All solutions Solution · ISO/IEC 42001

Implement ISO 42001: govern AI instead of letting it happen

ISO/IEC 42001:2023 describes how to build a management system for artificial intelligence: from clarifying roles through AI risk assessment to impact assessment for affected people. isidaten maps the standard with its own control catalog instead of folding it into ISO 27001.

Request a demo
Background

What ISO/IEC 42001 requires

AI rarely enters an organization through a strategic decision but through tools: an assistant here, an analysis there, a model inside a specialist application. ISO/IEC 42001:2023 counters this with a framework built like other management system standards: clauses 4 to 10 for context, leadership, planning, support, operation, evaluation and improvement, plus Annex A with 38 reference measures across nine control objectives and Annex B as implementation guidance. The standard complements the EU AI Act but does not replace it.

Context, leadership and AI policy (clauses 4 to 5)AI risk assessment and treatment (clause 6)AI impact assessment for affected individualsOperation, performance evaluation and improvement (clauses 8 to 10)38 reference measures from Annex A (A.2 to A.10)Statement of applicability across the Annex A measures
FAQ

Frequently asked questions

What exactly is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first international standard for an artificial intelligence management system (AIMS). It is structured like ISO 27001, with clauses 4 to 10 and an Annex A containing 38 reference measures across nine control objectives. Annex B provides the implementation guidance.

Does ISO 42001 satisfy the EU AI Act?

No. ISO 42001 is not a harmonised European standard and does not create a presumption of conformity under the AI Act. The standard helps govern AI systematically and many requirements overlap. The duties of the regulation must still be met separately.

Do we need this if we only buy AI tools?

Yes, even then. Whoever uses AI is accountable for the outcomes, regardless of who built the model. That is precisely why the standard requires an inventory of the systems in use, clarity about roles and an impact assessment for affected people.

How does ISO 42001 relate to ISO 27001?

Both are management system standards with the same basic structure but address different subjects: ISO 27001 information security, ISO 42001 the handling of AI, including topics such as transparency, data quality and impact on affected people. In isidaten both catalogs sit side by side on the same object base, so measures are maintained once and referenced to both frameworks.

Ready to simplify your compliance?

Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.