Map of ISO/IEC 42001:2023 as the international standard for AI Management Systems (AIMS). The 27001-equivalent for AI governance: Annex SL-aligned management-system requirements (Cl 4-10) plus Annex A controls specific to AI system development, deployment, and operation. Reference cluster for AI-agent system compliance, model-vendor relationships, autonomous-operations governance, and the procurement signals appearing with EU AI Act 2026-2027 enforcement.
Anchors
- position: current view, dated, revisable
- anchors: primary documents, ISO/IEC JTC 1/SC 42, certification bodies, named voices
Provenance
- ISO/IEC JTC 1/SC 42 β joint technical committee subcommittee on Artificial Intelligence. Established 2017. Working groups on foundational standards, computational approaches, trustworthiness, use cases and applications, governance.
- ISO/IEC 42001:2023 β published 18 December 2023. The first AI-specific management system standard. Result of multi-year SC 42 work; first major-ISO AI governance publication.
- Companion standards (SC 42 family):
- ISO/IEC 22989:2022 β AI concepts and terminology
- ISO/IEC 23053:2022 β Framework for AI using ML
- ISO/IEC 23894:2023 β AI risk management guidance
- ISO/IEC 5338:2023 β AI system life cycle processes
- ISO/IEC 5339:2024 β AI applications use cases
- ISO/IEC 27090 (in development) β AI security
- ISO/IEC 27091 (in development) β AI privacy
- ISO/IEC 42005 (in development) β AI system impact assessment
- ISO/IEC 42006 (in development) β Requirements for AI management system audit/certification bodies
- First certifications issued late 2024 / early 2025 by BSI, DNV, TΓV SΓΌd, others. Audit-practice maturity still ramping as of 2026-05-12.
What ISO 42001 is, in one paragraph
ISO/IEC 42001:2023 is a certifiable management-system standard for AI. It defines requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS). Annex SL aligned (shares high-level structure with ISO 9001, ISO 14001, ISO 27001). Applies to any organization developing, providing, or using AI systems, regardless of size or sector. Annex A contains a reference set of AI-specific controls covering policy, organizational roles, resources, AI system impact assessment, AI system lifecycle management, data handling, transparency, use of AI systems by the org, and third-party relationships. Sister standard to ISO 27001; many implementations integrate them.
Mandatory clauses (Cl 4-10, Annex SL aligned)
Same structure as ISO 27001 and other Annex SL standards:
| Clause | Title | Atom |
|---|---|---|
| 4 | Context of the Organization | ISO 42001 Clause Structure |
| 5 | Leadership | ISO 42001 Clause Structure |
| 6 | Planning | ISO 42001 Clause Structure |
| 7 | Support | ISO 42001 Clause Structure |
| 8 | Operation | ISO 42001 Clause Structure |
| 9 | Performance Evaluation | ISO 42001 Clause Structure |
| 10 | Improvement | ISO 42001 Clause Structure |
(Consolidated into a single clause-structure atom because the structure mirrors ISO 27001 mechanics; the AI-specific content lives mostly in Annex A.)
Detail in ISO 42001 Clause Structure.
Annex A controls (AI-specific)
Approximately 38 controls organized around 10 control objectives:
- A.2 Policies related to AI (~2 controls)
- A.3 Internal organization (~2 controls)
- A.4 Resources for AI systems (~5 controls)
- A.5 Assessing impacts of AI systems (~4 controls)
- A.6 AI system lifecycle (~7 controls)
- A.7 Data for AI systems (~4 controls)
- A.8 Information for interested parties of AI systems (~5 controls)
- A.9 Use of AI systems (~2 controls)
- A.10 Third-party and customer relationships (~3 controls)
Detail in ISO 42001 Annex A Controls.
The AI system lifecycle and AI system impact assessment are the load-bearing concepts. Lifecycle includes: planning, design and development, verification and validation, deployment, operation and monitoring, re-evaluation and retirement. Impact assessment is required for AI systems before significant deployment decisions.
Integration with ISO 27001 and ISO 27701
ISO 42001 is sibling to:
- ISO 27001 (Information Security Management System) β many controls overlap (information security, supplier management, asset management, incident management).
- ISO 27701 (Privacy Information Management System) β overlap on PII handling, data protection impact assessment, data subject rights.
