GuideGlobalISO/IEC 42001

ISO/IEC 42001 Requirements

ISO/IEC 42001:2023 places management-system requirements in Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, and improvement.

Annex A and Annex B are normative, but they have different jobs: Annex A is the reference control set used in risk treatment, while Annex B is adaptable implementation guidance. Annexes C and D are informative.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this guide to map the licensed ISO/IEC 42001:2023 text to owners, processes, and evidence. The first edition was published in December 2023 and applies to organisations of any size, type, or sector that provide or use products or services using AI systems. It specifies requirements for an organisational . Conformity or certification does not by itself establish the accuracy, safety, or legal compliance of an individual AI system.

Section 1

How are ISO/IEC 42001 requirements structured?

Clauses 4-10 contain the auditable management-system requirements. Clause 4 sets organisational context and scope; Clause 5 covers leadership; Clause 6 covers planning; Clause 7 covers support; Clause 8 covers operation; Clause 9 covers performance evaluation; and Clause 10 covers improvement.

The annexes support those clauses. Annex A is a reference set of control objectives and controls. Annex B is normative implementation guidance for the Annex A controls. Annex C is informative and lists potential AI-related organisational objectives and risk sources. Annex D is informative and discusses use of the AIMS across domains or sectors.

status does not make every Annex A control universally mandatory. Clause 6.1.3 requires the organisation to determine necessary controls, compare them with Annex A, consider relevant Annex A controls and Annex B guidance, add other controls where needed, and document the necessary controls and inclusion or exclusion reasons in the .

Annex B guidance is not a fixed checklist. The standard says an organisation can extend or modify the guidance or define its own implementation when it is not suitable or sufficient, and organisations do not have to justify inclusion or exclusion of Annex B guidance in the .

ISO International Standards are voluntary and do not replace national law. An applicable law, contract, procurement condition, or other external requirement can still make particular outcomes or use of the standard relevant to an organisation. Certification to ISO/IEC 42001 is also voluntary, is performed by an independent certification body rather than ISO, and assesses the defined AIMS scope rather than granting legal approval to an individual AI system.

  • Clause 4: determine context, relevant and requirements, roles for AI systems, the documented AIMS scope, and the management-system processes and interactions.
  • Clause 5: require top-management leadership, an AI policy, integration into business processes, resources, and assigned responsibilities and authorities.
  • Clause 6: establish risk criteria and repeatable risk assessment, risk treatment, impact assessment, objectives, and planned changes.
  • Clause 7: provide resources, competence, awareness, communications, and controlled .
  • Clause 8: operate planned processes and controls, manage changes and external provision, and repeat risk, treatment, and impact assessments at the specified triggers.
  • Clause 9: define monitoring and measurement, conduct internal audits, and complete management reviews at planned intervals.
  • Clause 10: improve the AIMS and correct nonconformities through cause analysis, corrective action, and effectiveness review.
Section 2

What do Clauses 4-7 require before operation?

Clause 4 starts with the organisation's purpose, internal and external issues, intended AI-system purposes, organisational roles, relevant and requirements, and the documented AIMS boundary. The organisation must determine whether climate change is a relevant issue. These inputs control which activities, risks, objectives, and controls the management system must address.

The roles considered can include AI providers; developers, deployers, operators, testers, and impact assessors; customers and users; integrators and data providers; people affected by the system; and relevant authorities. These are context examples, not fixed categories. The organisation's actual roles and jurisdiction affect which requirements and controls apply and how far they apply.

Clause 5 makes top management accountable for the AIMS. It must align the AI policy and objectives with strategic direction, integrate AIMS requirements into business processes, provide resources, communicate the importance of effective management, and assign responsibility for conformance and performance reporting.

Clause 6 requires risk criteria, a repeatable AI risk-assessment process, treatment decisions, an process, measurable objectives where practicable, and planned AIMS changes. Clause 7 covers the resources, competence, awareness, communications, and controls needed to support that work.

The standard prescribes some but does not prescribe the file names or templates below. Treat them as practical examples and keep only the records needed to meet the stated requirements and show that the scoped AIMS operates as planned.

