OnwynStandards › ISO/IEC 42001:2023

Certifiable standard · 2023

ISO/IEC 42001:2023

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence: it structures how an organization governs the AI systems it develops or uses — responsibly, transparently, and with managed risk. It matters for companies building AI products, for those deploying AI in sensitive processes, and increasingly as supporting evidence for EU AI Act readiness. The structure mirrors ISO 27001: management-system clauses 4-10 plus an Annex A control catalogue, so companies with an existing ISMS can extend rather than start over.

18
Requirements
7
Areas
15
Recommended documents
3
Mapped frameworks
Start ISO/IEC 42001:2023 free Have us do it instead

What this standard asks for

Every requirement in ISO/IEC 42001:2023, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

AI management system (clauses 4-10)

7 requirements

  • 4Context of the organization and AIMS scope
  • 5Leadership, AI policy and roles
  • 6Planning — AI risks, opportunities and objectives
  • 7Support — resources, competence, awareness and documentation
  • 8Operation — running AI risk and impact processes
  • 9Performance evaluation — monitoring, audit and management review
  • 10Improvement — nonconformity and continual improvement

AI governance & policy

2 requirements

  • A.2AI policy implementation
  • A.3Internal organization and accountability for AI

Resources & data

2 requirements

  • A.4Resources for AI systems — data, tooling, and people
  • A.7Data management for AI systems

Impact assessment

1 requirement

  • A.5AI system impact assessment

AI system life cycle

2 requirements

  • A.6AI system life cycle management
  • A.6.2Operation, monitoring and event logging of AI systems

Transparency & human oversight

2 requirements

  • A.8Information for interested parties
  • A.9Responsible use and human oversight

Third parties & suppliers

2 requirements

  • A.10Third-party and supplier management for AI
  • A.10.2AI systems acquired from or provided to customers

The documents you will end up with

The recommended document set for ISO/IEC 42001:2023 — 15 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

AIMS Scope Statement

Which AI systems, teams and activities the AI management system covers, and the internal and external context behind that boundary.

AI Policy

The organisation's stated position on how it builds and uses AI, approved at the top and translated into rules people can follow.

AI Roles and Accountability

Who owns AI decisions, which committee or forum resolves them, and how that connects to existing governance.

AI Risk Assessment and Objectives Plan

How AI risks and opportunities are assessed and treated, and the objectives the management system is aiming at.

AIMS Support and Documentation Procedure

The people, tooling and computing resources AI work depends on, the competence expected of those roles, and how AIMS documents are controlled.

AI Operational Planning and Control Procedure

How the risk and impact processes are actually triggered and run as AI work moves through the organisation.

AIMS Monitoring, Audit and Review Procedure

What you measure about the AI management system, how it is audited internally, and what leadership reviews.

Nonconformity and Improvement Procedure

How gaps in the AI management system get recorded, fixed at root and closed.

AI Data Management Policy

Where training and operating data comes from, how its quality and provenance are checked, and what may not be used.

AI System Impact Assessment Procedure

When a system needs an impact assessment, what it must consider about individuals, groups and society, and who signs it off.

AI System Life Cycle Standard

The gates an AI system passes through from idea to retirement: objectives, design, verification, deployment and decommissioning.

AI Operation and Event Logging Standard

How live AI systems are monitored, what is logged about their behaviour, and how long those records are kept.

Information for Interested Parties

What you tell users, customers and affected people about how the AI works, its limits, and how to raise a concern.

Responsible Use and Human Oversight Policy

The uses that are approved, the uses that are off-limits, and how a human stays able to intervene where it matters.

AI Supplier and Customer Requirements

What you require of AI vendors and model providers, and what you commit to when your own AI is supplied to customers.

Work that counts twice

ISO/IEC 42001:2023 overlaps with 3 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start ISO/IEC 42001:2023 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.