Skip to content

ISO/IEC 42001 mapping

  • Draft
  • v0.3.0
  • Compliance, legal, privacy, and assurance teams
  • Reviewed 2026-09-28

Informative mapping only

This page traces the framework's architecture capabilities and evidence to an external source. It is not legal advice, and it is not an audit, a certification, an authorization or a conformity assessment. Mapping a capability does not show that a control is implemented or effective.

Confirm applicability, edition and dates against the authoritative source, and obtain review from qualified legal, compliance, security, privacy and audit professionals before relying on it. Standards text is copyrighted: this page gives identifiers and short titles only, so obtain the licensed standard for the full requirements.

ISO/IEC 42001:2023 sets requirements for an AI management system (AIMS). An organization uses it to govern how it develops, provides or uses AI systems, and an accredited body can certify that management system. This framework does not certify anything. It supplies architecture and operational evidence that an AIMS can reference.

Item Value
Standard ISO/IEC 42001:2023, Information technology: Artificial intelligence: Management system
Edition 1.0, published 2023-12-18, by ISO/IEC JTC 1/SC 42
Structure Clauses 4 to 10 are requirements. Annex A lists 38 reference controls in 9 control objectives. Annex B gives implementation guidance for them.
Certification Accredited certification bodies audit against ISO/IEC 42006:2025
Last checked 2026-09-28

Management system clauses

Clauses 4 to 10 follow the harmonized structure that other ISO management system standards use, such as ISO/IEC 27001. Teams that already run an information security management system can extend it rather than build a second one.

Clause Requirement area Framework alignment Example evidence
4 Context of the organization Internal and external issues, interested parties, AIMS scope Enterprise Context Architecture context domains, stakeholder and affected-party analysis Context register, AIMS scope statement, interested-party register
5 Leadership Commitment, AI policy (5.2), roles and authorities (5.3) Operating model, policies Approved AI policy, charters, RACI
6 Planning AI risk assessment (6.1.2), AI risk treatment (6.1.3), AI system impact assessment (6.1.4), AI objectives (6.2) Risk management, risk tiering, impact assessment Risk register, treatment plan, statement of applicability, impact assessments, measurable objectives
7 Support Resources, competence, awareness, communication, documented information Capability model, roles and accountability Skills records, training records, communication plan, document control
8 Operation Operational planning and control, and running the assessments from clause 6 (8.2 to 8.4) Lifecycle gates, specification-driven delivery, supplier governance Design records, evaluations, gate approvals, supplier contracts
9 Performance evaluation Monitoring and measurement (9.1), internal audit (9.2), management review (9.3) Outcome and harm indicators, independent assurance Dashboards, audit reports, management review minutes
10 Improvement Continual improvement, nonconformity and corrective action Incident handling, AI incident response, lessons learned Corrective actions, root-cause analyses, change history

Annex A controls

Annex A is a reference set. An organization selects the controls its risk treatment needs, and records each inclusion or exclusion with a justification in its statement of applicability (6.1.3).

Objective Controls Framework alignment Example evidence
A.2 Policies related to AI A.2.2 AI policy; A.2.3 Alignment with other organizational policies; A.2.4 Review of the AI policy Policies AI policy, policy crosswalk, review records
A.3 Internal organization A.3.2 AI roles and responsibilities; A.3.3 Reporting of concerns Operating model, roles and accountability RACI, concern-reporting channel and records
A.4 Resources for AI systems A.4.2 Resource documentation; A.4.3 Data resources; A.4.4 Tooling resources; A.4.5 System and computing resources; A.4.6 Human resources Capability model, system inventory Component inventory, data and tool registers, staffing plan
A.5 Assessing impacts of AI systems A.5.2 AI system impact assessment process; A.5.3 Documentation of AI system impact assessments; A.5.4 Assessing AI system impact on individuals or groups of individuals; A.5.5 Assessing societal impacts of AI systems Risk management, impact assessment Impact assessment procedure and records (ISO/IEC 42005 gives guidance)
A.6 AI system life cycle A.6.1.2 Objectives for responsible development of AI system; A.6.1.3 Processes for responsible AI system design and development; A.6.2.2 AI system requirements and specification; A.6.2.3 Documentation of AI system design and development; A.6.2.4 AI system verification and validation; A.6.2.5 AI system deployment; A.6.2.6 AI system operation and monitoring; A.6.2.7 AI system technical documentation; A.6.2.8 AI system recording of event logs Specification-driven delivery, lifecycle gates, evaluation service Specifications, design records, evaluation reports, deployment approvals, monitoring plan, technical documentation, logging design
A.7 Data for AI systems A.7.2 Data for development and enhancement of AI system; A.7.3 Acquisition of data; A.7.4 Quality of data for AI systems; A.7.5 Data provenance; A.7.6 Data preparation Data protection, information context Data sheets, acquisition terms, quality analysis, lineage records, preparation steps
A.8 Information for interested parties of AI systems A.8.2 System documentation and information for users; A.8.3 External reporting; A.8.4 Communication of incidents; A.8.5 Information for interested parties Transparency notices, AI incident response User documentation, system cards, external reports, incident notices
A.9 Use of AI systems A.9.2 Processes for responsible use of AI systems; A.9.3 Objectives for responsible use of AI system; A.9.4 Intended use of the AI system Intended and prohibited use in the context record, human oversight design Acceptable-use rules, intended-use statement, oversight records
A.10 Third-party and customer relationships A.10.2 Allocation of responsibilities; A.10.3 Suppliers; A.10.4 Customers Supplier model, supply-chain controls in the threat model Responsibility matrix, supplier assessments, customer terms

Annex C lists possible AI-related organizational objectives and risk sources, such as fairness, transparency, safety, privacy and robustness. Annex D describes use of the management system across domains and sectors.

Standard Use it for
ISO/IEC 22989:2022 AI concepts and terminology
ISO/IEC 23894:2023 Guidance on AI risk management
ISO/IEC 5338:2023 AI system life cycle processes
ISO/IEC 42005:2025 (published 2025-05-28) Guidance on AI system impact assessment, which supports 6.1.4 and A.5
ISO/IEC 42006:2025 (published 2025-07-07) Requirements for bodies that audit and certify an AIMS
ISO/IEC 27001:2022 Information security management, which shares the clause structure

Sources

Checked 2026-09-28.

The clause and control titles above are short identifiers. Read the licensed standard for the requirements themselves.