ISO 42001
The second standard, on the same terms.
ISO/IEC 42001:2023 is the AI management system standard. Its clauses 4 to 10 are the Harmonized Structure — the same spine as ISO 27001, which is why building one gets you most of the way to the other, and why StandardOS runs both rather than being a 27001 tool with a second product bolted on. Where 42001 departs it departs substantially — the AI system impact assessment has no counterpart in 27001 at all — and this page names those places rather than glossing them.
28
covered
1
limit no tool removes
All 28 clauses have a place in the product, and each row below says where. That is not the same as being ready: an auditor tests what you have written, not what the software can hold, and an empty register in a covered clause passes nothing. Clause 5.1 is the honest edge — we can assemble the evidence that leadership committed, and we cannot be the commitment. The same page lives inside the product, counting what you have actually written against each clause, which is the number that decides your audit.
4 — Context of the organization
- 4.1Covered
Understanding the organization and what surrounds it
- 4.2Covered
Who has an interest, and what they require
- 4.3Covered
Deciding what the AI management system covers
- 4.4Covered
The management system and the processes that make it up
5 — Leadership
- 5.1Covered
Leadership actually owning the system
Every demonstration the clause asks for is assembled from records held elsewhere in the management system, so the evidence is produced rather than asserted. No software can show that top management personally did any of it — your auditor establishes that by interviewing them, and no tool in this market changes that.
- 5.2Covered
An AI policy
- 5.3Covered
Who is responsible for what, and with what authority
6 — Planning
- 6.1.1Covered
Acting on risks and on opportunities
- 6.1.2Covered
How AI risk is assessed, including harm beyond your organization
- 6.1.3Covered
Choosing controls and stating which apply
- 6.1.4Covered
Assessing what an AI system does to the people it touches
- 6.2Covered
AI objectives and how they will be met
- 6.3Covered
Planning changes to the management system
7 — Support
- 7.1Covered
The resources the management system needs
- 7.2Covered
Competence, and evidence of it
- 7.3Covered
Making people aware
- 7.4Covered
Communicating about the AI management system
- 7.5Covered
Controlling documented information
8 — Operation
- 8.1Covered
Planning and controlling how the system runs
- 8.2Covered
Assessing AI risk at planned intervals, and when things change
- 8.3Covered
Carrying out the AI risk treatment plan
- 8.4Covered
Carrying out the impact assessment, and keeping the result
9 — Performance evaluation
- 9.1Covered
Monitoring, measuring, analysing and evaluating
- 9.2.1Covered
Running internal audits
- 9.2.2Covered
The audit programme behind those audits
- 9.3Covered
Management review
10 — Improvement
- 10.1Covered
Continual improvement
- 10.2Covered
Nonconformity and corrective action
Clause numbers are exact. The descriptions are our own wording — ISO's text is copyrighted and is not reproduced here. Buy the standard from ISO or your national body to read it in full.