Sentrix

Framework · ISO 42001

ISO 42001: the first AI management system standard

ISO/IEC 42001:2023: requirements for an AI management system for any organization that develops, provides or uses AI, on the Annex SL structure of ISO 27001.

ISO/IEC 42001:2023, published in December 2023, is the first international AI management system (AIMS) standard. It applies to any organization that develops, provides, or uses AI-based products and services, in any sector. It follows the same Annex SL structure as ISO 27001 and ISO 9001, making integration straightforward for organizations already certified.

Key facts

  • December 2023: publication of the first international standard dedicated to AI management systems.
  • Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, improvement.
  • Annex A: AI-specific controls covering data governance, model transparency, accountability, impact assessment, and AI provider risk.
  • Annex SL: structure shared with ISO 27001, enabling an integrated management system.

What ISO 42001 covers

ISO 42001 is structured around a plan-do-check-act cycle applied to AI systems. It requires organizations to define the scope of their AIMS, identify AI-related risks and impacts, establish governance structures, and demonstrate continual improvement. Annex A provides controls that go beyond traditional security: algorithmic transparency, data quality, and AI system impact assessment.

  1. Clause 4, context: AIMS scope, interested parties, internal and external issues
  2. Clause 5, leadership: AI policy, roles, accountability, board-level AI governance
  3. Clause 6, planning: AI risk assessment, AI system impact assessment, objectives
  4. Clause 7, support: resources, competence, awareness, AI-specific documentation
  5. Clause 8, operation: AI development and deployment controls, third-party AI provider management
  6. Clauses 9 and 10, evaluation and improvement: internal audit, management review, nonconformity, corrective action

What Sentrix provides for ISO 42001

Annex A controls

AI-specific controls pre-built: data governance, model transparency, AI system impact assessment, algorithmic accountability, and third-party AI provider risk.

AI system impact assessment

Clause 6 requires an impact assessment for every in-scope AI application. Sentrix provides structured templates pre-mapped to Annex A controls and cross-referenced to your risk register.

Third-party AI provider management

Clause 8 covers procurement and oversight of external AI tools, models, and platforms. Sentrix onboards AI vendors into your third-party risk program and tracks their posture continuously.

Audit-ready AIMS reporting

Sentrix generates the AI management system evidence package: clause-level coverage, Annex A control status, impact assessment records, and management review documentation ready for certification audits.

Crosswalks

  • ISO 27001: shared Annex SL structure; substantial overlap of the management system clauses, mapped from your existing program.
  • NIST AI RMF: both frameworks address the same AI governance challenges from complementary angles; organizations pursuing both satisfy them from a single evidence set.

Further reading

Third-party risk for AI vendor oversight.

See your ISO 42001 posture against your real AI systems.

Contact us

Frequently asked questions

Who does ISO 42001 apply to?
ISO/IEC 42001:2023 applies to any organization that develops, provides, or uses AI-based products and services, whatever its size or sector. It establishes the requirements for an AI Management System (AIMS) structured around a plan-do-check-act cycle: define the scope, identify AI-related risks and impacts, establish governance structures, and demonstrate continual improvement.
What is an AI system impact assessment?
Clause 6 requires an impact assessment for every in-scope AI system: its potential effects on individuals, groups and society, beyond traditional security risks. Annex A adds AI-specific controls on algorithmic transparency, data quality and accountability. Sentrix provides structured assessment templates, mapped to the Annex A controls and cross-referenced to your risk register.
Does an ISO 27001-certified organization start with a head start?
Yes. ISO 42001 follows the same Annex SL structure as ISO 27001 and ISO 9001: context, leadership, planning, support, operation, performance evaluation and improvement. Your ISMS clauses, internal audit, management review and nonconformity management serve as the base of the AI management system. Sentrix pre-maps your existing controls to the ISO 42001 clauses and shows what remains AI-specific.

Let's talk about your compliance program.

Last updated: 2026-09-17