Information technology — Artificial intelligence — Management system

This document specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI (artificial intelligence) management system within the context of an organization.
This document is intended for use by an organization providing or using products or services that utilize AI systems. This document is intended to help the organization develop, provide or use AI systems responsibly in pursuing its objectives and meet applicable requirements, obligations related to interested parties and expectations from them.
This document is applicable to any organization, regardless of size, type and nature, that provides or uses products or services that utilize AI systems.

Technologies de l'information — Intelligence artificielle — Système de management

Informacijska tehnologija - Umetna inteligenca - Sistem vodenja

General Information

Status
Not Published
Technical Committee
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
08-Oct-2025
Due Date
13-Dec-2025
Standard
ISO/IEC 42001:2023 - Information technology — Artificial intelligence — Management system Released:18. 12. 2023
English language
51 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


INTERNATIONAL ISO/IEC
STANDARD 42001
First edition
2023-12
Information technology — Artificial
intelligence — Management system
Technologies de l'information — Intelligence artificielle — Système
de management
Reference number
© ISO/IEC 2023
© ISO/IEC 2023
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
© ISO/IEC 2023 – All rights reserved

Contents Page
Foreword .v
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Context of the organization .5
4.1 Understanding the organization and its context . 5
4.2 Understanding the needs and expectations of interested parties . 6
4.3 Determining the scope of the AI management system . 6
4.4 AI management system . 6
5 Leadership . 7
5.1 Leadership and commitment . 7
5.2 AI policy . 7
5.3 Roles, responsibilities and authorities . 8
6 Planning . 8
6.1 Actions to address risks and opportunities . 8
6.1.1 General . 8
6.1.2 AI risk assessment . 9
6.1.3 AI risk treatment . 9
6.1.4 AI system impact assessment . 10
6.2 AI objectives and planning to achieve them . 10
6.3 Planning of changes . 11
7 Support .11
7.1 Resources . 11
7.2 Competence . 11
7.3 Awareness . 12
7.4 Communication .12
7.5 Documented information . 12
7.5.1 General .12
7.5.2 Creating and updating documented information .12
7.5.3 Control of documented information . 13
8 Operation .13
8.1 Operational planning and control . 13
8.2 AI risk assessment .13
8.3 AI risk treatment . 14
8.4 AI system impact assessment . 14
9 Performance evaluation .14
9.1 Monitoring, measurement, analysis and evaluation . . 14
9.2 Internal audit . 14
9.2.1 General . 14
9.2.2 Internal audit programme . 14
9.3 Management review .15
9.3.1 General .15
9.3.2 Management review inputs . 15
9.3.3 Management review results . 15
10 Improvement .15
10.1 Continual improvement . 15
10.2 Nonconformity and corrective action . 16
Annex A (normative) Reference control objectives and controls .17
iii
© ISO/IEC 2023 – All rights reserved

Annex B (normative) Implementation guidance for AI controls .21
Annex C (informative) Potential AI-related organizational objectives and risk sources .46
Annex D (informative) Use of the AI management system across domains or sectors .49
Bibliography .51
iv
© ISO/IEC 2023 – All rights reserved

Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work.
The procedures used to develop this document and those intended for its further maintenance
are described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria
needed for the different types of document should be noted. This document was drafted in
accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives or
www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of
any claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC
had not received notice of (a) patent(s) which may be required to implement this document. However,
implementers are cautioned that this may not represent the latest information, which may be obtained
from the patent database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall
not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to
the World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT) see
www.iso.org/iso/foreword.html. In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 42, Artificial intelligence.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
v
© ISO/IEC 2023 – All rights reserved

Introduction
Artificial intelligence (AI) is increasingly applied across all sectors utilizing information technology
and is expected to be one of the main economic drivers. A consequence of this trend is that certain
applications can give rise to societal challenges over the coming years.
This document intends to help organizations responsibly perform their role with respect to AI systems
(e.g. to use, develop, monitor or provide products or services that utilize AI). AI potentially raises
specific considerations such as:
— The use of AI for automatic decision-making, sometimes in a non-transparent and non-explainable
way, can require specific management beyond the management of classical IT systems.
— The use of data analysis, insight and machine learning, rather than human-coded logic to design
systems, both increases the application opportunities for AI systems and changes the way that such
systems are developed, justified and deployed.
— AI systems th
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.