Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the ISO 42001 cluster.
Primary normative documents
- ISO/IEC 42001:2023 β Information technology β Artificial intelligence β Management system. Published 18 December 2023. Available from iso.org (CHF 173 / ~β¬180 single-user PDF) and national standards bodies.
- ISO/IEC 22989:2022 β Artificial intelligence concepts and terminology. Vocabulary reference.
- ISO/IEC 23053:2022 β Framework for AI systems using ML. Useful terminology and ML lifecycle reference.
- ISO/IEC 23894:2023 β AI risk management guidance. Companion to ISO 42001 risk content.
- ISO/IEC 5338:2023 β AI system life cycle processes. Deep on the lifecycle concept.
Standards in development (relevant)
- ISO/IEC 42005 β AI system impact assessment. Will deepen the impact-assessment content currently at policy level in 42001.
- ISO/IEC 42006 β Requirements for bodies providing audit and certification of AI management systems. Will formalize certification body accreditation criteria.
- ISO/IEC 27090 β AI security. Will bridge ISO 27001 and ISO 42001 security concerns.
- ISO/IEC 27091 β AI privacy. Will bridge ISO 27701 and ISO 42001 privacy concerns.
- ISO/IEC TR 5469:2024 β Functional safety and AI systems. Safety-critical AI context.
Owning body
- ISO/IEC JTC 1/SC 42 β joint technical committee subcommittee on Artificial Intelligence. Established October 2017. Multiple working groups:
- WG 1: Foundational standards
- WG 2: Data
- WG 3: Trustworthiness
- WG 4: Use cases and applications
- WG 5: Computational approaches and characteristics
- JWG 1 (with SC 27): Trustworthiness β interdisciplinary work on AI security and privacy
- Several joint working groups with other subcommittees
Chair leadership rotates; the subcommittee draws members from national bodies and liaison organizations worldwide.
Certification bodies (early adopters)
Bodies that started offering ISO 42001 certification in late 2024 / early 2025 (illustrative, not exhaustive):
- BSI Group β UK origin, global. Early to market.
- DNV β Norwegian origin, global.
- TΓV SΓΌd, TΓV Rheinland, TΓV Nord β German technical inspection bodies.
- LRQA β global.
- SGS β Swiss, global.
- Schellman β US-origin, also offering combined SOC 2 + ISO 27001 + ISO 42001 audits.
- A-LIGN β US-origin, similar combined offerings.
- PECB β emerging accreditation in this space.
Accreditation status for ISO 42001 is still developing under ISO/IEC 17021-1; ISO/IEC 42006 (in development) will formalize the AIMS-specific certification body requirements. Buyers should expect more rigorous accreditation enforcement once 42006 is published.
Related and adjacent frameworks
- NIST AI Risk Management Framework 1.0 (January 2023) + GenAI Profile (NIST AI 600-1, July 2024) β voluntary US framework. Four functions: Govern, Map, Measure, Manage. Complementary; mapping documents emerging.
- EU AI Act (Reg 2024/1689) β regulatory; not a framework. ISO 42001 likely to be harmonized under it.
- OECD AI Principles (2019, updated 2024) β voluntary international principles. Influence on national policies.
- UNESCO Recommendation on the Ethics of AI (2021) β voluntary international principles.
- Singapore Model AI Governance Framework (2020, GenAI extension 2024) β voluntary, widely-referenced practical guidance.
- UK AI Action Plan / DSIT AI policy work β voluntary; pro-innovation regulatory approach.
- OWASP LLM Top 10 (2023, 2024 revision / 2025 published Nov 2024) β operational application-security taxonomy.
- MITRE ATLAS β adversarial threat landscape for AI systems.
- MITRE AI-RMF mapping β bridges MITRE work and NIST AI RMF.
Sector-specific AI standards / guidance
- Financial services: BIS (Bank for International Settlements) work, FSB (Financial Stability Board) papers, ESMA / ECB / Fed AI guidance.
- Healthcare: FDA AI/ML SaMD guidance (USA), MHRA (UK), EMA (EU), IMDRF Working Group on AI/ML medical devices.
- Automotive: extensions of UN R155 / R156 for AI-enabled vehicle systems; ISO/SAE work on AI-specific safety considerations.
- Critical infrastructure: NERC CIP AI extensions in development, ENISA AI work for EU operators.
Named practitioners and reference voices
Standards work
- Wael William Diab β long-standing JTC 1/SC 42 chair; widely interviewed on the standard's development.
- Various SC 42 WG leads β convenors of working groups whose names appear in liaison documents.
- The Open Group AI Forum β adjacent standardization work.
- NIST AI team β Reva Schwartz, Apostol Vassilev, others. NIST AI RMF / AISI work.
Practitioner-side
- Reid Blackman β AI ethics consultant, "Ethical Machines" author.
- Cathy O'Neil β "Weapons of Math Destruction"; algorithmic bias frame.
- Timnit Gebru, Margaret Mitchell β DAIR / Stochastic Parrots / Model Cards work.
- Anthropic Constitutional AI team β RLAIF, Constitutional AI papers.
- Yann LeCun, Yoshua Bengio, Geoffrey Hinton β AI risk landscape voices (varied positions).
- Andrew Ng β practical AI risk framing.
- Stuart Russell β "Human Compatible"; AI safety long view.
Critical voices
- Emily Bender β linguist, critical of LLM capability claims; stochastic-parrots co-author.
- Gary Marcus β critical of deep-learning-only AGI claims; advocate for hybrid approaches.
- Various AI Safety Institute alumni β RAND, METR, Anthropic / OpenAI safety teams.
Audit and consultancy practitioners
- Big Four AI risk consulting practices (KPMG, Deloitte, PwC, EY) β published guidance on ISO 42001 implementation.
- Boutique AI governance consultancies emerging 2024-2026.
Reference resources
- iso.org/standard/81230.html β ISO 42001 official page; PDF purchase.
- NIST AIRC (airc.nist.gov) β NIST AI Resource Center, framework and playbook content.
- JTC1/SC 42 SharePoint β working documents (committee access only).
- AI Verify Foundation (Singapore) β open-source AI governance toolkit, references ISO 42001 alignment.
- Various industry-specific compliance vendor platforms β Drata, Vanta, Secureframe, Tugboat Logic, others β adding ISO 42001 readiness modules through 2024-2025.
Regulatory and procurement-driver context
- EU AI Act (Reg 2024/1689) β regulatory pressure. Risk-tier obligations 2026-2027.
- EU GDPR (Reg 2016/679) β overlaps with ISO 42001 data handling; ISO 27701 PIMS extension complementary.
- US Executive Orders on AI β EO 14110 (October 2023, rescinded January 2025), follow-on EOs through 2025-2026. NIST AI RMF as preferred reference for federal AI work.
- UK NCSC + DSIT AI guidance β voluntary; pro-innovation framing.
- Sector regulator publications β financial services regulators, healthcare regulators, transport regulators all publishing AI guidance increasingly.
See also
- cluster MOC Β· position
- ISO 27001 (sibling standard) Β· NIST AI RMF Cluster Β· EU AI Act Cluster Β· OWASP LLM Top 10 Cluster