A.5.4. Impact of AI System Documentation (4)
- Ch. VI — Annex A Controls — AI System Life Cycle (A.6)
- Art. A.6.2.2. Design and Development of AI System (5)
- Art. A.6.2.3. Training and Testing AI Model (14)
- Art. A.6.2.4. Verification and Validation of AI System (7)
- Art. A.6.2.5. Deployment of AI System (10)
- Art. A.6.2.6. Operation and Monitoring of AI System (10)
- Art. A.6.2.7. Retirement of AI System (10)
- Art. A.6.2.8. Responsible AI System Integration (9)
- Art. A.6.2.9. AI System Documentation (7)
- Art. A.6.2.10. Defined Use and Misuse of AI System (5)
- Art. A.6.2.11. Management of Third-Party AI System Components (6)
- Ch. VII — Annex A Controls — Data, Information, and Relationships (A.7-A.10)
- Art. A.7.2. Data for Development and Enhancement of AI System (11)
- Art. A.7.3. Data Quality for ML and Data for AI System (11)
- Art. A.7.4. Data Preparation (11)
- Art. A.7.5. Data Acquisition and Collection (6)
- Art. A.7.6. Data Provenance (7)
- Art. A.8.2. Informing Interested Parties About AI System Interaction (6)
- Art. A.8.3. Informing Interested Parties About AI Outcomes (4)
- Art. A.8.4. Access to Information About AI System Interaction (5)
- Art. A.8.5. Enabling Appropriate Human Actions in Response to AI Outputs (7)
- Art. A.9.2. Objectives for Responsible Use of AI System (6)
- Art. A.9.3. Intended Use of AI System (4)
- Art. A.9.4. Processes for Responsible Use of AI System (7)
- Art. A.9.5. Human Oversight Aspects (11)
- Art. A.10.2. Suppliers of AI System Components (8)
- Art. A.10.3. Shared ML Models (14)
- Art. A.10.4. Provision of AI System to Third Parties (5)
Documentation Obligations
71Title I — ISO/IEC 42001:2023 AI Management System Requirements
Chapter I — Context, Leadership, and Planning (Clauses 4-6)
Article 4.3. Determining the scope of the AI management system
1 obligation
Article 5.2. AI policy
1 obligation
Article 6.1.3. AI risk treatment
1 obligation
Article 6.1.4. AI system impact assessment
1 obligation
Article 6.3. Planning of changes
1 obligation
Chapter II — Support and Operation (Clauses 7-8)
Article 7.2. Competence
1 obligation
Article 7.5. Documented information
6 obligations
ISO42001-7.5-01
Documentation
Include required documented information in AI management system
The organization must include in its AI management system all documented information required by the ISO/IEC 42001:2023
ISO42001-7.5-02
Documentation
Include specific AI management documents
The organization must include specific documented information in the AI management system: AI policy, AI objectives, AI
ISO42001-7.5-03
Documentation
Ensure proper identification of documented information
When creating and updating documented information, the organization must ensure appropriate identification of the docume
ISO42001-7.5-04
Documentation
Ensure proper format of documented information
When creating and updating documented information, the organization must ensure appropriate format of the documents.
ISO42001-7.5-05
Documentation
Ensure review and approval of documented information
When creating and updating documented information, the organization must ensure appropriate review and approval processe
ISO42001-7.5-06
Documentation
Control documented information availability
The organization must control documented information to ensure it is available and suitable for use where and when neede
Article 8.1. Operational planning and control
1 obligation
Article 8.2. AI risk assessment (operational)
2 obligations
ISO42001-8.2-05
Documentation
Retain documented information of risk assessment results
The organization must maintain and preserve documented information containing the results of all AI risk assessments per
ISO42001-8.2-06
Documentation
Ensure traceability between risks and AI systems
The organization must establish and maintain traceability that links identified risks to the specific AI systems to whic
Article 8.3. AI risk treatment (operational)
3 obligations
ISO42001-8.3-02
Documentation
Retain documented information of AI risk treatment results
The organization must maintain documented information showing the results of AI risk treatment activities.
