ISO/IEC 42001Free Resource

ISO/IEC 42001 Scope, requirements, controls, evidence, and certification

ISO/IEC 42001:2023 is the current published first edition of the AI management-system standard. It applies to organisations of any size or sector that provide or use products or services using AI systems and sets requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system ().

By Sorena AIUpdated 2026No signup required
Quick scan
ISO/IEC 42001
AIMS scope and inventory
Define the covered units and activities, then map AI systems, roles, intended uses, , external dependencies, and responsibilities across the boundary.
Risk and impact controls
Connect AI risk criteria, risk and impact results, treatment decisions, selected and additional controls, residual-risk approval, monitoring, and corrective action.
Regulation overlap
Keep standards conformance separate from legal compliance: map each applicable law, role, risk category, duty, deadline, and evidence requirement on its own terms.

Start with scope and inventory, then move through Clauses 4-10, risk and impact decisions, the , operating evidence, internal audit, management review, and corrective action.

Key dates
Guides
Deep pages
FAQ
Standalone answers
Compare
Side-by-side
Evidence
Reusable
What this hub helps you do
AIMS scope and inventory
Define the organisational boundary and activities governed by the , identify relevant and requirements, map AI-system roles, and document interfaces with suppliers and shared services.
Risk and impact controls
Establish risk criteria and repeatable risk and impact methods, choose and justify necessary controls in the , operate them, and retain evidence of results.
Regulation overlap
Use the to organise governance work while separately mapping binding laws, contracts, customer duties, and sector requirements. Certification does not replace those assessments.
Scope
Evidence
Review
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 31, 2026

Clauses 4-10 contain the management-system requirements. Normative is a reference control set used during ; normative Annex B gives adaptable implementation guidance; informative Annexes C and D provide possible objectives, risk sources, and cross-domain context. Certification is voluntary and concerns the defined scope, not an individual model or automatic legal compliance.

Common starting points

Start with the AIMS decision in front of you

Use these guides to define the Artificial Intelligence Management System () required by ISO/IEC 42001, choose controls, assess impacts, and design . Certification covers the defined management-system scope; it does not certify an individual model or automatically prove legal compliance.

Design effective human oversight

ISO/IEC 42001 controls can assign trained people to review AI outputs, monitor performance and accuracy, report concerns, and override decisions under defined authority. For example, a credit reviewer can check the recommendation and its inputs, record a concern, and use the organization's documented override route.

Review human oversight requirements

Define the AIMS scope

The scope states which business units, locations, AI activities, systems, suppliers, and interfaces the management system covers. are people or organizations that affect, use, regulate, or are affected by that scope, such as workers, customers, regulators, and model suppliers.

Define the AIMS boundary

Run an AI system impact assessment

An records how a specific use could affect people, groups, or society. For a hiring tool, examine exclusion, accessibility, biased ranking, privacy, explanation, appeal, and human intervention in the actual legal and workplace setting. Reassess on schedule and before a significant change.

Use the impact assessment template

Choose and justify controls

selects controls for assessed AI risks. Compare the controls needed with , add any necessary controls outside it, and record inclusion and exclusion reasons in the . The treatment plan also needs management approval and acceptance of residual risk.

Map controls and governance
Recommended reading path

Build the AIMS in management-system order

Define the boundary and AI-system inventory first. Then map Clauses 4-10, run and impact assessment, operate necessary controls, and evaluate the system. These pages explain the decision path but do not replace the licensed standard.

1

Start here: scope and inventory

Determine the organisational boundary, AI activities and roles, relevant interested parties and requirements, external interfaces, and system inventory that later risk and control decisions depend on.

3

Risk, impacts, and operating evidence

Turn risk and impact methods, the statement of applicability, residual-risk approval, selected controls, supplier responsibilities, monitoring, audit, and corrective action into traceable records.

Next step

Turn ISO/IEC 42001 guidance into a cited workflow

Route ISO/IEC 42001 implementation into owned tasks, evidence requests, and review checkpoints so standards work does not remain scattered across documents.

What this unlocks
  • Start from the ISO/IEC 42001 page that matches the decision or evidence gap.
  • Open Research Copilot for interpretation questions tied to cited sources.
  • Use a single source of truth to keep evidence, owners, and review history governed in one place.