ISO-42001
ISO/IEC 42001:2023 — AI Management Systems
- I. ISO/IEC 42001:2023 AI Management System Requirements
- Ch. I — Context, Leadership, and Planning (Clauses 4-6)
- Art. 4.1. Understanding the organization and its context (8)
- Art. 4.2. Understanding the needs and expectations of interested parties (4)
- Art. 4.3. Determining the scope of the AI management system (9)
- Art. 4.4. AI management system (12)
- Art. 5.1. Leadership and commitment (10)
- Art. 5.2. AI policy (8)
- Art. 5.3. Roles, responsibilities and authorities (10)
- Art. 6.1.1. General (actions to address risks and opportunities) (7)
- Art. 6.1.2. AI risk assessment (13)
- Art. 6.1.3. AI risk treatment (6)
- Art. 6.1.4. AI system impact assessment (5)
- Art. 6.2. AI objectives and planning to achieve them (12)
- Art. 6.3. Planning of changes (7)
- Ch. II — Support and Operation (Clauses 7-8)
- Art. 7.1. Resources (9)
- Art. 7.2. Competence (5)
- Art. 7.3. Awareness (6)
- Art. 7.4. Communication (3)
- Art. 7.5. Documented information (9)
- Art. 8.1. Operational planning and control (10)
- Art. 8.2. AI risk assessment (operational) (6)
- Art. 8.3. AI risk treatment (operational) (6)
- Art. 8.4. AI system impact assessment (operational) (13)
- Ch. III — Performance Evaluation and Improvement (Clauses 9-10)
- Art. 9.1. Monitoring, measurement, analysis and evaluation (4)
- Art. 9.2. Internal audit (10)
- Art. 9.3. Management review (10)
- Art. 10.1. Continual improvement (9)
- Art. 10.2. Nonconformity and corrective action (10)
- Ch. IV — Annex A Controls — Policies and Organization (A.2-A.3)
- Art. A.2.2. AI Policy (9)
- Art. A.2.3. Responsible AI Topics in AI Policy (4)
- Art. A.3.2. Roles and Responsibilities for AI (6)
- Art. A.3.3. Reporting of AI Concerns (9)
- Art. A.3.4. Impact of Organizational Changes (6)
- Ch. V — Annex A Controls — Resources and Impact Assessment (A.4-A.5)
- Art. A.4.2. Resources Related to AI Systems (5)
- Art. A.4.3. Competencies Related to AI Systems (4)
- Art. A.4.4. Awareness of Responsible Use of AI Systems (4)
- Art. A.4.5. Consultation (6)
- Art. A.4.6. Communication About the AI System (6)
- Art. A.5.2. AI System Risk Assessment (5)
- Art. A.5.3. AI System Impact Assessment (8)
- Art. A.5.4. Impact of AI System Documentation (4)
- Ch. VI — Annex A Controls — AI System Life Cycle (A.6)
- Art. A.6.2.2. Design and Development of AI System (5)
- Art. A.6.2.3. Training and Testing AI Model (14)
- Art. A.6.2.4. Verification and Validation of AI System (7)
- Art. A.6.2.5. Deployment of AI System (10)
- Art. A.6.2.6. Operation and Monitoring of AI System (10)
- Art. A.6.2.7. Retirement of AI System (10)
- Art. A.6.2.8. Responsible AI System Integration (9)
- Art. A.6.2.9. AI System Documentation (7)
- Art. A.6.2.10. Defined Use and Misuse of AI System (5)
- Art. A.6.2.11. Management of Third-Party AI System Components (6)
- Ch. VII — Annex A Controls — Data, Information, and Relationships (A.7-A.10)
- Art. A.7.2. Data for Development and Enhancement of AI System (11)
- Art. A.7.3. Data Quality for ML and Data for AI System (11)
- Art. A.7.4. Data Preparation (11)
- Art. A.7.5. Data Acquisition and Collection (6)
- Art. A.7.6. Data Provenance (7)
- Art. A.8.2. Informing Interested Parties About AI System Interaction (6)
- Art. A.8.3. Informing Interested Parties About AI Outcomes (4)
- Art. A.8.4. Access to Information About AI System Interaction (5)
- Art. A.8.5. Enabling Appropriate Human Actions in Response to AI Outputs (7)
- Art. A.9.2. Objectives for Responsible Use of AI System (6)
- Art. A.9.3. Intended Use of AI System (4)
- Art. A.9.4. Processes for Responsible Use of AI System (7)
- Art. A.9.5. Human Oversight Aspects (11)
- Art. A.10.2. Suppliers of AI System Components (8)
- Art. A.10.3. Shared ML Models (14)
- Art. A.10.4. Provision of AI System to Third Parties (5)
Risk Management Obligations
78Title I — ISO/IEC 42001:2023 AI Management System Requirements
Chapter I — Context, Leadership, and Planning (Clauses 4-6)
