Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
21 / 34

Chapter 19

19ISO 42001 from the Inside: The AI Management System

3 min read21 of 34Read it in the book · page 113

“Responsible AI is not a slogan on the website, but a system that is managed and audited.”

ISO/IEC 42001 was published in December 2023 as the first auditable, certifiable international standard for an AI management system (AIMS). It is aimed at every organisation that develops, provides or uses AI systems, from start-up to enterprise, and from the agency building an agent for a client to the studio using generative tools every day.

Why Responsible AI Matters in Modern Organisations

AI raises productivity and opens new doors for creativity, but it makes or influences decisions in ways that are sometimes hard to explain, and can repeat the biases of its data at scale. An organisation that governs its AI earns the trust of clients and regulators, avoids reputational harm, and prepares for legislation that widens every year.

Structure of the Standard

Structure of ISO 42001:2023: Clauses 4 to 10 and annexesStructure of ISO 42001:2023: Clauses 4 to 10 and annexes
Structure of ISO 42001:2023: Clauses 4 to 10 and annexes
Text in this figure

Context · Your AI role · Leadership · AI policy · Planning · Risk and impact · Support · Resources, skills · Operation · System life cycle · Evaluation · Monitor and audit · Improvement · Corrective action · Annexes A–D · 38 controls, guidance · Same clauses as ISO 27001, with AI-specific requirements in Clauses 4, 6 and 8 · Figure 24

  • Clause 4 · Context: Understanding the organisation and its role towards AI systems, interested parties, and the system scope.
  • Clause 5 · Leadership: The AI policy, roles and responsibilities, and management commitment.
  • Clause 6 · Planning: AI risks, their treatment, system impact assessment, and objectives.
  • Clause 7 · Support: Resources, competence, awareness, communication and documented information.
  • Clause 8 · Operation: Implementing the plans, and assessing risks and impact periodically.
  • Clause 9 · Performance evaluation: Monitoring, measurement, internal audit and management review.
  • Clause 10 · Improvement: Nonconformity, corrective action and continual improvement.

The clauses are followed by four annexes: Annex A with the reference controls, Annex B with guidance for implementing them, Annex C with potential objectives and risk sources, and Annex D on using the system across different sectors.

Context: What Is Your Role Towards AI?

Clause 4 requires the organisation to determine its role towards each AI system, because obligations differ by role. An agency may be a user of a generative tool and a producer of an agent it builds for a client at the same time.

Organisational roles towards an AI systemOrganisational roles towards an AI system
Organisational roles towards an AI system
Text in this figure

AI · System · Provider · Offers the system · Producer, developer · Builds and trains · Customer, user · Uses it at work · Partner · Data · tech · integration · Affected subject · Touched by outputs · Figure 25

RoleExample from the creative industries
AI providerA company offering an image generation platform to the public.
AI producerAn agency building a custom chat assistant for a client.
Customer or userA studio using a tool to write copy.
PartnerA data provider or systems integrator.
Affected subjectAn audience receiving an AI-personalised advert.

Leadership and the AI Policy

As in 27001, top management is accountable. The AI policy sets out the organisation’s commitment to responsible use and its principles (such as transparency, fairness and human oversight), and is linked to existing security and privacy policies. A clear role, an individual or a committee, is assigned for AI governance: approving new systems, reviewing impact assessments and deciding borderline cases.

2026 Update

In 2025, ISO/IEC 42005 was published with detailed guidance on AI system impact assessment, and ISO/IEC 42006 with requirements for bodies that audit and certify 42001. 42001 certifications have begun spreading quickly among AI service providers who want to prove responsibility to their clients.

ISO 42001 does not only ask: is your system secure? It asks: is it trustworthy?

Lessons Learned

  1. 1ISO 42001 is the first certifiable standard for managing AI.
  2. 2Its Clauses 4 to 10 follow the same harmonized structure as 27001.
  3. 3The role towards a system defines the obligations, and roles can overlap.
  4. 4The AI policy and its governance role are leadership’s responsibility.

Tip: use ← → to move between sections.