We built our rhythm with agile methodologies, hardened our systems with DevSecOps and established trust with ISO 27001. But AI carries risks that go beyond traditional data security: we are no longer merely protecting data; we are governing decisions, ethics and societal impact.
Your security framework is ready for data. But is it ready for AI?
This is where ISO/IEC 42001:2023, the first international standard for an AI management system, becomes our essential guide. In my book “AISEC Mastery”, I present it not as a compliance hurdle but as a strategic framework for mastering responsible innovation.
The AI Management System (AIMS)
The standard guides us in building an AI Management System (AIMS): a governance playbook that helps an organisation manage the unique risks and opportunities of AI across its entire life cycle.
- Protects the confidentiality, integrity and availability of information
- Assesses risks to information assets
- 93 controls in Annex A
- Governs the decisions of intelligent systems and their impact
- Assesses risks and impact on individuals and society
- 38 controls in Annex A
Rather than a dry list of clauses, let us look at the core pillars of a robust system:
Pillar 1: Strategic alignment and leadership
It begins with top management's commitment to a clear AI policy aligned with business objectives, and with understanding the organisation's context: are you a developer of AI, a user of it, or a provider? Then comes clearly defining governance roles and responsibilities. This is how strategic direction is set.
Pillar 2: Proactive risk and impact assessment
This is where ISO 42001 truly differs from traditional security: it requires assessing the technical and security risks of AI, and also assessing the system's impact on individuals and society. This pushes us to look beyond the code, towards global regulations and societal expectations, such as the EU AI Act, and local trust certifications such as the “Dubai AI Seal”. This proactive governance demands questions such as:
- Ethical implicationsCould our system lead to biased or unfair outcomes?
- Societal impactWhat is the potential impact on individuals and communities?
- TransparencyCan we explain how the system makes its decisions?
The aim is to manage risks before they turn into reputational crises, and to demonstrate verifiable compliance with leading global standards.
Pillar 3: Operational excellence and support
A strategy is only as good as its execution. This pillar ensures the right resources, competent teams and clear communication, and covers day-to-day operational controls and continuous performance monitoring through audits and reviews.
Pillar 4: Evolution and continual improvement
The world of AI is not static, and neither is the system that governs it. This pillar embeds a culture of continual improvement: managing “nonconformities” when things go wrong, and taking corrective actions that turn mistakes into lessons that strengthen governance over time.
- 1Act enters into forceAugust 2024
- 2Prohibited practices bannedplus the AI literacy requirementFebruary 2025
- 3General-purpose models (GPAI)Obligations for model providersAugust 2025
- 4Transparency obligationsArticle 50: disclosure and content labellingAugust 2026
- 5High-risk systemsUse cases in Annex IIIDecember 2027
- 6Regulated productsAnnex I systemsAugust 2028
Takeaways
- ISO 42001 governs decisions and impact, not data alone.
- Assessing impact on individuals and society is what sets AI governance apart.
- The EU postponement for high-risk systems is not a cancellation; the obligations remain.

