ISO/IEC 42001 explained: the AI management system standard
ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence: it sets out how an organisation governs the AI it develops or uses, through scope, policy, roles, risk and impact assessment, a statement of applicability over 38 Annex A controls, monitoring, internal audit and management review.
Updated: 8 September 2026
The standard
What ISO/IEC 42001 is
ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system — a way of organising how a company decides what AI it uses, on what basis, with which safeguards, and who is accountable. It follows the same harmonised structure as ISO/IEC 27001 and ISO 9001, so an organisation that already runs one of those will recognise the shape immediately: the same clause numbering, the same rhythm of plan, operate, check, improve.
What it is not: a technical specification for models, a safety test, or a substitute for the law. It says nothing about which algorithm you may use. It asks whether you can show that you decided deliberately and are watching the result. That distinction is what separates it from the EU AI Act, which does set legal requirements for particular systems and particular uses.
The management system, on screen
Where the AIMS actually lives once you stop reading about it: the document pyramid, the requirements reference and the reports it produces.
The document pyramid
Four levels from policy down to records, exactly as ISO/IEC 42001 expects them, with a saved count on every tile that already has content.
In your own words
Both frameworks side by side as a searchable reference, summarised rather than quoted, plus the organisation-wide statement of applicability kept in one place.
One button, three reports
Compliance report, dossier and statement of applicability generate per system, plus a management report and training record that cover the whole organisation.
What the standard requires: clauses 4 to 10
The requirements sit in clauses 4 to 10. In everyday terms:
- Clause 4 — work out where AI touches your organisation, who has a stake in it, and where you draw the boundary of the management system.
- Clause 5 — leadership has to own it: a policy, assigned roles, and a decision that this is a management responsibility rather than an IT side project.
- Clause 6 — assess and treat AI risks, set objectives, and record in a statement of applicability which Annex A controls apply and why.
- Clause 7 — resources, competence, awareness, and the documented information the rest of the system rests on.
- Clause 8 — run it: operational planning and control, plus the assessments the standard expects before and during use.
- Clause 9 — monitor and measure, audit internally, and review at management level on a fixed rhythm.
- Clause 10 — handle what did not work and improve it, in a way that leaves a trace.
Nothing in that list is exotic. What makes it work is doing it once properly and then keeping it current — which is exactly the part that fails when it lives in a folder of Word documents.
The 38 Annex A controls
Annex A of ISO/IEC 42001:2023 holds 38 reference controls, grouped under nine control objectives numbered A.2 to A.10. The statement of applicability required by clause 6.1.3 records, for every one of those controls, whether it applies, why, and how far it is implemented. It is the document an auditor reaches for first, because it shows in one view what you decided and what you left out.
| Objective | Subject | Controls |
|---|---|---|
| A.2 | Policy for the use of AI | 3 |
| A.3 | Roles and internal organisation | 2 |
| A.4 | Resources: data, tooling, computing, people | 5 |
| A.5 | Impact assessment for individuals and society | 4 |
| A.6 | The life cycle of an AI system | 9 |
| A.7 | Data used to build and run AI | 5 |
| A.8 | Information for the parties concerned | 4 |
| A.9 | Responsible use of AI systems | 3 |
| A.10 | Suppliers, customers and shared responsibility | 3 |
| A.2–A.10 | Nine control objectives | 38 |
The subjects in the middle column are TSMONDO wording, not the headings of the standard. ISO/IEC 42001 is copyrighted, so this page carries control identifiers and counts only. The counts were checked against published Annex A control lists at control-identifier level on 19 August 2026.
Two practical points. A control you exclude is not a gap — an exclusion with a stated reason is a legitimate outcome, and pretending everything applies makes the system heavier without making it better. And the statement of applicability belongs to the organisation, not to a single AI project: it is maintained once and referenced from every project, otherwise the versions drift apart within a quarter.
ISO/IEC 42001 and the EU AI Act
The EU AI Act says what must be achieved; ISO/IEC 42001 gives it an organisational structure. A 42001 certificate does not create a presumption of conformity with the regulation. They are separate instruments with a large practical overlap.
The overlap is where the work is saved. Risk management under Article 9 of the regulation and the risk clause of the standard ask for the same discipline in different words. Human oversight, record-keeping, data governance and post-market monitoring all have a counterpart in the management system. Building the two separately means writing the same thing twice and letting the copies diverge; building them once, with a mapping between them, is the difference between maintenance and a second project.