ISO42001-8.3-03
Documentation
Provide evidence of effective control implementation
The organization must maintain evidence demonstrating that selected controls have been implemented effectively as part o
ISO42001-8.3-04
Documentation
Document acceptable residual risk levels
The organization must maintain documentation showing that residual risks are within acceptable levels after risk treatme
Article 8.4. AI system impact assessment (operational)
1 obligation
Chapter III — Performance Evaluation and Improvement (Clauses 9-10)
Article 9.1. Monitoring, measurement, analysis and evaluation
1 obligation
Article 9.3. Management review
2 obligations
ISO42001-9.3-09
Documentation
Document management review outputs with improvement decisions
The outputs of the management review must include decisions related to continual improvement opportunities.
ISO42001-9.3-10
Documentation
Document management review outputs with system change decisions
The outputs of the management review must include any need for changes to the AI management system.
Article 10.2. Nonconformity and corrective action
1 obligation
Chapter IV — Annex A Controls — Policies and Organization (A.2-A.3)
Article A.2.3. Responsible AI Topics in AI Policy
1 obligation
Article A.3.2. Roles and Responsibilities for AI
1 obligation
Article A.3.3. Reporting of AI Concerns
1 obligation
Chapter V — Annex A Controls — Resources and Impact Assessment (A.4-A.5)
Article A.4.5. Consultation
4 obligations
ISO42001-A.4.5-03
Documentation
Document consultation processes and procedures
The organization must document its consultation process, including the established procedures, methodologies, and framew
ISO42001-A.4.5-04
Documentation
Document parties consulted in AI system consultations
The organization must maintain documentation identifying all parties that were consulted regarding its AI systems, inclu
ISO42001-A.4.5-05
Documentation
Document input received from consultations
The organization must document all input, feedback, recommendations, and concerns received from consulted parties regard
ISO42001-A.4.5-06
Documentation
Document consideration of consultation input in AI system decisions
The organization must document how the input received from consultations was considered, evaluated, and incorporated (or
Article A.5.2. AI System Risk Assessment
1 obligation
Article A.5.3. AI System Impact Assessment
1 obligation
Article A.5.4. Impact of AI System Documentation
3 obligations
ISO42001-A.5.4-01
Documentation
Document AI system impact assessment results
The organization must document the complete results of AI system impact assessments, including methodology used, impacts
ISO42001-A.5.4-03
Documentation
Maintain impact assessment documentation throughout AI system lifecycle
The organization must maintain impact assessment documentation continuously throughout the entire AI system lifecycle fr
ISO42001-A.5.4-04
Documentation
Update impact assessment documentation when significant changes occur
The organization must update impact assessment documentation whenever significant changes occur to the AI system or its
Chapter VI — Annex A Controls — AI System Life Cycle (A.6)
Article A.6.2.2. Design and Development of AI System
1 obligation
Article A.6.2.3. Training and Testing AI Model
4 obligations
ISO42001-A.6.2.3-11
Documentation
Document training and testing methodologies
The organization must document the methodologies used for training and testing AI models as part of their compliance req
ISO42001-A.6.2.3-12
Documentation
Document datasets used in training and testing
The organization must document all datasets used in the training and testing of AI models, including their characteristi
ISO42001-A.6.2.3-13
Documentation
Document training and testing results obtained
The organization must document all results obtained from training and testing processes, including performance metrics a
ISO42001-A.6.2.3-14
Documentation
Document decisions made based on training and testing results
The organization must document all decisions made based on training and testing results, including rationale and justifi
Article A.6.2.4. Verification and Validation of AI System
1 obligation
Article A.6.2.5. Deployment of AI System
2 obligations
ISO42001-A.6.2.5-09
Documentation
Document the deployment process
The organization must document the AI system deployment process to maintain records of deployment activities and decisio
ISO42001-A.6.2.5-10
Documentation
Document deviations from planned deployment activities and their resolution
The organization must document any deviations from planned deployment activities and how these deviations were resolved.
