
Artificial intelligence is becoming increasingly embedded in how organisations operate, from automated decision-making and customer service chatbots to generative AI tools and machine learning systems. As the use of AI grows, so does the need for organisations to manage the associated risks, responsibilities and opportunities.
ISO/IEC 42001 provides a structured framework for doing exactly that. It is the international standard for Artificial Intelligence Management Systems (AIMS), helping organisations establish, implement, maintain and continually improve their approach to managing AI.
But what does ISO 42001 actually require?
For organisations considering certification, understanding the key ISO 42001 requirements is an important first step. This blog explains the main requirements of the standard and what organisations should consider when implementing an AI Management System.
ISO/IEC 42001:2023 is an international management system standard specifically designed for organisations that develop, provide or use AI-based products and services.
Unlike a technical standard that specifies how an individual AI system should be designed, ISO 42001 focuses on the management and governance of AI within an organisation. It provides a systematic approach to identifying and managing AI-related risks and opportunities.
The standard follows the familiar management system approach used by standards such as ISO 9001 and ISO 27001. This means organisations establish policies and objectives, implement processes and controls, monitor performance, conduct internal audits and continually improve their management system.
ISO 42001 can therefore provide a framework for organisations to demonstrate that AI is being managed in a structured, responsible and controlled way.
ISO 42001 follows the common structure used by modern ISO management system standards. The requirements are primarily contained within Clauses 4 to 10, covering the organisation's context, leadership, planning, support, operation, performance evaluation and continual improvement.
The standard also includes Annex A, which provides a set of reference controls specifically related to AI management.
Here is an overview of the key areas organisations need to address.
The first step is understanding the environment in which the organisation operates and how AI fits into it.
Organisations need to determine the internal and external issues that are relevant to their purpose and that can affect their ability to achieve the intended outcomes of their AI Management System.
This can include considerations such as:
The organisation must also determine the scope of its AI Management System.
This is particularly important because ISO 42001 does not necessarily mean that every AI system used by a large organisation must automatically be included in the certification scope. The organisation needs to establish a clearly defined scope based on its activities, products, services and relevant AI-related processes.
ISO 42001 places responsibility for the effectiveness of the AIMS with top management.
Senior leadership needs to demonstrate commitment to the AI Management System and ensure that AI governance is aligned with the organisation's overall strategic direction.
This includes establishing an appropriate AI policy, assigning responsibilities and authorities, and ensuring that the necessary resources are available.
Leadership should also ensure that responsibilities for AI-related activities are clearly defined.
Depending on the organisation, this could involve people from areas such as:
AI governance should not necessarily sit within a single department. Effective implementation often requires collaboration across different parts of the organisation.
Risk management is a central part of ISO 42001.
Organisations need to establish processes for identifying and assessing risks and opportunities associated with their AI activities.
AI-related risks can vary considerably depending on how AI is being developed or used. Examples might include:
The organisation then needs to determine how these risks will be addressed and establish appropriate objectives and plans.
The approach should be proportionate to the organisation's circumstances and the potential impact of its AI activities.
Organisations need to establish relevant objectives for their AI Management System.
These objectives should be consistent with the AI policy and should be measurable where practicable.
For example, an organisation might establish objectives relating to:
Objectives should not simply exist as statements of intent. Organisations need to establish how they will achieve them, including what will be done, what resources are required, who is responsible and how results will be evaluated.
Like other management system standards, ISO 42001 requires organisations to provide the resources needed to establish and maintain the AIMS.
This includes ensuring that people performing relevant activities are competent.
For organisations using AI, competence can involve much more than technical AI knowledge. Employees may need to understand:
Organisations should also ensure that relevant employees are aware of the implications of failing to follow the AIMS requirements.
A functioning AI Management System needs appropriate documented information.
This does not mean that an organisation needs to create paperwork for its own sake. The documentation should provide evidence that the management system is established, implemented and operating effectively.
Depending on the organisation and its scope, this may include information relating to:
Organisations should ensure that documented information is appropriately controlled and remains available where it is needed.
One of the most important areas of ISO 42001 is putting the management system into practice.
Organisations need to plan, implement and control the processes required to meet their AI-related requirements and objectives.
This means moving beyond policies and procedures and demonstrating that the organisation actually manages AI-related activities in accordance with its defined processes.
The organisation should consider AI throughout relevant stages of its lifecycle and establish appropriate controls based on its risks and circumstances.
This can involve activities such as AI system development, deployment, monitoring, use, modification and eventual retirement.
ISO 42001 places particular emphasis on assessing the risks associated with AI systems.
Organisations need to establish an appropriate process for identifying, analysing and evaluating AI-related risks.
For certain AI systems, organisations may also need to consider the potential impacts of those systems on individuals, groups and society.
An AI impact assessment can help an organisation consider questions such as:
The precise approach will depend on the organisation, the AI system and its intended use.
Annex A of ISO 42001 provides a set of reference controls that organisations can use when establishing their AIMS.
These controls cover areas such as:
Organisations do not necessarily apply every Annex A control in exactly the same way. The controls that are relevant will depend on the organisation's context, risks and scope.
This is an important distinction when preparing for ISO 42001 certification: implementing ISO 42001 is not simply a matter of creating a checklist and applying every possible control.
The organisation needs to determine what is relevant to its AI activities and be able to justify its approach.
Organisations need to determine what needs to be monitored and measured and how the performance of the AI Management System will be evaluated.
