Implement ISO 42001: govern AI instead of letting it happen
ISO/IEC 42001:2023 describes how to build a management system for artificial intelligence: from clarifying roles through AI risk assessment to impact assessment for affected people. isidaten maps the standard with its own control catalog instead of folding it into ISO 27001.
What ISO/IEC 42001 requires
AI rarely enters an organization through a strategic decision but through tools: an assistant here, an analysis there, a model inside a specialist application. ISO/IEC 42001:2023 counters this with a framework built like other management system standards: clauses 4 to 10 for context, leadership, planning, support, operation, evaluation and improvement, plus Annex A with 38 reference measures across nine control objectives and Annex B as implementation guidance. The standard complements the EU AI Act but does not replace it.
How isidaten maps ISO/IEC 42001
Each requirement meets a module that runs on the same object base as the risk register, so the evidence stays connected instead of copied across tools.
Inventory your AI systems
Keep the AI systems and software you use as assets and classify them by risk class under the AI Act. Without this inventory, every assessment stays piecemeal.
View module: IT Asset ManagementAssess and treat AI risks
Keep AI risks in the risk register, assess them and connect them to measures. ISO 42001 is selectable there as a framework, as it is in measures and templates.
View module: Risk RegisterControl catalog and evidence
The Annex A catalog is available OSCAL-natively. Implementations are documented per measure and produce the coverage the cockpit reports.
View module: Security AutomationAI policy and guidelines
Keep the AI policy and its accompanying rules as controlled documents, with approval, version and acknowledgement.
View module: Policy ManagementAI providers and supply chain
Keep providers of AI services and models on file as service providers, because a purchased model does not shift accountability.
View module: Supplier ManagementDemonstrate effectiveness
Evaluate the effectiveness of AI measures and evidence the continual improvement required by clause 10.
View module: Effectiveness AssessmentFrequently asked questions
What exactly is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international standard for an artificial intelligence management system (AIMS). It is structured like ISO 27001, with clauses 4 to 10 and an Annex A containing 38 reference measures across nine control objectives. Annex B provides the implementation guidance.
Does ISO 42001 satisfy the EU AI Act?
No. ISO 42001 is not a harmonised European standard and does not create a presumption of conformity under the AI Act. The standard helps govern AI systematically and many requirements overlap. The duties of the regulation must still be met separately.
Do we need this if we only buy AI tools?
Yes, even then. Whoever uses AI is accountable for the outcomes, regardless of who built the model. That is precisely why the standard requires an inventory of the systems in use, clarity about roles and an impact assessment for affected people.
How does ISO 42001 relate to ISO 27001?
Both are management system standards with the same basic structure but address different subjects: ISO 27001 information security, ISO 42001 the handling of AI, including topics such as transparency, data quality and impact on affected people. In isidaten both catalogs sit side by side on the same object base, so measures are maintained once and referenced to both frameworks.
Ready to simplify your compliance?
Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.