AI Atlas
EN TR
Intermediate · ~3 min read #standard #certification #aims

ISO/IEC 42001

The AI management system (AIMS) standard

An international, certifiable standard describing how an organisation establishes, operates and continually improves a management system for responsibly developing, providing or using AI.

ISO/IEC 42001 · AI MANAGEMENT SYSTEM (AIMS)PLANDOCHECKACTcl. 4–6context, policy, riskcl. 7–8support, operationcl. 9audit, reviewcl. 10improvementAIMSANNEX A · 9 OBJECTIVES · 38 CONTROLSA.2AI policiesA.3internal org.A.4resourcesA.5impact assessmentA.6life cycleA.7dataA.8stakeholder infoA.9use of AI systemsA.10suppliers, customers✓ certifiablesame structure: ISO 27001 · ISO 9001companions: 42005 impact · 42006 certifiersaudits how the organisation manages AI, not how good the model is
Definition

ISO/IEC 42001:2023, published in December 2023, is the first AI management system (AIMS) standard. It doesn't measure how good an AI model is; it measures how the organisation manages AI. It applies to any organisation that develops, provides or uses AI, regardless of size or sector.

It shares the common management system structure used by ISO 27001 (information security) and ISO 9001 (quality), and runs on the Plan-Do-Check-Act (PDCA) cycle: - Clauses 4–10 (mandatory requirements): context and scope, leadership and the AI policy, planning for risks and opportunities, AI risk assessment, AI system impact assessment, resources and competence, operation, performance evaluation (internal audit, management review) and improvement. - Annex A (reference controls): 38 controls under 9 control objectives (A.2–A.10): policies related to AI, internal organisation, resources for AI systems, assessing impacts, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, third-party and customer relationships. - Annex B: implementation guidance for the Annex A controls. - Annexes C and D: potential AI objectives and risk sources; use across domains and sectors.

The organisation records which Annex A controls it applies, and why it excludes any, in a Statement of Applicability (SoA).

Certification: an accredited certification body can audit the AIMS independently and issue a certificate. Additional requirements for those certification bodies were published in 2025 as ISO/IEC 42006. For impact assessments there is also the ISO/IEC 42005:2025 guidance standard.

Relation to ISO 27001: because they share a structure, an organisation with an ISO 27001 system can reuse document control, internal audit and management review. But 42001 goes beyond information security: fairness, transparency, human oversight, societal impact.

Relation to the EU AI Act: a 42001 certificate does not mean AI Act compliance. Under the AI Act, presumption of conformity comes from harmonised European standards cited in the Official Journal. Still, 42001's risk management, documentation and life cycle processes are a strong foundation for the quality management system the AI Act requires. This page is informational, not legal advice.

Analogy

Like a restaurant's food hygiene certificate. The inspector doesn't taste the food; they look at how the kitchen runs: where ingredients come from, who is responsible for what, whether temperatures are logged, what happens when a complaint comes in. The certificate shows that a system exists to make the food safe every time.

Real-world example

A B2B software company in Ankara sells an AI product that classifies documents. Enterprise customers in the EU now ask during procurement: "how do you prove your AI governance?" The company already holds ISO 27001.

1. Scope: the AIMS scope is set as "development and provision of the AI product"; internal coding assistants are brought into scope too. 2. Policy and roles: top management signs an AI policy; each product gets a named AI system owner. 3. Risk and impact assessment: every AI system gets a risk assessment and an impact assessment covering the people named in the documents it processes. 4. Annex A and SoA: all 38 controls are considered; most are applied, a few are excluded with a justification. 5. Integrating with the existing system: document control, internal audit and management review run jointly with ISO 27001. 6. Audit: after an internal audit, an accredited body performs a two-stage certification audit, followed by annual surveillance audits.

The certificate shortens sales cycles; the real gain is that every AI change now goes through a defined process.

Code examples
Statement of Applicability (SoA) · excerpt markdown
# ISO/IEC 42001 — Statement of Applicability (excerpt) · v1.3

| Annex A objective                   | Applied | Justification / Evidence              |
|-------------------------------------|---------|---------------------------------------|
| A.2 Policies related to AI          | Yes     | POL-AI-001 AI Policy                  |
| A.3 Internal organisation           | Yes     | RACI matrix, AI committee charter     |
| A.4 Resources for AI systems        | Yes     | Data/tooling/compute inventory        |
| A.5 Assessing impacts               | Yes     | Impact assessment template (42005)    |
| A.6 AI system life cycle            | Yes     | SDLC-AI procedure, release gate       |
| A.7 Data for AI systems             | Yes     | Data provenance and quality records   |
| A.8 Information for interested      | Yes     | Model cards, user notices             |
|     parties                         |         |                                       |
| A.9 Use of AI systems               | Yes     | Acceptable use policy                 |
| A.10 Third-party and customer       | Partly  | Supplier assessment; customer         |
|      relationships                  |         | contract template under revision      |

Note: this table is at objective level; a real SoA has one row
per control.
AIMS internal audit plan yaml
aims_internal_audit_2026:
  standard: ISO/IEC 42001:2023
  scope: "Development and provision of the AI product + internal AI tools"
  integrated_with: ISO/IEC 27001     # shared document/audit process
  auditor: internal-audit@example.com # independent of the audited team
  schedule:
    - { clause: "4-5 Context, leadership, AI policy", month: 2026-10 }
    - { clause: "6 Risk + impact assessment", month: 2026-11 }
    - { clause: "8 Operation (Annex A.6 life cycle)", month: 2026-11 }
    - { clause: "9 Performance + management review", month: 2026-12 }
  sampling:
    ai_systems: [AI-017, AI-031]      # high-risk systems first
  outputs:
    - nonconformities + corrective actions
    - input to management review
  external_audit: "Stage 1 + Stage 2, 2027-Q1"
When to use
  • Customers or tenders ask for independent, auditable evidence of AI governance
  • You already run an ISO 27001 or ISO 9001 management system and want AI under the same roof
  • You need a solid base of risk management, documentation and life cycle processes for AI Act readiness
  • Organisations with several AI products looking for one consistent governance model
When not to use
  • An early-stage startup with one small AI feature and no customer demand — certification cost and effort may be disproportionate
  • Expecting it to replace AI Act compliance — a certificate doesn't meet legal obligations
  • Producing paperwork just for the certificate; an AIMS that doesn't run shows up in the audit and in real incidents
Common pitfalls

Drawing the scope wrong

Limiting scope to one product and leaving internal AI tools out makes certification easier but hides the real risks. Remember customers read what the certificate actually covers.

Treating Annex A as a checklist

Annex A is a reference list; the risk assessment decides which controls you need. 'Everything applies' without reasoning, or exclusions without justification, are the first things an auditor questions.

Copy-pasting from 27001

The shared structure speeds things up, but AI-specific topics such as impact assessment, data provenance, human oversight and transparency aren't in 27001. They need their own processes and evidence.

Not legal advice

This page is general information. The full text of the standard is paid and available from iso.org; work with an accredited certification body for certification decisions.