Article A.6.2.6. Operation and Monitoring of AI System
1 obligation
Article A.6.2.7. Retirement of AI System
4 obligations
ISO42001-A.6.2.7-04
Documentation
Address Documentation Preservation or Secure Disposal in Retirement
Retirement processes must include procedures for the preservation or secure disposal of documentation associated with th
ISO42001-A.6.2.7-08
Documentation
Document AI System Retirement Decisions
The organization must document all decisions related to the retirement of AI systems.
ISO42001-A.6.2.7-09
Documentation
Document AI System Retirement Activities
The organization must document all activities performed during the retirement of AI systems.
ISO42001-A.6.2.7-10
Documentation
Document Ongoing Obligations Related to Retired AI Systems
The organization must document any ongoing obligations that remain after the AI system has been retired.
Article A.6.2.9. AI System Documentation
6 obligations
ISO42001-A.6.2.9-01
Documentation
Maintain comprehensive AI system documentation throughout lifecycle
The organization must maintain comprehensive documentation for each AI system covering its purpose, design, data sources
ISO42001-A.6.2.9-02
Documentation
Ensure documentation enables system behavior understanding
Documentation must be sufficient to enable understanding of the AI system's behavior by relevant stakeholders.
ISO42001-A.6.2.9-03
Documentation
Ensure documentation supports troubleshooting and incident investigation
Documentation must be adequate to support troubleshooting activities and investigation of incidents involving the AI sys
ISO42001-A.6.2.9-04
Documentation
Ensure documentation facilitates audits
Documentation must be designed and maintained to facilitate audit processes of the AI system.
ISO42001-A.6.2.9-06
Documentation
Keep AI system documentation current
The organization must ensure that AI system documentation remains current and up-to-date.
ISO42001-A.6.2.9-07
Documentation
Update documentation when significant system changes occur
The organization must update AI system documentation whenever significant changes are made to the system.
Article A.6.2.10. Defined Use and Misuse of AI System
1 obligation
Article A.6.2.11. Management of Third-Party AI System Components
1 obligation
Chapter VII — Annex A Controls — Data, Information, and Relationships (A.7-A.10)
Article A.7.2. Data for Development and Enhancement of AI System
1 obligation
Article A.7.3. Data Quality for ML and Data for AI System
3 obligations
ISO42001-A.7.3-09
Documentation
Document Data Quality Processes
The organization must document its data quality processes for ML and AI systems.
ISO42001-A.7.3-10
Documentation
Document Data Quality Metrics
The organization must document its data quality metrics for ML and AI systems.
ISO42001-A.7.3-11
Documentation
Document Data Quality Results
The organization must document its data quality results for ML and AI systems.
Article A.7.4. Data Preparation
2 obligations
ISO42001-A.7.4-02
Documentation
Document Data Preparation Processes
Data preparation processes must be documented to ensure they can be understood, reviewed, and audited by relevant stakeh
ISO42001-A.7.4-10
Documentation
Record Data Preparation Methodologies
The organization must record the specific methodologies and approaches used for data preparation to support transparency
Article A.7.5. Data Acquisition and Collection
1 obligation
Article A.7.6. Data Provenance
1 obligation
Article A.8.4. Access to Information About AI System Interaction
1 obligation
Article A.9.3. Intended Use of AI System
1 obligation
Article A.9.4. Processes for Responsible Use of AI System
1 obligation
Article A.10.3. Shared ML Models
4 obligations
ISO42001-A.10.3-06
Documentation
Maintain documentation of shared model provenance
The organization must maintain documentation of the provenance of shared models.
ISO42001-A.10.3-07
Documentation
Maintain documentation of shared model training data characteristics
The organization must maintain documentation of the training data characteristics of shared models.
ISO42001-A.10.3-08
Documentation
Maintain documentation of shared model known limitations
The organization must maintain documentation of the known limitations of shared models.
ISO42001-A.10.3-09
Documentation
Maintain documentation of shared model performance characteristics
The organization must maintain documentation of the performance characteristics of shared models.