Compliance Guide

    ISO/IEC 42001:2023 AI Management System

    ISO/IEC 42001:2023 is the world's first international, certifiable standard for an Artificial Intelligence Management System (AIMS). Published by ISO and IEC, it provides a structured framework to responsibly develop, deploy, and manage AI systems - with a focus on accountability, transparency, traceability, and risk management for AI-specific risks like bias, data quality, explainability, and societal impact.

    Key Components of ISO/IEC 42001

    Built around the Plan-Do-Check-Act (PDCA) cycle, the standard requires organizations to establish, implement, maintain, and continually improve an AIMS. It follows the same High-Level Structure as ISO 27001, ISO 9001, and ISO 27701 - making integration straightforward.

    Scope

    Applies to any organization that develops, provides, or uses AI systems - regardless of size or industry.

    Risk Assessment

    Mandatory systematic identification, analysis, and treatment of AI-specific risks and opportunities.

    Leadership & Commitment

    Top management must demonstrate leadership, establish an AI policy, and define roles and objectives.

    Annex A Controls

    38 reference controls across 9 control objectives. Selected and implemented via a Statement of Applicability tailored to your AI risk profile.

    Not sure if ISO 42001 applies to your AI use cases?

    A short scoping call clarifies which AI systems fall in scope, which Annex A controls are relevant, and how 42001 maps to standards you already follow.

    Scope My AIMS

    Why ISO/IEC 42001 Certification Matters

    Competitive Advantage

    Positions your organization as a leader in responsible AI and differentiates you from competitors.

    Regulatory Alignment

    Prepares you for emerging global regulations including the EU AI Act, demonstrating proactive compliance.

    Trust & Reputation

    Builds stakeholder confidence by proving ethical, transparent, and reliable AI practices.

    Risk Reduction

    Systematically mitigates AI-specific risks before they become costly issues.

    Operational Efficiency

    Integrates seamlessly with existing management systems, reducing duplication and audit fatigue.

    Responsible AI

    Embeds bias mitigation, explainability, and human oversight into every stage of the AI lifecycle.

    ISO/IEC 42001 is not a one-time certification - it is an ongoing management system that requires continual improvement and annual surveillance audits.

    Common Controls Tested in an ISO 42001 Audit

    Certification bodies assess both the AIMS requirements (Clauses 4-10) and the selected Annex A controls. Key focus areas include:

    • AI governance, leadership, and policy
    • Risk management and impact assessments
    • AI system lifecycle (design, development, deployment, monitoring)
    • Data governance and quality for AI systems
    • Transparency, explainability, and human oversight
    • Third-party and supply chain management
    • Incident management and continual improvement

    The ISO/IEC 42001 Certification Process

    Certification is performed by an accredited certification body and follows a two-stage audit process - identical to other ISO management system standards. Successful certification is valid for 3 years, with surveillance audits required annually.

    Stage 1 Audit

    Typically 1-2 days

    Reviews your policies, procedures, AIMS documentation, and risk management framework.

    Stage 2 Audit

    Typically 3-9+ days

    Tests the operational effectiveness and implementation of controls in practice. Duration depends on scope.

    Maintenance

    3-year cycle

    Annual surveillance audits required, with a full recertification audit in Year 3.

    Preparing for ISO/IEC 42001 in 2026: Step-by-Step Checklist

    A practical, phased roadmap used by organizations implementing an AIMS.

    Phase 1 - Planning & Scoping

    • Inventory all AI systems and use cases in scope.
    • Secure leadership commitment and designate an AI governance lead (often the CISO or Chief AI Officer).
    • Define the AIMS scope and boundaries.
    • Engage an accredited certification body early for guidance.

    Phase 2 - Gap Assessment & Remediation

    • Conduct a gap analysis against the standard and Annex A controls.
    • Perform an AI risk assessment and impact analysis.
    • Develop or update required policies, procedures, and controls.
    • Implement technical and operational safeguards, including data quality processes and human oversight mechanisms.

