How should teams handle Generative AI under ISO/IEC 42001?
Treat each generative AI use as a system in context, not as a model name or vendor account. Document the intended purpose, users and affected parties, prohibited or , decisions influenced by outputs, deployment environment, model and service versions, system prompts, retrieval sources, connected tools, input and output data, and supplier-imposed limits.
Classify the relationship before selecting controls. An organisation that trains or fine-tunes a model controls different lifecycle evidence from one that calls an external API, adds retrieval and tools to a supplied model, enables a feature inside business software, or permits staff to use a public service. For each case, record which controls the organisation operates, which evidence the supplier provides, which evidence is unavailable, and whether the remaining limitation is accepted, mitigated, or blocks the use.
Use the and risk assessment to select evaluation and oversight. Examples can include testing grounded answers against approved sources for a retrieval assistant, checking whether a coding assistant introduces insecure dependencies, testing demographic and language performance for a customer service tool, and preventing a content generator from exposing confidential prompts or producing prohibited impersonation. These are examples; the intended use and affected parties determine the actual tests.
Generative AI is not a separate ISO/IEC 42001 certification class, and it is not automatically a general-purpose AI model under the EU AI Act. Where EU law applies, assess the model, downstream system, operator role, and Chapter V or other obligations separately. ISO/IEC 42001:2023 is voluntary unless a contract, policy, or law requires its use. The standard has no universal statutory implementation deadline.
- Record intended use, users, affected parties, decision consequences, and for each use case rather than approving a model for every purpose.
- Map model, data, prompts, retrieval, tooling, hosting, access, logging, moderation, and supplier dependencies, including which party can change each component.
- Set evaluation criteria for the actual use. Include task success, unsupported claims, harmful or prohibited content, privacy and security failures, and performance for relevant groups where those measures fit the impact analysis.
- Define when a human must review, reject, override, or escalate an output, and name the authority that can restrict, suspend, or retire the use.
ISO/IEC 42001:2023 applies to organisations developing, providing, or using AI systems. Clauses 4, 6, and 8 and Annex controls A.4-A.10 ground scope, resources, lifecycle, data, information, responsible use, and supplier treatment for generative AI.
Articles 2 and 3 and Chapter V provide the separate binding EU scope, definitions, and general-purpose AI model obligations; the legal category does not follow from the marketing label 'generative AI'.