Presumption of conformity under the AI Act comes from harmonised standards, and those are still being finalised. Regulation (EU) 2026/1744, the digital omnibus on artificial intelligence, has been in force since 27 July 2026 and moved the application of the high-risk rules in Chapter III, Sections 1 to 3, to 2 December 2027 for the systems listed in Annex III of the AI Act and to 2 August 2028 for high-risk AI inside the regulated products of Annex I. Until those dates, 42001 remains an organisational structure, not a legal shortcut. If you are weighing which of the two to build on, the comparison sits on the AI governance page.
Certification: what it involves
A certificate is issued by an accredited certification body, not by a consultancy and not by a piece of software. The usual sequence is a gap analysis against the standard, a period of running the system so that there are records to look at, a stage one review of the documentation, and a stage two audit of the practice, followed by surveillance in later years.
Costs vary too much by size, scope and body for a number on this page to be honest. The drivers are consistent, though: how many AI use cases fall inside the scope, how much evidence already exists in a usable form, and how much of the documentation has to be written from scratch. The first and third of those are the ones you can influence before you ask for a quote.
Who needs ISO/IEC 42001
No law requires ISO/IEC 42001. In practice it is asked for by three groups: customers who have put AI governance into their supplier questionnaires, regulated organisations that have to show a system rather than good intentions, and boards that want one answer to how AI is being used in the house.
It pays off in organisations with several AI use cases spread across departments, at least one of which touches people directly — recruitment, credit, health, education, public administration. At that point the informal route stops working: two teams answer the same customer questionnaire differently, and nobody can say which model version was in use when a decision was made.
Organisations with a single, well-understood AI tool rarely need a full management system on day one. A documented decision on scope, a short risk assessment and a named owner will carry them further than a certification project. The standard becomes worth the effort when the number of use cases, or the number of people who may start one, grows beyond what one person can hold in their head.
From reading to doing
The searches around this standard are mostly for a checklist, a controls list, a gap analysis or a documentation toolkit. That instinct is right: the work is largely structure and evidence. Two things are worth knowing before you pick any of them.
- Nobody may hand you the text of the standard. ISO/IEC 42001 is copyrighted and has to be licensed from ISO or a national standards body. A tool that reproduces it is a problem, not a feature — and TSMONDO does not do it. The AI Manager works with clause and control identifiers and its own wording.
- A spreadsheet is a snapshot; a management system is a state. The clause-9 rhythm — monitoring, internal audit, management review — is where spreadsheets quietly die. Whatever you use has to carry dates and owners, not just rows.
The TSMONDO AI Manager is the tool built for that documentation work. It runs on your own machine without a cloud account and covers scope and context, policy and roles, an AI risk register per use case, a statement of applicability across the 38 Annex A controls, dates and named owners for the clause-9 activities, and a conformity report per AI system derived from the mapping between the regulation and the standard. It brings 30 document templates, 8 training modules and 46 example use cases from 12 areas of a business, so the first pass over scope starts from a list rather than a blank page. The details sit on the AI Manager page; the drafting help it uses is described under the local AI assistant.
The clause reference inside the tool
The reference built into the AI Manager now lists every clause of the standard rather than a selection: all seven main chapters with 32 sections, plus the 38 Annex A controls — 70 clauses in all. Earlier versions carried four chapters with 11 sections and left the rest out. Each of the 70 has a note on how the tool implements it: which tab, which step, and what that step produces. Each also takes a named reviewer and a review interval, and those dates run into the deadline calendar — so the person answerable for a clause is recorded in the same place as the documents that answer it.
Three of the additions in the current version land on clauses rather than beside them. An organisation-wide register of open items — what came up in operation, in a review, after an incident — carries the audit findings and corrective actions that clauses 9.2 and 10.2 ask about, and produces the record from them. Every document now has a version, a status of draft, approved or needs revision, the name of whoever approved it and the date, and a date for the next review: control of documented information under clause 7.5. And training is recorded participant by participant, with a refresher proposed after a year, instead of one field for the whole company — which is the evidence clause 7.2 asks for on competence.
For 15 of those 70 clauses the note says the opposite: the software offers nothing of its own. The ones an auditor reaches for early are among them — measurement with a history (9.1), the internal audit programme (9.2), the management review (9.3), and developing your own models (Annex A.6). The AI Manager maps the structure and builds the documentation; it does not keep a metrics history, does not run an audit programme and does not hold a management review for you. That work stays with the organisation, in whatever tool it already uses. No document tool covers ISO/IEC 42001 completely — the question worth putting to any vendor is where the tool stops, and whether it tells you before a stage two audit does.
