ISO 42001 anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the ISO 42001 cluster.

Primary normative documents

  • ISO/IEC 42001:2023 β€” Information technology β€” Artificial intelligence β€” Management system. Published 18 December 2023. Available from iso.org (CHF 173 / ~€180 single-user PDF) and national standards bodies.
  • ISO/IEC 22989:2022 β€” Artificial intelligence concepts and terminology. Vocabulary reference.
  • ISO/IEC 23053:2022 β€” Framework for AI systems using ML. Useful terminology and ML lifecycle reference.
  • ISO/IEC 23894:2023 β€” AI risk management guidance. Companion to ISO 42001 risk content.
  • ISO/IEC 5338:2023 β€” AI system life cycle processes. Deep on the lifecycle concept.

Standards in development (relevant)

  • ISO/IEC 42005 β€” AI system impact assessment. Will deepen the impact-assessment content currently at policy level in 42001.
  • ISO/IEC 42006 β€” Requirements for bodies providing audit and certification of AI management systems. Will formalize certification body accreditation criteria.
  • ISO/IEC 27090 β€” AI security. Will bridge ISO 27001 and ISO 42001 security concerns.
  • ISO/IEC 27091 β€” AI privacy. Will bridge ISO 27701 and ISO 42001 privacy concerns.
  • ISO/IEC TR 5469:2024 β€” Functional safety and AI systems. Safety-critical AI context.

Owning body

  • ISO/IEC JTC 1/SC 42 β€” joint technical committee subcommittee on Artificial Intelligence. Established October 2017. Multiple working groups:
    • WG 1: Foundational standards
    • WG 2: Data
    • WG 3: Trustworthiness
    • WG 4: Use cases and applications
    • WG 5: Computational approaches and characteristics
    • JWG 1 (with SC 27): Trustworthiness β€” interdisciplinary work on AI security and privacy
    • Several joint working groups with other subcommittees

Chair leadership rotates; the subcommittee draws members from national bodies and liaison organizations worldwide.

Certification bodies (early adopters)

Bodies that started offering ISO 42001 certification in late 2024 / early 2025 (illustrative, not exhaustive):

  • BSI Group β€” UK origin, global. Early to market.
  • DNV β€” Norwegian origin, global.
  • TÜV SΓΌd, TÜV Rheinland, TÜV Nord β€” German technical inspection bodies.
  • LRQA β€” global.
  • SGS β€” Swiss, global.
  • Schellman β€” US-origin, also offering combined SOC 2 + ISO 27001 + ISO 42001 audits.
  • A-LIGN β€” US-origin, similar combined offerings.
  • PECB β€” emerging accreditation in this space.

Accreditation status for ISO 42001 is still developing under ISO/IEC 17021-1; ISO/IEC 42006 (in development) will formalize the AIMS-specific certification body requirements. Buyers should expect more rigorous accreditation enforcement once 42006 is published.

  • NIST AI Risk Management Framework 1.0 (January 2023) + GenAI Profile (NIST AI 600-1, July 2024) β€” voluntary US framework. Four functions: Govern, Map, Measure, Manage. Complementary; mapping documents emerging.
  • EU AI Act (Reg 2024/1689) β€” regulatory; not a framework. ISO 42001 likely to be harmonized under it.
  • OECD AI Principles (2019, updated 2024) β€” voluntary international principles. Influence on national policies.
  • UNESCO Recommendation on the Ethics of AI (2021) β€” voluntary international principles.
  • Singapore Model AI Governance Framework (2020, GenAI extension 2024) β€” voluntary, widely-referenced practical guidance.
  • UK AI Action Plan / DSIT AI policy work β€” voluntary; pro-innovation regulatory approach.
  • OWASP LLM Top 10 (2023, 2024 revision / 2025 published Nov 2024) β€” operational application-security taxonomy.
  • MITRE ATLAS β€” adversarial threat landscape for AI systems.
  • MITRE AI-RMF mapping β€” bridges MITRE work and NIST AI RMF.

Sector-specific AI standards / guidance

  • Financial services: BIS (Bank for International Settlements) work, FSB (Financial Stability Board) papers, ESMA / ECB / Fed AI guidance.
  • Healthcare: FDA AI/ML SaMD guidance (USA), MHRA (UK), EMA (EU), IMDRF Working Group on AI/ML medical devices.
  • Automotive: extensions of UN R155 / R156 for AI-enabled vehicle systems; ISO/SAE work on AI-specific safety considerations.
  • Critical infrastructure: NERC CIP AI extensions in development, ENISA AI work for EU operators.

Named practitioners and reference voices

Standards work

  • Wael William Diab β€” long-standing JTC 1/SC 42 chair; widely interviewed on the standard's development.
  • Various SC 42 WG leads β€” convenors of working groups whose names appear in liaison documents.
  • The Open Group AI Forum β€” adjacent standardization work.
  • NIST AI team β€” Reva Schwartz, Apostol Vassilev, others. NIST AI RMF / AISI work.

Practitioner-side

  • Reid Blackman β€” AI ethics consultant, "Ethical Machines" author.
  • Cathy O'Neil β€” "Weapons of Math Destruction"; algorithmic bias frame.
  • Timnit Gebru, Margaret Mitchell β€” DAIR / Stochastic Parrots / Model Cards work.
  • Anthropic Constitutional AI team β€” RLAIF, Constitutional AI papers.
  • Yann LeCun, Yoshua Bengio, Geoffrey Hinton β€” AI risk landscape voices (varied positions).
  • Andrew Ng β€” practical AI risk framing.
  • Stuart Russell β€” "Human Compatible"; AI safety long view.

Critical voices

  • Emily Bender β€” linguist, critical of LLM capability claims; stochastic-parrots co-author.
  • Gary Marcus β€” critical of deep-learning-only AGI claims; advocate for hybrid approaches.
  • Various AI Safety Institute alumni β€” RAND, METR, Anthropic / OpenAI safety teams.

Audit and consultancy practitioners

  • Big Four AI risk consulting practices (KPMG, Deloitte, PwC, EY) β€” published guidance on ISO 42001 implementation.
  • Boutique AI governance consultancies emerging 2024-2026.

Reference resources

  • iso.org/standard/81230.html β€” ISO 42001 official page; PDF purchase.
  • NIST AIRC (airc.nist.gov) β€” NIST AI Resource Center, framework and playbook content.
  • JTC1/SC 42 SharePoint β€” working documents (committee access only).
  • AI Verify Foundation (Singapore) β€” open-source AI governance toolkit, references ISO 42001 alignment.
  • Various industry-specific compliance vendor platforms β€” Drata, Vanta, Secureframe, Tugboat Logic, others β€” adding ISO 42001 readiness modules through 2024-2025.

Regulatory and procurement-driver context

  • EU AI Act (Reg 2024/1689) β€” regulatory pressure. Risk-tier obligations 2026-2027.
  • EU GDPR (Reg 2016/679) β€” overlaps with ISO 42001 data handling; ISO 27701 PIMS extension complementary.
  • US Executive Orders on AI β€” EO 14110 (October 2023, rescinded January 2025), follow-on EOs through 2025-2026. NIST AI RMF as preferred reference for federal AI work.
  • UK NCSC + DSIT AI guidance β€” voluntary; pro-innovation framing.
  • Sector regulator publications β€” financial services regulators, healthcare regulators, transport regulators all publishing AI guidance increasingly.

See also