Catalog / ISO 42001

ISO 42001 ISO/IEC 42001:2023 · AI management

The AI management system standard: clauses 4–10 plus all 38 Annex A controls, from AI policy and impact assessment through the system life cycle, data provenance, and third-party responsibility.

9
domains
64
controls
143
tests the agent runs

Control catalog

AIMS Management System

MS · 26 controls
  • 4.1

    Understanding the organization and its context

    Internal and external issues relevant to the AIMS and its intended outcomes are identified and kept current.

  • 4.2

    Understanding the needs and expectations of interested parties

    Interested parties relevant to the AIMS and their requirements are identified.

  • 4.3

    Determining the scope of the AI management system

    The AIMS scope is documented, justified and consistent with the AI systems actually operated.

  • 4.4

    AI management system

    An AIMS is established, implemented, maintained and continually improved.

  • 5.1

    Leadership and commitment

    Top management demonstrates leadership and commitment to the AIMS.

  • 5.2

    AI policy

    An AI policy appropriate to the organisation's purpose is established and communicated.

  • 5.3

    Roles, responsibilities and authorities

    AIMS roles are assigned, communicated and understood.

  • 6.1.2

    AI risk assessment

    A repeatable AI risk assessment process is defined and applied.

  • 6.1.3

    AI risk treatment

    AI risks are treated, controls selected, and a Statement of Applicability produced.

  • 6.1.4

    AI system impact assessment

    The process for assessing AI system impacts is defined and integrated with risk management.

  • 6.2

    AI objectives and planning to achieve them

    Measurable AI objectives are set and planned.

  • 6.3

    Planning of changes

    Changes to the AIMS are planned rather than made ad hoc.

  • 7.1

    Resources

    Resources needed for the AIMS are determined and provided.

  • 7.2

    Competence

    People doing AIMS work are competent, and gaps are closed.

  • 7.3

    Awareness

    People are aware of the AI policy and their contribution to the AIMS.

  • 7.4

    Communication

    Internal and external AIMS communications are determined.

  • 7.5

    Documented information

    AIMS documented information is controlled.

  • 8.1

    Operational planning and control

    AIMS processes are planned, implemented and controlled in operation.

  • 8.2

    AI risk assessment (operation)

    AI risk assessments are performed at planned intervals and on significant change.

  • 8.3

    AI risk treatment (operation)

    The AI risk treatment plan is implemented.

  • 8.4

    AI system impact assessment (operation)

    Impact assessments are performed and retained for AI systems in scope.

  • 9.1

    Monitoring, measurement, analysis and evaluation

    AIMS performance and effectiveness are monitored and evaluated.

  • 9.2

    Internal audit

    Internal audits of the AIMS are planned and performed by objective auditors.

  • 9.3

    Management review

    Top management reviews the AIMS at planned intervals.

  • 10.1

    Continual improvement

    The AIMS is continually improved.

  • 10.2

    Nonconformity and corrective action

    Nonconformities are corrected, root causes addressed, and effectiveness reviewed.

A.2–A.3 AI Policy & Internal Organization

AG · 5 controls
  • A.2.2

    AI policy

    A documented AI policy exists and is approved by management.

  • A.2.3

    Alignment with other organizational policies

    The AI policy is aligned with other policies it touches.

  • A.2.4

    Review of the AI policy

    The AI policy is reviewed at planned intervals or on significant change.

  • A.3.2

    AI roles and responsibilities

    AI roles and responsibilities are defined and allocated.

  • A.3.3

    Reporting of concerns

    A route exists to report concerns about AI systems.

A.4 Resources for AI Systems

AR · 5 controls
  • A.4.2

    Resource documentation

    Resources for AI systems are identified and documented.

  • A.4.3

    Data resources

    Data resources used by AI systems are documented.

  • A.4.4

    Tooling resources

    Tooling used across the AI life cycle is documented.

  • A.4.5

    System and computing resources

    System and computing resources are documented.

  • A.4.6

    Human resources

    Human resources involved in the AI life cycle are documented, including competence.

A.5 Assessing Impacts of AI Systems

AI · 4 controls
  • A.5.2

    AI system impact assessment process

    A process exists to assess AI system impacts on individuals, groups and societies.

  • A.5.3

    Documentation of AI system impact assessments

    Impact assessment results are documented and retained.

  • A.5.4

    Assessing AI system impact on individuals or groups

    Impacts on individuals and groups are assessed throughout the life cycle.

  • A.5.5

    Assessing societal impacts of AI systems

    Societal impacts are assessed and documented.

A.6 AI System Life Cycle

AL · 9 controls
  • A.6.1.2

    Objectives for responsible development of AI system

    Objectives for responsible development are identified and documented.

  • A.6.1.3

    Processes for responsible design and development

    Processes for responsible design and development are defined and applied.

  • A.6.2.2

    AI system requirements and specification

    AI system requirements are specified, including non-functional and responsible-AI requirements.

  • A.6.2.3

    Documentation of AI system design and development

    Design and development are documented.

  • A.6.2.4

    AI system verification and validation

    Verification and validation measures are defined and performed.

  • A.6.2.5

    AI system deployment

    Deployment follows a documented plan with requirements met.

  • A.6.2.6

    AI system operation and monitoring

    AI systems are monitored in operation against defined measures.

  • A.6.2.7

    AI system technical documentation

    Technical documentation is produced for relevant interested parties.

  • A.6.2.8

    AI system recording of event logs

    AI systems record event logs automatically.

A.7 Data for AI Systems

AD · 5 controls
  • A.7.2

    Data for development and enhancement of AI system

    Data used for development is defined and documented.

  • A.7.3

    Acquisition of data

    Data acquisition is controlled, lawful and documented.

  • A.7.4

    Quality of data for AI systems

    Data quality requirements are defined and met.

  • A.7.5

    Data provenance

    Provenance of data is recorded and maintained.

  • A.7.6

    Data preparation

    Data preparation is defined and documented.

A.8 Information for Interested Parties

AT · 4 controls
  • A.8.2

    System documentation and information for users

    Users are given the information needed to use the system properly.

  • A.8.3

    External reporting

    A capability exists for interested parties to report adverse impacts.

  • A.8.4

    Communication of incidents

    AI incidents are communicated to users and relevant parties.

  • A.8.5

    Information for interested parties

    Obligations to report information to interested parties are identified and met.

A.9 Use of AI Systems

AU · 3 controls
  • A.9.2

    Processes for responsible use of AI systems

    Processes for responsible use are defined and applied.

  • A.9.3

    Objectives for responsible use of AI system

    Objectives for responsible use are identified and documented.

  • A.9.4

    Intended use of the AI system

    The system is used in accordance with its intended use and documentation.

A.10 Third-Party & Customer Relationships

AP · 3 controls
  • A.10.2

    Allocating responsibilities

    Responsibilities are allocated across the AI value chain.

  • A.10.3

    Suppliers

    Suppliers of AI services and components are managed against AIMS requirements.

  • A.10.4

    Customers

    Customer-facing AI obligations are understood and met.

See ISO 42001 tested against your evidence.