How should teams handle Generative AI under ISO/IEC 42001?
Start with the operational decision: define what Generative AI means in your ISO/IEC 42001 scope, who owns it, and what record proves the decision is current.
For AI governance work, start from the AI system inventory: purpose, role, provider or deployer status, data inputs, impact assessment, control owner, monitoring signal, human oversight, and change trigger. This keeps the answer useful in audits, customer reviews, incidents, supplier reviews, and management review.
- Name the accountable owner and reviewer for Generative AI.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when Generative AI changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
ISO listing for AIMS requirements that supports keeping generative AI uses in scoped governance, owner assignment, monitoring, and continual-improvement evidence.
ISO risk-management listing that supports identifying, evaluating, treating, and monitoring generative AI risks across the AI system lifecycle.