In practice: TSMONDO works on ISO/IEC 42001 with DFMG Deutsche Funkturm, named with permission. The AI Manager does not reproduce the text of the standard, does not issue a certificate, and does not replace a certification audit or legal advice.
How to start
Four decisions come before the first document of the management system is written. Each one is cheap to make now and expensive to revise once the documentation exists, because a change of scope or of certification intent reaches back into every record already produced.
- List the AI in use first — scope decisions made before you know what is in the house get redone.
- Decide whether you are aiming at a certificate — it changes how much formality is worth it, and it is cheaper to decide early than to retrofit.
- Write the statement of applicability early, not last — it forces the decisions that otherwise stay vague.
- Put dates on the clause-9 activities immediately — a management system without a calendar is a document set.
Frequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system. It sets out how an organisation governs its use of AI: scope, policy, roles, risk assessment and treatment, a statement of applicability, operation, monitoring, internal audit and management review.
How many controls does Annex A of ISO/IEC 42001 contain?
Annex A of ISO/IEC 42001:2023 contains 38 reference controls, grouped under nine control objectives numbered A.2 to A.10: three under A.2, two under A.3, five under A.4, four under A.5, nine under A.6, five under A.7, four under A.8, three under A.9 and three under A.10. Which of them apply to a given organisation is decided and recorded in the statement of applicability under clause 6.1.3.
Is ISO/IEC 42001 mandatory?
No. It is a voluntary standard. The EU AI Act is the binding instrument; 42001 is a way of organising the work it requires, and is often asked for by customers, insurers or a company's own board.
Does ISO/IEC 42001 certification make me compliant with the EU AI Act?
No. A certificate does not create a presumption of conformity with the regulation. Presumption of conformity comes from harmonised standards, which are still being finalised. Regulation (EU) 2026/1744 moved the high-risk rules of Chapter III to 2 December 2027 for Annex III systems and to 2 August 2028 for high-risk AI in the regulated products of Annex I. The two instruments overlap substantially in practice, but they remain separate.
What is the statement of applicability?
The document required by clause 6.1.3 that records, for each of the 38 Annex A controls, whether it applies, the justification for that decision, and how far it is implemented. It belongs to the organisation as a whole rather than to a single AI project, and it is usually the first thing an auditor asks for.
How is ISO/IEC 42001 related to ISO/IEC 27001?
They share the harmonised management-system structure, so clauses 4 to 10 line up and an existing information security management system can be extended rather than duplicated. The subject matter differs: 27001 governs information security, 42001 governs the use of artificial intelligence.
Can software cover ISO/IEC 42001 for me?
Not completely, and a tool that claims otherwise is worth a second look. The TSMONDO AI Manager maps the structure and builds the documentation: its built-in reference carries all seven main chapters with 32 sections and the 38 Annex A controls, 70 clauses in all, each with a note on how the tool implements it and each with a named reviewer and a review interval that feeds the deadline calendar. For 15 of those 70 the note states that the software offers nothing of its own — among them measurement with a history under 9.1, the internal audit programme under 9.2, the management review under 9.3, and developing your own models under Annex A.6. That part stays organisational work.
Built by one specialist, not resold as a platform
One point of contact with the papers to match
- ISO 27001 Lead Auditor and Lead Implementer
- ISACA CISM (Certified Information Security Manager)
- Certified data protection officer and IT security officer (TÜV)
- Member of the Alliance for Cyber Security (BSI, Germany)
Organisations already working with it
- Industry, media, healthcare, the public sector and digital platforms
- On security, NIS2 and data protection
- Named only with permission — full list at tsmondo.de/referenzen
Try it first, decide afterwards
- 21 days, no registration and no cloud account
- Runs locally on Windows; nothing is sent anywhere
- Your inventory, classifications and evidence stay on your own machine
- If it does not fit, delete the folder — nothing is left behind
Priced by company size, not per seat
- From EUR 499 per year or EUR 49 per month, both net
- One licence per company, unlimited users at every site — the price band follows the number of employees
- Monthly subscription cancellable from the end of the current month, annual with one month's notice
- Reverse charge applies for businesses in other EU member states with a valid VAT identification number
Local · no cloud · no data passed to third parties · built by an ISO 27001 Lead Auditor and ISACA CISM. This offer is addressed exclusively to businesses; there is no right of withdrawal. Our terms and conditions apply.
Where to go next
The EU AI Act is the binding instrument, ISO/IEC 42001 is the management-system structure that goes with it. Both pages set out the requirements; the AI Manager is the tool TSMONDO builds for the documentation work behind them.