FAQGlobalISO/IEC 42001

ISO/IEC 42001 FAQ

Answers to recurring questions about ISO/IEC 42001 scope, AI policy, risk and impact assessment, Annex controls, monitoring, roles, certification, and the relationship with legal requirements.

ISO/IEC 42001 is a voluntary, certifiable management-system standard. It can organise AI governance but does not certify a model or replace applicable law, contracts, sector rules, or customer requirements.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start with the boundary and the organisation's role in developing, providing, or using AI systems. The answers below distinguish management-system requirements from optional implementation choices and from separate legal classifications such as the EU AI Act's provider, deployer, or high-risk categories.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items32
Focused FAQ modules
8
Showing 8 of 8
FAQ module

ISO/IEC 42001 AI Policy FAQ

ISO/IEC 42001 AI policy requirements, approval, communication, evidence, alignment with other policies, and review triggers.

4 items
FAQ module

ISO/IEC 42001 Certification FAQ

ISO/IEC 42001 certification scope, readiness evidence, internal audit, management review, corrective action, and claim limits.

4 items
FAQ module

ISO/IEC 42001 Generative AI FAQ

Apply ISO/IEC 42001 to generative AI development, procurement, integration, employee use, supplier evidence, impacts, controls, and monitoring.

4 items
FAQ module

ISO/IEC 42001 High Risk AI FAQ

Separate ISO/IEC 42001 organisational risk criteria from legal high-risk AI classifications, with evidence, approval, and reassessment triggers.

4 items
FAQ module

ISO/IEC 42001 Human Oversight FAQ

Design and evidence effective human oversight under ISO/IEC 42001, including competence, information, intervention authority, testing, and review.

4 items
FAQ module

ISO/IEC 42001 Post Market Monitoring FAQ

Distinguish ISO/IEC 42001 operational monitoring from legal post-market monitoring and connect real-world evidence to risk, review, incidents, and correction.

4 items
FAQ module

ISO/IEC 42001 Provider and Deployer Roles FAQ

Map ISO/IEC 42001 lifecycle responsibilities across developers, users, suppliers, customers, and third parties while keeping legal operator roles separate.

4 items
FAQ module

ISO/IEC 42001 Risk Controls FAQ

Select, justify, approve, operate, and review ISO/IEC 42001 risk controls, including Annex A comparison, the statement of applicability, residual risk, and evidence.

4 items
Question 1

What does ISO/IEC 42001 cover, and what does it not prove?

The standard specifies requirements for establishing, implementing, maintaining, and continually improving an . Its Clauses 4-10 cover context, leadership, planning, support, operation, performance evaluation, and improvement.

A conformity claim or certificate relates to the defined scope and audit criteria. It does not by itself prove that a particular model is accurate, unbiased, safe, lawful, or compliant with the EU AI Act or another regulation.

  • Scope: identify the legal entity, functions, locations, products, services, AI activities, and interfaces that the covers, and keep that boundary as controlled documented information.
  • Roles: determine whether the organisation develops, provides, or uses each AI system; one organisation can hold different roles for different systems.
  • Limits: check applicable law, contracts, sector rules, and customer requirements separately. ISO/IEC 42001 does not displace them.
Question 2

Are all Annex A controls mandatory?

No. The organisation determines necessary controls through AI risk treatment, compares them with Annex A to check that necessary controls were not omitted, considers relevant Annex A controls and Annex B guidance, and identifies additional controls where needed.

Document the rationale for selected, excluded, different, and additional controls. The resulting set should address the organisation's objectives, risks, AI activities, interested-party requirements, and context.

  • Create a statement of applicability that lists the necessary controls and justifies each inclusion and exclusion.
  • Keep the approved risk-treatment plan and acceptance of residual AI risk by designated management.
  • Retain operating evidence for selected controls; a control name or policy reference alone does not show that the control works.
  • Revisit the control set when a significant change or a new risk makes the existing treatment ineffective.
Question 3

How do AI risk assessment and AI-system impact assessment differ?

AI risk assessment applies the organisation's risk criteria to identify, analyse, and evaluate AI risks. AI-system impact assessment examines potential consequences of deployment, intended use, and foreseeable misuse for individuals, groups, and societies in the relevant context.

The impact-assessment result informs the AI risk assessment. It should be performed at planned intervals or when significant changes are proposed, and its results should be retained. Discipline-specific privacy, safety, security, or legal assessments can still be necessary.

