What is ISO/IEC 42001?
By Identra · Updated
ISO/IEC 42001 is an international standard that sets requirements for an artificial intelligence management system (AIMS). It gives an organization a structure for assigning responsibility, managing AI risks and impacts, and continually improving how it develops, provides or uses AI.
What does an AI management system cover?
An AIMS is the set of policies, roles, processes and records an organization uses to govern AI. It fits a company that only buys AI as well as one that builds it. And it reaches past security into reliability, transparency and effects on people. ISO's standard overview describes the scope.
You choose the boundary. One company scopes it to its internal coding assistant program. Another scopes it to building and running a customer support bot. Write the boundary down plainly, because customers and auditors will read it.
For a CISO the payoff is AI governance you can trace. Who approved this use case, what risk they accepted, when it gets looked at again.
How does ISO/IEC 42001 work in practice?
It follows the same management-system structure as ISO/IEC 27001. Set policy and objectives, assess risk, apply controls, measure, fix what is broken. Leadership owns direction and resourcing. Engineers supply evidence of how the systems actually behave. Annex A lists reference controls, and you record which ones apply in a statement of applicability.
Risk assessment and impact assessment run side by side. AI risk management asks what could go wrong and how to treat it. The AI system impact assessment asks what the system could do to individuals, groups and society. A hiring assistant can save recruiters real time and still screen out qualified applicants unfairly.
Assessments go stale. New data sources, new users or new authority to act should send one back for review. A pilot with one friendly team tells you little about a company-wide rollout.
How is ISO/IEC 42001 different from ISO/IEC 27001?
27001 is about information security, meaning confidentiality, integrity and availability. 42001 is about managing AI, including the harm a system can do with no attacker anywhere in the picture. They overlap wherever AI handles sensitive data. See ISO's information security overview.
Reuse what you already run for 27001. Training, document control, internal audit and management review all carry over. Then add the AI assessments and the operating evidence. A 27001 certificate does not make you conformant with 42001, and it does not work the other way either.
Management focus
- ISO/IEC 42001
- Responsible development, provision and use of AI
- ISO/IEC 27001
- Security of information
Example assessment question
- ISO/IEC 42001
- Could an AI recommendation lead to an unfair or harmful decision?
- ISO/IEC 27001
- Could unauthorized access expose or alter protected information?
Shared machinery
- ISO/IEC 42001
- Accountability, risk treatment, evaluation, improvement
- ISO/IEC 27001
- Accountability, risk treatment, evaluation, improvement
What does ISO/IEC 42001 look like for a real AI use case?
Say a support team adds an assistant that drafts replies from Zendesk tickets. The owner defines the use. It suggests text and a person sends it. Security checks which ticket data the assistant can reach. Privacy and the service owner look at data handling and what a wrong answer costs.
Treatments might include limiting it to approved help-center articles, blocking access to other customers' tickets and making a human press send. Testing covers a ticket with planted instructions, an answer with no source behind it and an attempt to pull another customer's data. Those are the team's choices. ISO does not prescribe a configuration.
Then someone asks for the assistant to issue refunds. It is a different system now. It changes records and moves money. Reassess, apply least privilege to the payment access and decide where human approval sits. Keep the assessment, the approval, the test results and the new restrictions on file.
How should security teams prepare for ISO/IEC 42001?
Begin with real use cases and leave the audit binder for later. Compare the approved list against what turns up in browsers, on laptops and in connected SaaS and cloud tenants. Shadow AI will surface tools that need an assessment or a scope decision.
- Name an accountable owner for each in-scope use case. Record purpose, users, data sources, suppliers and permitted actions.
- Write the acceptable use and approval rules. Employees should know which data is off limits and who to ask.
- Assess risks and impacts. Record assumptions, chosen controls, residual risk and who accepted it.
- Test controls against realistic failures such as unauthorized data access, misleading output and unsafe actions.
- Keep evidence that controls run: approvals, configuration records, training records, exceptions, corrective actions.
- After a change or incident, assign remediation and check the fix actually worked.
What does ISO/IEC 42001 certification prove?
That an independent certification body assessed the management system within its stated scope. ISO writes the standard but does not certify anyone. Certification says nothing about whether a particular model output or agent action is safe.
Reviewing a supplier? Read the scope on the certificate and check that the service you are buying sits inside it. Ask how responsibilities split between you and them. Their certificate does not cover your deployment, your data access or how your staff use the product.
An AI audit trail helps with evidence. Logs on their own will not show an auditor a working management system. They want to see the decision, what happened next, what failed and what changed.
How Identra thinks about it
Identra shows which AI apps, accounts and agents are in use across browsers, endpoints and connected identity, SaaS and cloud services. Every AI agent run on an endpoint is recorded with the user, device, AI client and whether it was allowed or blocked. That record is operating evidence an AI governance review can sample.
Go deeper: AI security, built on identity
Frequently asked questions
Can a company that only uses third-party AI adopt ISO/IEC 42001?
Yes. The standard covers organizations that develop, provide or use AI. A company that only buys AI still governs its own use cases, access, data handling and responsibilities.
Is certification required to use the standard?
No. You can implement the management system without seeking certification. Certification adds independent assessment for customers or regulators who want it.
Does ISO/IEC 42001 prescribe a specific security product?
No. Organizations choose controls that fit their context and risks. Buying a tool does not make the management system conformant.
Can existing ISO/IEC 27001 audit evidence be reused?
Yes, where it applies to the AI management system's scope and requirements. Shared training, access review and corrective action records help, but they do not replace AI-specific assessments and decisions.
Is an AI inventory enough to prepare for an audit?
No. An inventory shows what needs governing. Auditors also look for evidence of responsibility, assessment, implementation, evaluation and improvement.