Article 5.3. Roles, responsibilities and authorities
1 obligation
Article 6.1.1. General (actions to address risks and opportunities)
2 obligations
ISO42001-6.1.1-02
Risk Management
Determine Risks and Opportunities for AI Management System
The organization must identify and determine the risks and opportunities that need to be addressed in relation to the AI
ISO42001-6.1.1-03
Risk Management
Plan Actions to Address Risks and Opportunities
The organization must develop and plan specific actions to address the identified risks and opportunities related to the
Article 6.1.2. AI risk assessment
13 obligations
ISO42001-6.1.2-01
Risk Management
Define and apply AI risk assessment process
The organization must establish and implement a formal AI risk assessment process that includes defined methodologies an
ISO42001-6.1.2-02
Risk Management
Establish and maintain AI risk criteria
The organization must define, document, and keep current the criteria used to evaluate AI risks, including what constitu
ISO42001-6.1.2-03
Risk Management
Establish criteria for performing AI risk assessments
The organization must define the specific criteria and parameters that govern how AI risk assessments are to be conducte
ISO42001-6.1.2-04
Risk Management
Ensure consistent, valid, and comparable risk assessment results
The organization must implement controls and procedures to guarantee that repeated AI risk assessments produce results t
ISO42001-6.1.2-05
Risk Management
Identify AI system development risks
The organization must systematically identify and catalog risks associated with the development phase of AI systems, inc
ISO42001-6.1.2-06
Risk Management
Identify AI system provision risks
The organization must systematically identify and catalog risks associated with the provision or deployment of AI system
ISO42001-6.1.2-07
Risk Management
Identify AI system use risks
The organization must systematically identify and catalog risks associated with the use or operation of AI systems, incl
ISO42001-6.1.2-08
Risk Management
Analyze and evaluate identified AI risks
The organization must conduct detailed analysis and evaluation of all identified AI risks, systematically examining thei
ISO42001-6.1.2-09
Risk Management
Consider likelihood in AI risk evaluation
The organization must assess and factor in the probability or likelihood of identified AI risks materializing as part of
ISO42001-6.1.2-10
Risk Management
Consider severity in AI risk evaluation
The organization must assess and factor in the potential severity or magnitude of impact of identified AI risks as part
ISO42001-6.1.2-11
Risk Management
Consider nature of potential impacts in AI risk evaluation
The organization must assess and factor in the qualitative characteristics and nature of potential impacts from identifi
ISO42001-6.1.2-12
Risk Management
Compare risk evaluation results with established criteria
The organization must systematically compare the results of AI risk analysis and evaluation against the previously estab
ISO42001-6.1.2-13
Risk Management
Determine which risks require treatment
The organization must make explicit determinations about which identified and evaluated AI risks exceed acceptable thres
Article 6.1.3. AI risk treatment
5 obligations
ISO42001-6.1.3-01
Risk Management
Define and apply AI risk treatment process
The organization must establish and implement a formal AI risk treatment process that selects appropriate risk treatment
ISO42001-6.1.3-02
Risk Management
Determine necessary controls for AI risk treatment
The organization must identify and determine all controls required to implement the chosen AI risk treatment options, wh
ISO42001-6.1.3-04
Risk Management
Formulate AI risk treatment plan
The organization must develop a comprehensive AI risk treatment plan as part of the risk treatment process.
ISO42001-6.1.3-05
Risk Management
Obtain risk owners' approval of treatment plan
The organization must secure formal approval from risk owners for the AI risk treatment plan before implementation.
