home / frameworks / iso-42001

// International standards

ISO/IEC 42001:2023

ISO/IEC 42001 sets requirements for an artificial intelligence management system (AIMS) covering the responsible development, provision, and use of AI. It pairs management system clauses with 38 reference controls and can be certified by an accredited body.

InternationalISO/IEC 42001:2023 (Edition 1, December 2023)

Overview

ISO/IEC 42001 is the first international management system standard for artificial intelligence. ISO and the IEC published it in December 2023 through ISO/IEC JTC 1/SC 42, the joint committee on AI. It's still the first edition. The standard sets requirements for establishing, running, and improving an AI management system, or AIMS, for organizations that develop, provide, or use AI-based products and services.

Like ISO/IEC 27001, it follows the harmonized structure of clauses 4 to 10 and is risk based. It adds AI-specific duties, such as AI risk assessment, AI risk treatment, and AI system impact assessments that consider effects on individuals, groups, and society. Annex A lists 38 reference controls under 9 control objectives, Annex B gives implementation guidance for them, and Annexes C and D cover possible objectives, risk sources, and use across sectors. Not every control must apply. As with ISO/IEC 27001, the organization records its control choices in a Statement of Applicability.

Certification bodies are audited against ISO/IEC 17021-1 and ISO/IEC 42006:2025, which ISO published in July 2025 to set extra requirements for bodies that audit and certify an AIMS. In Canada, the Standards Council of Canada offers an AI management systems accreditation program based on ISO/IEC 42001. Demand for certification in Canada comes mainly from customers, by voluntary commitments such as the federal code of conduct for advanced generative AI systems, and by foreign rules such as the EU AI Act. Many pair it with ISO/IEC 27001.

Who it applies to in Canada

Organizations of any size, sector, or type that develop, provide, or use AI systems, including public agencies and not-for-profits. It covers the governance of AI rather than the technical performance of a single model.

Canadian AI developers and the organizations that buy from them use ISO/IEC 42001 to show responsible AI governance to customers, partners, and investors. The Standards Council of Canada was early to offer accreditation for AI management systems certification bodies, after a pilot completed in 2023.

Controls at a glance

Clauses 4 to 10 set the management system requirements, and Annex A lists 38 reference controls under 9 control objectives numbered A.2 to A.10.

Context and leadership (clauses 4 and 5)

  • Determine the organization's roles in relation to AI
  • Identify interested parties and their AI requirements
  • Define the AIMS scope
  • Top management sets an AI policy and assigns roles

Planning (clause 6)

  • Assess AI risks against defined criteria
  • Plan AI risk treatment and select controls
  • Produce a Statement of Applicability
  • Carry out AI system impact assessments
  • Set AI objectives and plan changes

Support and operation (clauses 7 and 8)

  • Provide resources, competence, awareness, and communication
  • Control documented information
  • Run AI risk assessments, treatment, and impact assessments as planned
  • Control externally provided AI-related processes

Evaluation and improvement (clauses 9 and 10)

  • Monitor and measure AIMS performance
  • Run internal audits and management reviews
  • Correct nonconformities and keep improving

Policies and internal organization (A.2 and A.3)

  • Document an AI policy aligned with other policies
  • Review the AI policy at planned intervals
  • Define AI roles and responsibilities
  • Set up a way to report concerns about AI

Resources and impact assessment (A.4 and A.5)

  • Document data, tooling, computing, and human resources
  • Assess impacts of AI systems on individuals and groups
  • Assess societal impacts of AI systems
  • Document impact assessment results

AI system life cycle and data (A.6 and A.7)

  • Set objectives for responsible AI development
  • Define requirements, design, verification, and validation
  • Plan deployment, operation, monitoring, and event logs
  • Manage data acquisition, quality, and provenance
  • Document data preparation methods

Interested parties, use, and third parties (A.8 to A.10)

  • Give users and affected parties information about the system
  • Plan how incidents are communicated
  • Define processes and objectives for responsible AI use
  • Use AI systems as intended
  • Allocate responsibilities with suppliers, partners, and customers

Certification and assessment

A certification body audits the AIMS in stage 1 and stage 2 audits, checking the AI risk and impact assessments, the Statement of Applicability, and evidence that controls operate. If it conforms, the body issues a certificate for a defined scope. Certification bodies follow ISO/IEC 17021-1 and ISO/IEC 42006:2025.

Dates to know

2023-12
ISO/IEC 42001:2023 published
2025-07
ISO/IEC 42006:2025 published, setting requirements for AIMS certification bodies

Resources

Official texts and free tools for ISO 42001. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. ISO/IEC 42001:2023 Artificial intelligence management system, ISO
  2. ISO/IEC 42006:2025 Requirements for AIMS audit and certification bodies, ISO
  3. SCC launches artificial intelligence management systems accreditation, Standards Council of Canada