  • Example Clause 4 evidence: context and climate-relevance analysis, AI-role map, interested-party register, documented scope, process map, and an AI-system inventory supporting the boundary.
  • Example Clause 5 evidence: approved AI policy, policy communications, objectives, resource decisions, role descriptions, authorities, and performance reports to top management.
  • Example Clause 6 evidence: risk criteria, assessment method and results, impact-assessment method and results, , treatment plan, residual-risk approval, objectives, and change plans.
  • Example Clause 7 evidence: resource plans, competence criteria and records, awareness records, communication plan and outputs, document approvals, access controls, versions, retention rules, and protected records.
Section 3

What does Clause 8 require during operation?

Clause 8 requires the organisation to plan, implement, and control the processes needed to meet the AIMS requirements and carry out Clause 6 actions. It must set process criteria, operate the selected controls, monitor their effectiveness, control planned changes, review unintended changes, and control relevant externally provided processes, products, and services.

AI risk assessments must be performed at planned intervals or when significant changes are proposed or occur. AI-system impact assessments must be performed at planned intervals or when significant changes are proposed. Risk treatment must follow the approved plan, be checked for effectiveness, and be repeated when new risks need treatment or existing treatment options are ineffective.

Retain the results of every AI risk assessment, risk treatment, and AI-system impact assessment. The standard does not prescribe one universal interval; the organisation must perform the assessments at planned intervals and apply the specified change triggers.

  • Set operational criteria for each AIMS process and identify the records that show the criteria were followed.
  • Link lifecycle gates and change requests to risk, impact, treatment, and approval records.
  • Monitor selected controls and consider corrective action when intended results are not achieved.
  • Define supplier requirements, evidence, review frequency, exceptions, and responsibility allocation for externally provided AI-related services or components.
  • Keep planned-interval and significant-change triggers distinct so a material proposal is not delayed until the next scheduled review.
Section 4

How do Annex A controls relate to Clause 6?

Annex A groups reference controls under AI policy, internal organisation, AI-system resources, impact assessment, lifecycle, data, information for , responsible use, and third-party and customer relationships. Use it as a completeness comparison during risk treatment, not as a substitute for the risk assessment.

The must contain all controls determined necessary, including additional controls not listed in Annex A, and justify inclusion and exclusion. A control can be excluded when it is not necessary based on the risk assessment and is not required by an applicable external requirement, including where an external requirement provides an exception.

Annex B explains ways to implement the Annex A controls, but the organisation remains responsible for choosing an implementation that meets its own control requirements and treatment needs.

  • Do not mark every Annex A control applicable without linking it to risk treatment or another documented need.
  • Do not omit a necessary control because Annex A lacks an exact label for it.
  • Do not treat Annex B wording as the only permitted implementation.
  • Do not use the without the current risk assessment, treatment plan, and management approval of residual risks.
Section 5

What do Clauses 9 and 10 require?

Clause 9 requires the organisation to decide what to monitor and measure, which methods will produce valid results, when measurement occurs, and when results are analysed and evaluated. It must evaluate AIMS performance and effectiveness and retain evidence of results.

Internal audits must occur at planned intervals and test conformance to the organisation's own AIMS requirements and ISO/IEC 42001, plus effective implementation and maintenance. Top management must review the AIMS at planned intervals using previous actions, context and interested-party changes, performance trends, audit results, and improvement opportunities.

Clause 10 requires continual improvement. When a occurs, the organisation must control and correct it, deal with consequences, evaluate causes and possible recurrence elsewhere, implement needed corrective action, review effectiveness, and change the AIMS if needed.

The records below are practical examples, not ISO-prescribed forms. Each organisation can choose its format as long as the required is controlled and provides the necessary evidence.

  • Example monitoring record: defined measure, method, owner, frequency, result, analysis, threshold, exception, and action.
  • Example internal-audit record: programme, audit objectives, criteria, scope, objective and impartial auditor assignment, samples, findings, and reports to relevant managers.
  • Example management-review record: required inputs, decisions on improvement and AIMS changes, owners, resources, and follow-up status.
  • Example corrective-action record: , immediate correction, consequences, cause analysis, similar-condition review, action, owner, due date, and effectiveness result.
Primary sources