This could include monitoring:
The organisation should use the results to determine whether its AIMS is working as intended and identify opportunities for improvement.
Before certification, organisations should conduct internal audits of their AI Management System.
Internal audits provide an opportunity to determine whether the AIMS:
Internal audits should be planned based on the importance of the processes involved, changes affecting the organisation and the results of previous audits.
Importantly, an internal audit should not simply be a document review. It should provide evidence that the organisation's AI management processes are operating effectively in practice.
Top management must periodically review the AI Management System.
The management review provides an opportunity for senior leadership to evaluate whether the AIMS remains suitable, adequate and effective.
Inputs can include:
The outcome should include decisions and actions relating to opportunities for improvement and any required changes to the management system.
ISO 42001 does not stop once an organisation achieves certification.
The organisation needs to continually improve the suitability, adequacy and effectiveness of its AI Management System.
This is particularly important for AI because technologies, risks, regulations and expectations can change rapidly.
Organisations should therefore have processes for identifying and addressing nonconformities, implementing corrective actions and identifying opportunities for improvement.
Certification should be viewed as part of an ongoing AI governance programme rather than a one-off project.
| Area | Examples of what organisations may need to consider |
| AI policies | Establishing policies for responsible AI |
| Internal organisation | Defining roles, responsibilities and accountability |
| Resources | Managing resources needed for AI systems |
| Impact assessment | Assessing potential impacts of AI systems |
| AI system lifecycle | Managing AI through relevant lifecycle stages |
| Data | Managing data used by AI systems |
| Information for interested parties | Providing appropriate information about AI systems |
| Use of AI systems | Establishing controls around AI use |
| Third parties | Managing AI-related suppliers and external providers |
No.
An organisation can implement ISO 42001 without becoming certified. Certification involves an independent third-party certification body (such as TÜV UK) assessing the organisation's AI Management System against the requirements of the standard.
For organisations seeking certification, the process generally involves an initial assessment of the management system followed by a more detailed assessment of its implementation and effectiveness.
The ISO 42001 certification process includes Stage 1, which examines the design and documentation of the management system, followed by Stage 2, which evaluates its implementation and effectiveness. Successful certification is then subject to ongoing surveillance and periodic recertification audits.
Organisations considering certification can start by taking a structured approach:
1. Define your scope
Determine which organisational activities, locations, products, services and AI-related processes will be covered by the AIMS.
2. Understand your AI landscape
Identify the AI systems your organisation develops, provides or uses and understand how they are being used.
3. Conduct a gap analysis
Compare your existing processes against the requirements of ISO 42001 to identify areas requiring development.
4. Identify AI risks and impacts
Establish processes for identifying, assessing and treating relevant AI risks and evaluating potential impacts.
5. Develop your AIMS
Establish the necessary policies, processes, responsibilities, objectives and controls.
6. Implement and monitor
Put the management system into operation and gather evidence that processes and controls are working effectively.
7. Conduct an internal audit
Evaluate your AIMS before the certification audit and address any identified issues.
8. Conduct a management review
Ensure top management has reviewed the performance and effectiveness of the AIMS.
9. Apply for certification
Once the management system has been implemented and is operating effectively, an independent certification body can assess it against ISO 42001.
Organisations do not necessarily need to implement ISO 42001 in isolation.
Because ISO 42001 follows the common management system structure used by many ISO standards, it can be integrated with existing management systems.
For example, an organisation certified to ISO 27001 may already have established processes for information security, risk management, internal audits and management review that can support its AIMS.
However, ISO 42001 introduces specific considerations relating to artificial intelligence that need to be addressed separately. In another blog, we explore the relationship between ISO 42001 and ISO 27001 in more detail.
Not necessarily.
ISO/IEC 42001 is designed to be applicable to organisations of different sizes and across different sectors that develop, provide or use AI-based products or services.
However, the value of certification will depend on an organisation's circumstances.
For some organisations, demonstrating structured AI governance may be increasingly important to customers, regulators, investors and other stakeholders. For others, implementing the standard may provide a framework for improving internal AI governance and risk management.
The important point is that ISO 42001 provides a management framework for responsible AI, rather than being a technical certification for an individual AI product.
Implementing ISO 42001 can help organisations:
ISO itself identifies risk and opportunity management, responsible AI, traceability, transparency and reliability among the potential benefits of implementing ISO/IEC 42001.
ISO/IEC 42001 provides organisations with a structured framework for managing the opportunities and risks associated with artificial intelligence.
While the requirements cover areas familiar from other management system standards, organisations also need to address AI-specific considerations including AI risk management, impact assessments, data, lifecycle management, transparency and responsible use.
For organisations considering certification, the key is not simply to create documentation. The AI Management System needs to be implemented, maintained, monitored and continually improved.
TÜV UK provides UKAS-accredited ISO/IEC 42001 certification services for organisations looking to demonstrate their commitment to responsible AI management. As part of TÜV NORD Group, TÜV UK combines UK certification expertise with international experience in AI management systems.
Interested in ISO 42001 certification? Contact TÜV UK to discuss your requirements and find out how certification can support your organisation's approach to AI governance.
TÜV UK Ltd
AMP House
Suites 27 - 29, Fifth Floor, Dingwall Road
Croydon, CR0 2LX
Tel.: +44 20 8680-7711
Enquiries.UK@tuv-nord.com