ISO42001-6.1.3-06
Risk Management
Obtain risk owners' acceptance of residual AI risks
The organization must secure formal acceptance from risk owners for the residual AI risks that remain after treatment im
Article 6.1.4. AI system impact assessment
1 obligation
Article 6.3. Planning of changes
2 obligations
ISO42001-6.3-02
Risk Management
Consider purpose and consequences of AI management system changes
The organization must evaluate and consider the purpose of proposed changes to the AI management system and assess their
ISO42001-6.3-03
Risk Management
Consider integrity of AI management system during changes
The organization must evaluate and ensure that proposed changes do not compromise the overall integrity of the AI manage
Chapter II — Support and Operation (Clauses 7-8)
Article 8.1. Operational planning and control
1 obligation
Article 8.2. AI risk assessment (operational)
4 obligations
ISO42001-8.2-01
Risk Management
Perform AI risk assessments at planned intervals
The organization must conduct AI risk assessments at predetermined scheduled intervals, following the criteria establish
ISO42001-8.2-02
Risk Management
Perform AI risk assessments when significant changes occur
The organization must conduct AI risk assessments whenever significant changes are proposed or occur to AI systems, appl
ISO42001-8.2-03
Risk Management
Conduct risk assessments for each AI system within scope
The organization must perform AI risk assessments for every individual AI system that falls within the scope of the mana
ISO42001-8.2-04
Risk Management
Consider system-specific characteristics in risk assessments
The organization must take into account the specific characteristics, data inputs, outputs, operational context, and aff
Article 8.3. AI risk treatment (operational)
3 obligations
ISO42001-8.3-01
Risk Management
Implement AI risk treatment plan
The organization must implement the AI risk treatment plan that was established in section 6.1.3 of the standard.
ISO42001-8.3-05
Risk Management
Review and update risk treatment plan when outcomes not achieved
When AI risk treatment actions do not achieve the desired outcomes, the organization must review and update the risk tre
ISO42001-8.3-06
Risk Management
Integrate risk treatment into AI system lifecycle processes
The organization must ensure that risk treatment activities are integrated into the AI system lifecycle processes.
Article 8.4. AI system impact assessment (operational)
9 obligations
ISO42001-8.4-01
Risk Management
Perform AI system impact assessments in accordance with established process
The organization must conduct AI system impact assessments following the process established in section 6.1.4 of the sta
ISO42001-8.4-03
Risk Management
Conduct impact assessments when significant changes are proposed to AI systems
The organization must perform impact assessments whenever significant changes to AI systems are proposed, before impleme
ISO42001-8.4-04
Risk Management
Conduct impact assessments when significant changes occur to AI systems
The organization must perform impact assessments whenever significant changes actually occur to AI systems or their oper
ISO42001-8.4-05
Risk Management
Perform impact assessments before deployment of new AI systems
The organization must complete impact assessments prior to deploying any new AI systems into operational use.
ISO42001-8.4-06
Risk Management
Perform impact assessments for material changes to existing systems
The organization must conduct impact assessments when there are material changes to existing AI systems.
ISO42001-8.4-08
Risk Management
Perform impact assessments for material changes to operational environment
The organization must conduct impact assessments when there are material changes to the operational environment of AI sy
ISO42001-8.4-09
Risk Management
Perform impact assessments for material changes to affected populations
The organization must conduct impact assessments when there are material changes to the populations that AI systems affe
ISO42001-8.4-11
Risk Management
Use impact assessment findings to inform risk treatment decisions
The organization must utilize the findings from impact assessments to guide and inform risk treatment decisions.
ISO42001-8.4-12
Risk Management
Use impact assessment findings to inform system design decisions
The organization must utilize the findings from impact assessments to guide and inform AI system design decisions.
Chapter III — Performance Evaluation and Improvement (Clauses 9-10)
Article 10.1. Continual improvement
1 obligation
Chapter IV — Annex A Controls — Policies and Organization (A.2-A.3)
Article A.2.2. AI Policy
1 obligation
Article A.2.3. Responsible AI Topics in AI Policy
1 obligation
Article A.3.3. Reporting of AI Concerns
1 obligation
Article A.3.4. Impact of Organizational Changes
4 obligations
ISO42001-A.3.4-01
Risk Management
Assess Impact of Organizational Changes on AI Systems
The organization must evaluate how organizational changes (strategy, structure, processes, personnel, technology, or bus
ISO42001-A.3.4-02
Risk Management
Review and Update AI Risk Assessments When Changes Affect Performance
When organizational changes may affect the performance, risk profile, or compliance of AI systems, the organization must
ISO42001-A.3.4-03
Risk Management
Review and Update Impact Assessments When Changes Affect Systems
When organizational changes may affect the performance, risk profile, or compliance of AI systems, the organization must
ISO42001-A.3.4-04
Risk Management
Review and Update Associated Controls When Changes Affect Systems
When organizational changes may affect the performance, risk profile, or compliance of AI systems, the organization must
Chapter V — Annex A Controls — Resources and Impact Assessment (A.4-A.5)
Article A.5.2. AI System Risk Assessment
4 obligations
ISO42001-A.5.2-01
Risk Management
Conduct AI System Risk Assessments
The organization must perform risk assessments for each AI system, taking into account the system's specific characteris
ISO42001-A.5.2-02
Risk Management
Identify and Evaluate Multi-Domain AI System Risks
Risk assessments must identify and evaluate risks across multiple domains including accuracy, reliability, fairness, pri
ISO42001-A.5.2-03
Risk Management
Conduct Lifecycle-Wide Risk Assessment
The organization must consider risks across the entire AI system lifecycle, covering all phases from design and developm
ISO42001-A.5.2-05
Risk Management
Use Risk Assessment Results for Control Determination
Risk assessment results must be used to determine appropriate controls and risk treatment measures for the AI system.