References and citations

iso.org
Referenced sections
  • Official ISO explanation that International Standards are voluntary, do not replace national law, and use shall for requirements, should for recommendations, and may for permission.
iso.org
Referenced sections
  • Official ISO explanation that ISO/IEC 42001 certification is voluntary, ISO does not certify organisations, and independent certification bodies perform certification.
iso.org
Referenced sections
  • Clauses 9 and 10 of the licensed standard establish monitoring, internal-audit, management-review, continual-improvement, and corrective-action requirements.
Related guides

Explore more topics

ISO/IEC 42001 AI Impact Assessment Template
ISO/IEC 42001 AI-system impact assessment template for consequences, affected people, foreseeable misuse, context, evidence, approval, and reassessment.
ISO/IEC 42001 AI Management FAQ
Plain-language ISO/IEC 42001 FAQ covering scope, policy, Annex controls, risk and impact assessment, suppliers, monitoring, certification, and legal limits.
ISO/IEC 42001 AI Policy FAQ
ISO/IEC 42001 AI policy requirements, approval, communication, evidence, alignment with other policies, and review triggers.
ISO/IEC 42001 AI System Inventory Guide
Build an ISO/IEC 42001 AI inventory covering purpose, owners, lifecycle roles, data, resources, suppliers, impacts, risks, controls, and monitoring.
ISO/IEC 42001 AI System Inventory Workflow
ISO/IEC 42001 workflow for creating, approving, maintaining, changing, and retiring AI-system inventory records with accountable evidence.
ISO/IEC 42001 AIMS Scope Decision Guide
Define an auditable ISO/IEC 42001 AIMS boundary across organisational units, AI activities, products, services, interfaces, suppliers, and customers.
ISO/IEC 42001 AIMS Scope Decision Workflow
ISO/IEC 42001 AIMS scope workflow for context, interested parties, AI activities, external dependencies, boundary approval, and change review.
ISO/IEC 42001 Certification FAQ
ISO/IEC 42001 certification scope, readiness evidence, internal audit, management review, corrective action, and claim limits.
ISO/IEC 42001 Compliance Guide
ISO/IEC 42001 conformance guide for Clauses 4-10, risk treatment, controls, operating evidence, internal audit, management review, and correction.
ISO/IEC 42001 Controls and Governance Model Guide
ISO/IEC 42001 governance model linking leadership, policy, risk and impact assessment, Annex controls, lifecycle roles, monitoring, audit, and improvement.
ISO/IEC 42001 Generative AI FAQ
Apply ISO/IEC 42001 to generative AI development, procurement, integration, employee use, supplier evidence, impacts, controls, and monitoring.
ISO/IEC 42001 High Risk AI FAQ
Separate ISO/IEC 42001 organisational risk criteria from legal high-risk AI classifications, with evidence, approval, and reassessment triggers.
ISO/IEC 42001 Human Oversight FAQ
Design and evidence effective human oversight under ISO/IEC 42001, including competence, information, intervention authority, testing, and review.
ISO/IEC 42001 Model Monitoring Evidence Guide
ISO/IEC 42001 monitoring evidence for AIMS performance, AI-system outcomes, impacts, control effectiveness, supplier signals, escalation, and correction.
ISO/IEC 42001 Post Market Monitoring FAQ
Distinguish ISO/IEC 42001 operational monitoring from legal post-market monitoring and connect real-world evidence to risk, review, incidents, and correction.
ISO/IEC 42001 Provider and Deployer Roles FAQ
Map ISO/IEC 42001 lifecycle responsibilities across developers, users, suppliers, customers, and third parties while keeping legal operator roles separate.
ISO/IEC 42001 Risk Controls FAQ
Select, justify, approve, operate, and review ISO/IEC 42001 risk controls, including Annex A comparison, the statement of applicability, residual risk, and evidence.
ISO/IEC 42001 vs EU AI Act Comparison
Compare voluntary ISO/IEC 42001 AIMS certification with binding EU AI Act roles, classifications, duties, evidence, dates, and enforcement.
ISO/IEC 42001 vs ISO/IEC 23894 Comparison
Compare certifiable ISO/IEC 42001 AIMS requirements with ISO/IEC 23894 AI risk-management guidance and see how to integrate their evidence.
ISO/IEC 42001 vs NIST AI RMF Comparison
Compare ISO/IEC 42001 AIMS requirements with the voluntary NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions and evidence.