- ISO 9001 (Quality Management System) β process discipline overlap.
Combined implementation is the dominant pattern. Detail in ISO 42001 vs ISO 27001 Integration.
Certification process
Standard ISO certification mechanics:
- Stage 1 audit (documentation review)
- Stage 2 audit (implementation audit)
- Initial certification, 3-year validity
- Annual surveillance audits
- Recertification at three-year mark
Certification bodies started offering ISO 42001 audits in late 2024. Audit-practice maturity is still developing; auditor depth on AI-specific controls varies materially across providers.
Detail in ISO 42001 Certification Process.
ISO 42001 in the wider regulatory landscape
ISO 42001 connects to multiple regulatory and standardization streams:
- EU AI Act (Reg 2024/1689) β ISO 42001 is widely expected to become the harmonized standard supporting AI Act compliance for general-purpose and high-risk AI systems. Formal harmonization process underway in 2025-2026.
- NIST AI RMF (US) β voluntary; outcomes-oriented. Maps to ISO 42001 at a function level (govern / map / measure / manage maps to ISO clauses + controls). Combined implementation is feasible.
- National AI strategies β various jurisdictions (UK, Canada, Singapore, Japan, Australia, Brazil) referencing ISO 42001 in voluntary or upcoming-regulatory contexts.
- Sector-specific AI guidance β financial services (BIS, FSB), healthcare (FDA, EMA, MHRA), automotive (UN R155-style extensions) often reference or build on ISO 42001 structure.
Why this matters for SRE and AI-agent work
- AIMS is the standard frame for AI governance. Like ISO 27001 became the InfoSec governance frame, ISO 42001 is positioning to become the AI governance frame.
- Procurement signal incoming. As EU AI Act enforcement ramps (Aug 2026, Aug 2027), buyers will increasingly specify AI governance evidence. ISO 42001 cert is the most defensible signal currently available.
- Lifecycle discipline. The AI system lifecycle concept formalizes what SRE / DevOps teams already do informally for ML systems. Aligns with MLOps practice.
- Impact assessment as a control. AI impact assessment is mandatory for in-scope AI systems. Covers fairness, robustness, transparency, accountability, environmental impact, societal impact. Formal process required.
- Third-party / customer relationships clause. Model provider relationships (Anthropic, OpenAI, Google, Cohere, etc.) get explicit treatment. Vendor due diligence, contract terms, ongoing monitoring required.
- Documentation expectations are heavy. Like ISO 27001, ISO 42001 expects substantial documented information. Lean orgs need to design the documentation to add value rather than ceremony.
Stefan-context relevance
Stefan does SRE / staff-engineer-track work touching:
- AI-agent operations (OpenCode plugins, Claude Code, MCP servers, vault-based agent systems)
- Model-vendor relationships across multiple providers
- Client engagements where AI features are increasingly load-bearing
- German Mittelstand procurement that will see AI Act enforcement pressure 2026+
Cluster atoms should:
- Stay implementation-grounded (named clauses, named controls, real evidence artefacts)
- Make the ISO 27001 / ISO 42001 / NIST AI RMF / OWASP LLM Top 10 / EU AI Act stack-fit explicit
- Bridge MLOps and AIOps practice to the management-system language
- Carry procurement-readiness through Stefan's likely engagement paths
Related clusters and atoms
- ISO 27001 β InfoSec management system, sibling
- TISAX β automotive supplier assurance; AI-handling concerns increasingly relevant
- ITIL β service management; AI feature service-management overlap
- TOGAF β enterprise architecture; AI systems as architectural concerns
- NIST AI RMF β voluntary US framework, complementary
- OWASP LLM Top 10 β operational threat taxonomy
- EU AI Act β regulatory driver
Conventions for this cluster
- Atoms named
ISO 42001 <Topic>.mdwith consistent structure - ISO 42001:2023 is the default version reference
- Cross-link to ISO 27001 cluster atoms when control content overlaps
- All atoms cite the relevant clause or control reference number explicitly
- Practical examples drawn from real AI-agent operations work where possible
See also
ISO 42001 Cluster (pillars MOC) Β· position Β· anchors Β· ISO 27001 Cluster Β· NIST AI RMF Cluster Β· EU AI Act Cluster