Catalog / ISO 42001
ISO 42001 ISO/IEC 42001:2023 · AI management
The AI management system standard: clauses 4–10 plus all 38 Annex A controls, from AI policy and impact assessment through the system life cycle, data provenance, and third-party responsibility.
- 9
- domains
- 64
- controls
- 143
- tests the agent runs
Control catalog
AIMS Management System
-
4.1Understanding the organization and its context
Internal and external issues relevant to the AIMS and its intended outcomes are identified and kept current.
-
4.2Understanding the needs and expectations of interested parties
Interested parties relevant to the AIMS and their requirements are identified.
-
4.3Determining the scope of the AI management system
The AIMS scope is documented, justified and consistent with the AI systems actually operated.
-
4.4AI management system
An AIMS is established, implemented, maintained and continually improved.
-
5.1Leadership and commitment
Top management demonstrates leadership and commitment to the AIMS.
-
5.2AI policy
An AI policy appropriate to the organisation's purpose is established and communicated.
-
5.3Roles, responsibilities and authorities
AIMS roles are assigned, communicated and understood.
-
6.1.2AI risk assessment
A repeatable AI risk assessment process is defined and applied.
-
6.1.3AI risk treatment
AI risks are treated, controls selected, and a Statement of Applicability produced.
-
6.1.4AI system impact assessment
The process for assessing AI system impacts is defined and integrated with risk management.
-
6.2AI objectives and planning to achieve them
Measurable AI objectives are set and planned.
-
6.3Planning of changes
Changes to the AIMS are planned rather than made ad hoc.
-
7.1Resources
Resources needed for the AIMS are determined and provided.
-
7.2Competence
People doing AIMS work are competent, and gaps are closed.
-
7.3Awareness
People are aware of the AI policy and their contribution to the AIMS.
-
7.4Communication
Internal and external AIMS communications are determined.
-
7.5Documented information
AIMS documented information is controlled.
-
8.1Operational planning and control
AIMS processes are planned, implemented and controlled in operation.
-
8.2AI risk assessment (operation)
AI risk assessments are performed at planned intervals and on significant change.
-
8.3AI risk treatment (operation)
The AI risk treatment plan is implemented.
-
8.4AI system impact assessment (operation)
Impact assessments are performed and retained for AI systems in scope.
-
9.1Monitoring, measurement, analysis and evaluation
AIMS performance and effectiveness are monitored and evaluated.
-
9.2Internal audit
Internal audits of the AIMS are planned and performed by objective auditors.
-
9.3Management review
Top management reviews the AIMS at planned intervals.
-
10.1Continual improvement
The AIMS is continually improved.
-
10.2Nonconformity and corrective action
Nonconformities are corrected, root causes addressed, and effectiveness reviewed.
A.2–A.3 AI Policy & Internal Organization
-
A.2.2AI policy
A documented AI policy exists and is approved by management.
-
A.2.3Alignment with other organizational policies
The AI policy is aligned with other policies it touches.
-
A.2.4Review of the AI policy
The AI policy is reviewed at planned intervals or on significant change.
-
A.3.2AI roles and responsibilities
AI roles and responsibilities are defined and allocated.
-
A.3.3Reporting of concerns
A route exists to report concerns about AI systems.
A.4 Resources for AI Systems
-
A.4.2Resource documentation
Resources for AI systems are identified and documented.
-
A.4.3Data resources
Data resources used by AI systems are documented.
-
A.4.4Tooling resources
Tooling used across the AI life cycle is documented.
-
A.4.5System and computing resources
System and computing resources are documented.
-
A.4.6Human resources
Human resources involved in the AI life cycle are documented, including competence.
A.5 Assessing Impacts of AI Systems
-
A.5.2AI system impact assessment process
A process exists to assess AI system impacts on individuals, groups and societies.
-
A.5.3Documentation of AI system impact assessments
Impact assessment results are documented and retained.
-
A.5.4Assessing AI system impact on individuals or groups
Impacts on individuals and groups are assessed throughout the life cycle.
-
A.5.5Assessing societal impacts of AI systems
Societal impacts are assessed and documented.
A.6 AI System Life Cycle
-
A.6.1.2Objectives for responsible development of AI system
Objectives for responsible development are identified and documented.
-
A.6.1.3Processes for responsible design and development
Processes for responsible design and development are defined and applied.
-
A.6.2.2AI system requirements and specification
AI system requirements are specified, including non-functional and responsible-AI requirements.
-
A.6.2.3Documentation of AI system design and development
Design and development are documented.
-
A.6.2.4AI system verification and validation
Verification and validation measures are defined and performed.
-
A.6.2.5AI system deployment
Deployment follows a documented plan with requirements met.
-
A.6.2.6AI system operation and monitoring
AI systems are monitored in operation against defined measures.
-
A.6.2.7AI system technical documentation
Technical documentation is produced for relevant interested parties.
-
A.6.2.8AI system recording of event logs
AI systems record event logs automatically.
A.7 Data for AI Systems
-
A.7.2Data for development and enhancement of AI system
Data used for development is defined and documented.
-
A.7.3Acquisition of data
Data acquisition is controlled, lawful and documented.
-
A.7.4Quality of data for AI systems
Data quality requirements are defined and met.
-
A.7.5Data provenance
Provenance of data is recorded and maintained.
-
A.7.6Data preparation
Data preparation is defined and documented.
A.8 Information for Interested Parties
-
A.8.2System documentation and information for users
Users are given the information needed to use the system properly.
-
A.8.3External reporting
A capability exists for interested parties to report adverse impacts.
-
A.8.4Communication of incidents
AI incidents are communicated to users and relevant parties.
-
A.8.5Information for interested parties
Obligations to report information to interested parties are identified and met.
A.9 Use of AI Systems
-
A.9.2Processes for responsible use of AI systems
Processes for responsible use are defined and applied.
-
A.9.3Objectives for responsible use of AI system
Objectives for responsible use are identified and documented.
-
A.9.4Intended use of the AI system
The system is used in accordance with its intended use and documentation.
A.10 Third-Party & Customer Relationships
-
A.10.2Allocating responsibilities
Responsibilities are allocated across the AI value chain.
-
A.10.3Suppliers
Suppliers of AI services and components are managed against AIMS requirements.
-
A.10.4Customers
Customer-facing AI obligations are understood and met.