ISO 42001

The second standard, on the same terms.

ISO/IEC 42001:2023 is the AI management system standard. Its clauses 4 to 10 are the Harmonized Structure — the same spine as ISO 27001, which is why building one gets you most of the way to the other, and why StandardOS runs both rather than being a 27001 tool with a second product bolted on. Where 42001 departs it departs substantially — the AI system impact assessment has no counterpart in 27001 at all — and this page names those places rather than glossing them.

28

covered

1

limit no tool removes

All 28 clauses have a place in the product, and each row below says where. That is not the same as being ready: an auditor tests what you have written, not what the software can hold, and an empty register in a covered clause passes nothing. Clause 5.1 is the honest edge — we can assemble the evidence that leadership committed, and we cannot be the commitment. The same page lives inside the product, counting what you have actually written against each clause, which is the number that decides your audit.

4 — Context of the organization

  • 4.1

    Understanding the organization and what surrounds it

    Covered
  • 4.2

    Who has an interest, and what they require

    Covered
  • 4.3

    Deciding what the AI management system covers

    Covered
  • 4.4

    The management system and the processes that make it up

    Covered

5 — Leadership

  • 5.1

    Leadership actually owning the system

    Every demonstration the clause asks for is assembled from records held elsewhere in the management system, so the evidence is produced rather than asserted. No software can show that top management personally did any of it — your auditor establishes that by interviewing them, and no tool in this market changes that.

    Covered
  • 5.2

    An AI policy

    Covered
  • 5.3

    Who is responsible for what, and with what authority

    Covered

6 — Planning

  • 6.1.1

    Acting on risks and on opportunities

    Covered
  • 6.1.2

    How AI risk is assessed, including harm beyond your organization

    Covered
  • 6.1.3

    Choosing controls and stating which apply

    Covered
  • 6.1.4

    Assessing what an AI system does to the people it touches

    Covered
  • 6.2

    AI objectives and how they will be met

    Covered
  • 6.3

    Planning changes to the management system

    Covered

7 — Support

  • 7.1

    The resources the management system needs

    Covered
  • 7.2

    Competence, and evidence of it

    Covered
  • 7.3

    Making people aware

    Covered
  • 7.4

    Communicating about the AI management system

    Covered
  • 7.5

    Controlling documented information

    Covered

8 — Operation

  • 8.1

    Planning and controlling how the system runs

    Covered
  • 8.2

    Assessing AI risk at planned intervals, and when things change

    Covered
  • 8.3

    Carrying out the AI risk treatment plan

    Covered
  • 8.4

    Carrying out the impact assessment, and keeping the result

    Covered

9 — Performance evaluation

  • 9.1

    Monitoring, measuring, analysing and evaluating

    Covered
  • 9.2.1

    Running internal audits

    Covered
  • 9.2.2

    The audit programme behind those audits

    Covered
  • 9.3

    Management review

    Covered

10 — Improvement

  • 10.1

    Continual improvement

    Covered
  • 10.2

    Nonconformity and corrective action

    Covered

Clause numbers are exact. The descriptions are our own wording — ISO's text is copyrighted and is not reproduced here. Buy the standard from ISO or your national body to read it in full.