  • Risk assessment: use repeatable criteria to identify risks, analyse consequences and realistic likelihood where applicable, determine risk levels, and prioritise treatment.
  • Impact assessment: examine consequences for individuals, groups, and societies across the relevant technical, societal, deployment, and jurisdictional context.
  • Connection: document the impact result and consider it in the AI risk assessment. Retain both records. Repeat risk assessment at planned intervals or when significant changes are proposed or occur; repeat impact assessment at planned intervals or when significant changes are proposed.
Question 4

How are suppliers, customers, and third parties handled?

Annex A.10 addresses allocation of responsibilities across the AI-system lifecycle, supplier alignment with the organisation's responsible AI approach, and consideration of customer expectations and needs.

Contracts can support that allocation, but the still needs operational evidence: accepted responsibilities, information exchange, service and model changes, incident routes, monitoring data, limitations, and escalation or exit arrangements.

  • List every party that supplies data, models, components, integration, operation, support, or customer-facing information, then allocate the material lifecycle responsibilities.
  • Set supplier requirements according to what is supplied and the risk it creates, including documentation, change notice, monitoring, incident, and corrective-action expectations.
  • Tell customers the system's intended domain, material limits, instructions, and the responsibilities they must carry; do not assume the contract label settles a legal operator role.
Question 5

What keeps the AIMS current after implementation?

Monitor and evaluate performance and control effectiveness, run an internal audit programme, conduct management reviews, address nonconformities and their causes, and verify corrective-action effectiveness.

Also trigger review when the boundary, organisational context, interested-party requirements, AI purpose, data, supplier, customer allocation, deployment context, risk, impact, or relevant law changes.

  • Define what will be monitored, the methods that produce valid results, the timing, and when results will be analysed and evaluated.
  • Audit at planned intervals with objective and impartial auditors, defined criteria and scope, and retained audit results.
  • Use management review for decisions on continual improvement and changes to the , then correct nonconformities, address causes, and verify corrective-action effectiveness.
Recommended next step

Put the ISO/IEC 42001 FAQ into practice

Capture owners, evidence, decisions, and review dates in one workflow record so AI governance controls and escalation points stay auditable over time.

Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 42001:2023 Clauses 9 and 10 require performance evaluation, internal audit, management review, continual improvement, and controlled corrective action.
"requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System"
Related guides

Explore more topics

ISO/IEC 42001 AI Impact Assessment Template
ISO/IEC 42001 AI-system impact assessment template for consequences, affected people, foreseeable misuse, context, evidence, approval, and reassessment.
ISO/IEC 42001 AI System Inventory Guide
Build an ISO/IEC 42001 AI inventory covering purpose, owners, lifecycle roles, data, resources, suppliers, impacts, risks, controls, and monitoring.
ISO/IEC 42001 AI System Inventory Workflow
ISO/IEC 42001 workflow for creating, approving, maintaining, changing, and retiring AI-system inventory records with accountable evidence.
ISO/IEC 42001 AIMS Scope Decision Guide
Define an auditable ISO/IEC 42001 AIMS boundary across organisational units, AI activities, products, services, interfaces, suppliers, and customers.
ISO/IEC 42001 AIMS Scope Decision Workflow
ISO/IEC 42001 AIMS scope workflow for context, interested parties, AI activities, external dependencies, boundary approval, and change review.
ISO/IEC 42001 Compliance Guide
ISO/IEC 42001 conformance guide for Clauses 4-10, risk treatment, controls, operating evidence, internal audit, management review, and correction.
ISO/IEC 42001 Controls and Governance Model Guide
ISO/IEC 42001 governance model linking leadership, policy, risk and impact assessment, Annex controls, lifecycle roles, monitoring, audit, and improvement.
ISO/IEC 42001 Model Monitoring Evidence Guide
ISO/IEC 42001 monitoring evidence for AIMS performance, AI-system outcomes, impacts, control effectiveness, supplier signals, escalation, and correction.
ISO/IEC 42001 Requirements Guide
ISO/IEC 42001:2023 requirements explained across Clauses 4-10, Annex A controls, Annex B guidance, evidence, audit, review, and improvement.
ISO/IEC 42001 vs EU AI Act Comparison
Compare voluntary ISO/IEC 42001 AIMS certification with binding EU AI Act roles, classifications, duties, evidence, dates, and enforcement.
ISO/IEC 42001 vs ISO/IEC 23894 Comparison
Compare certifiable ISO/IEC 42001 AIMS requirements with ISO/IEC 23894 AI risk-management guidance and see how to integrate their evidence.
ISO/IEC 42001 vs NIST AI RMF Comparison
Compare ISO/IEC 42001 AIMS requirements with the voluntary NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions and evidence.