Article A.5.3. AI System Impact Assessment
6 obligations
ISO42001-A.5.3-01
Risk Management
Conduct AI System Impact Assessments
The organization must conduct impact assessments to evaluate the potential effects of AI systems on individuals, groups,
ISO42001-A.5.3-02
Risk Management
Consider Direct and Indirect Impacts in Assessment
Impact assessments must consider both direct and indirect impacts, including effects on human rights, fundamental freedo
ISO42001-A.5.3-03
Risk Management
Ensure Proportionate Assessment to System Complexity
The impact assessment must be proportionate to the complexity and potential impact of the AI system being evaluated.
ISO42001-A.5.3-04
Risk Management
Consider Affected Stakeholder Perspectives
The impact assessment must consider the perspectives of affected stakeholders in the evaluation process.
ISO42001-A.5.3-06
Risk Management
Use Results to Inform Risk Treatment Decisions
Impact assessment results must inform risk treatment decisions within the organization.
ISO42001-A.5.3-07
Risk Management
Use Results to Inform System Design Choices
Impact assessment results must inform system design choices and decisions.
Chapter VI — Annex A Controls — AI System Life Cycle (A.6)
Article A.6.2.5. Deployment of AI System
1 obligation
Article A.6.2.6. Operation and Monitoring of AI System
1 obligation
Article A.6.2.7. Retirement of AI System
1 obligation
Article A.6.2.8. Responsible AI System Integration
2 obligations
ISO42001-A.6.2.8-05
Risk Management
Consider Potential for Unintended Consequences from System Interactions
Integration activities must consider the potential for unintended consequences arising from system interactions.
ISO42001-A.6.2.8-06
Risk Management
Assess and Manage Integration Context Risks
The organization must assess and manage risks specific to the integration context.
Article A.6.2.10. Defined Use and Misuse of AI System
1 obligation
Article A.6.2.11. Management of Third-Party AI System Components
1 obligation
Chapter VII — Annex A Controls — Data, Information, and Relationships (A.7-A.10)
Article A.7.3. Data Quality for ML and Data for AI System
1 obligation
Article A.7.5. Data Acquisition and Collection
1 obligation
Article A.7.6. Data Provenance
1 obligation
Article A.8.4. Access to Information About AI System Interaction
1 obligation
Article A.8.5. Enabling Appropriate Human Actions in Response to AI Outputs
1 obligation
Article A.9.4. Processes for Responsible Use of AI System
1 obligation
Article A.10.3. Shared ML Models
4 obligations
ISO42001-A.10.3-02
Risk Management
Assess shared models for quality before integration
Controls must address the assessment of shared models for quality before integration into the organization's AI systems.
ISO42001-A.10.3-03
Risk Management
Assess shared models for bias before integration
Controls must address the assessment of shared models for bias before integration into the organization's AI systems.
ISO42001-A.10.3-04
Risk Management
Assess shared models for security vulnerabilities before integration
Controls must address the assessment of shared models for security vulnerabilities before integration into the organizat
ISO42001-A.10.3-05
Risk Management
Assess shared models for fitness for purpose before integration
Controls must address the assessment of shared models for fitness for purpose before integration into the organization's
Article A.10.4. Provision of AI System to Third Parties
2 obligations
ISO42001-A.10.4-04
Risk Management
Consider potential for third-party misuse
The organization must actively consider and assess the potential for misuse of AI systems by third parties as part of th
ISO42001-A.10.4-05
Risk Management
Implement controls to mitigate third-party misuse risks
The organization must implement appropriate controls to mitigate the risks associated with potential misuse of AI system