Framework · ISO 42001
ISO 42001: the first AI management system standard
ISO/IEC 42001:2023: requirements for an AI management system for any organization that develops, provides or uses AI, on the Annex SL structure of ISO 27001.
ISO/IEC 42001:2023, published in December 2023, is the first international AI management system (AIMS) standard. It applies to any organization that develops, provides, or uses AI-based products and services, in any sector. It follows the same Annex SL structure as ISO 27001 and ISO 9001, making integration straightforward for organizations already certified.
Key facts
- December 2023: publication of the first international standard dedicated to AI management systems.
- Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, improvement.
- Annex A: AI-specific controls covering data governance, model transparency, accountability, impact assessment, and AI provider risk.
- Annex SL: structure shared with ISO 27001, enabling an integrated management system.
What ISO 42001 covers
ISO 42001 is structured around a plan-do-check-act cycle applied to AI systems. It requires organizations to define the scope of their AIMS, identify AI-related risks and impacts, establish governance structures, and demonstrate continual improvement. Annex A provides controls that go beyond traditional security: algorithmic transparency, data quality, and AI system impact assessment.
- Clause 4, context: AIMS scope, interested parties, internal and external issues
- Clause 5, leadership: AI policy, roles, accountability, board-level AI governance
- Clause 6, planning: AI risk assessment, AI system impact assessment, objectives
- Clause 7, support: resources, competence, awareness, AI-specific documentation
- Clause 8, operation: AI development and deployment controls, third-party AI provider management
- Clauses 9 and 10, evaluation and improvement: internal audit, management review, nonconformity, corrective action
What Sentrix provides for ISO 42001
Annex A controls
AI-specific controls pre-built: data governance, model transparency, AI system impact assessment, algorithmic accountability, and third-party AI provider risk.
AI system impact assessment
Clause 6 requires an impact assessment for every in-scope AI application. Sentrix provides structured templates pre-mapped to Annex A controls and cross-referenced to your risk register.
Third-party AI provider management
Clause 8 covers procurement and oversight of external AI tools, models, and platforms. Sentrix onboards AI vendors into your third-party risk program and tracks their posture continuously.
Audit-ready AIMS reporting
Sentrix generates the AI management system evidence package: clause-level coverage, Annex A control status, impact assessment records, and management review documentation ready for certification audits.
Crosswalks
- ISO 27001: shared Annex SL structure; substantial overlap of the management system clauses, mapped from your existing program.
- NIST AI RMF: both frameworks address the same AI governance challenges from complementary angles; organizations pursuing both satisfy them from a single evidence set.
Further reading
Third-party risk for AI vendor oversight.
See your ISO 42001 posture against your real AI systems.
Frequently asked questions
- Who does ISO 42001 apply to?
- ISO/IEC 42001:2023 applies to any organization that develops, provides, or uses AI-based products and services, whatever its size or sector. It establishes the requirements for an AI Management System (AIMS) structured around a plan-do-check-act cycle: define the scope, identify AI-related risks and impacts, establish governance structures, and demonstrate continual improvement.
- What is an AI system impact assessment?
- Clause 6 requires an impact assessment for every in-scope AI system: its potential effects on individuals, groups and society, beyond traditional security risks. Annex A adds AI-specific controls on algorithmic transparency, data quality and accountability. Sentrix provides structured assessment templates, mapped to the Annex A controls and cross-referenced to your risk register.
- Does an ISO 27001-certified organization start with a head start?
- Yes. ISO 42001 follows the same Annex SL structure as ISO 27001 and ISO 9001: context, leadership, planning, support, operation, performance evaluation and improvement. Your ISMS clauses, internal audit, management review and nonconformity management serve as the base of the AI management system. Sentrix pre-maps your existing controls to the ISO 42001 clauses and shows what remains AI-specific.
Related pages
Framework · NIST AI RMF
NIST AI RMF: the risk framework for trustworthy AI
The NIST AI Risk Management Framework, version 1.0 of January 2023: four functions, Govern, Map, Measure, Manage, across the full AI lifecycle in any sector.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Let's talk about your compliance program.
Last updated: 2026-09-17