    Phase 3 - Evidence, Internal Audit & Certification

    • Build a centralized evidence repository.
    • Deliver AI-specific training and awareness programs.
    • Conduct an internal audit and management review.
    • Undergo the two-stage external audit and address any nonconformities.

    Need an experienced AIMS implementer?

    We deliver gap analyses, policy packs, evidence collection automation, and audit support so your team can focus on building AI - not chasing documentation.

    Plan My ISO 42001 Project

    Typical ISO/IEC 42001 Certification Timeline (2026 Averages)

    Total time from kickoff to certificate typically ranges from 6-12 months depending on scope and maturity.

    PhaseDuration
    Planning & Gap Analysis1-2 months
    Policy & Control Implementation2-4 months
    Operation & Internal Audit1-2 months
    Certification Audits & Reporting4-8 weeks

    Pro Tip: If you already hold ISO 27001 certification, you can reuse approximately 50% of existing controls and documentation, shortening the timeline by 40-50%. Our compliance automation platform can reduce manual effort by up to 80% through automated evidence collection, risk tracking, and pre-built AIMS templates.

    Required Policies and Procedures for ISO/IEC 42001

    The standard requires documented information to support the AIMS. Policies must be living documents, reviewed annually, and tailored to your AI risk profile.

    Core Governance & Leadership

    • AI Policy (overall commitment and objectives).
    • Information Security Policy (extended for AI).
    • Risk Management & AI Impact Assessment Policy.
    • Roles, Responsibilities, and Authorities for AIMS.

    Operational & Technical

    • AI System Lifecycle Management Policy.
    • Data Governance & Quality Policy for AI Systems.
    • Transparency, Explainability & Human Oversight Policy.
    • Change Management & Configuration Policy for AI Systems.
    • Incident Response & AI Incident Management Plan.

    Third-Party & Continual Improvement

    • Third-Party / Supplier AI Risk Management Policy.
    • Monitoring, Measurement, Analysis & Evaluation Procedures.
    • Nonconformity, Corrective Action & Continual Improvement Policy.

    Our AI Transparency Guarantee

    Artificial Intelligence (AI) Usage and Accountability

    Brent Norris utilizes Artificial Intelligence (AI) and Large Language Models (LLMs) to accelerate engineering processes, structure compliance strategies, and draft technical blueprints. AI models do not possess professional licenses, certified security auditor credentials, or legal authority. Any architectural plans, code generation, or technical recommendations produced with AI assistance are treated as advanced drafts. Brent Norris assumes complete and final human accountability for all deployed systems. AI is not utilized as a replacement for certified security professionals or compliance officers. No client data or Protected Health Information (PHI) is ever entered into unauthorized or public AI models.

    Annex A: 9 Control Objectives

    Annex A provides 38 controls across 9 objectives. Organizations select those applicable to their AI systems via a Statement of Applicability. These controls must demonstrate both design and operational effectiveness during the Stage 2 audit.

    Control ObjectiveFocus Areas
    Internal OrganizationRoles, responsibilities, and AI governance.
    Resources for AI SystemsData, tools, and human resources.
    AI System Impact AssessmentRisk and societal impact evaluations.
    AI System Life CycleDesign, development, deployment, and monitoring.
    Data for AI SystemsQuality, traceability, and management.
    Information for Interested PartiesTransparency and communication.
    Responsible Use of AI SystemsEthical use and human oversight.
    Third-Party & Customer RelationshipsSupply chain and external AI dependencies.
    AI Incident ManagementResponse and continual improvement.

    Ready to operationalize Annex A?

    We translate the 9 control objectives into a tailored Statement of Applicability and turn each control into automated, audit-ready evidence.

    Book an Annex A Workshop

    Frequently asked questions

    Build Trustworthy AI - and Prove It

    ISO/IEC 42001 turns "responsible AI" from a marketing claim into an audited, certifiable practice. We help you get there with practical, automated, and integrated implementations that respect the work you've already done in SOC 2, HIPAA, HITRUST, and ISO 27001.

    Digital Business Systems and Design Architect specializing in AI strategy, security, data compliance, and strategic technology leadership.

    © 1998-2026 Brent Norris. All rights reserved.