ISO/IEC 42001:2023
ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Annex A AIMS controls - A.10 Third-party and customer relationships
| Code | Title |
|---|---|
| A.10.2 | Confidentiality obligations of personnel |
| A.10.3 | Restriction of creation of hardcopy material |
| A.10.4 | Control and logging of data restoration |
Annex A AIMS controls - A.2 Policies related to AI
| Code | Title |
|---|---|
| A.2.2 | AI policy |
| A.2.3 | Alignment with other organizational policies |
| A.2.4 | Review of the AI policy |
Annex A AIMS controls - A.3 Internal organization
| Code | Title |
|---|---|
| A.3.2 | AI roles and responsibilities |
| A.3.3 | Reporting of concerns |
Annex A AIMS controls - A.4 Resources for AI systems
| Code | Title |
|---|---|
| A.4.2 | Resource documentation |
| A.4.3 | Data resources |
| A.4.4 | Tooling resources |
| A.4.5 | System and computing resources |
| A.4.6 | Human resources |
Annex A AIMS controls - A.5 Assessing impacts of AI systems
| Code | Title |
|---|---|
| A.5.2 | AI system impact assessment process |
| A.5.3 | Documentation of AI system impact assessments |
| A.5.4 | Assessing AI system impact on individuals or groups |
| A.5.5 | Assessing societal impacts of AI systems |
Annex A AIMS controls - A.6 AI system life cycle
| Code | Title |
|---|---|
| A.6.1.1 | Objectives for responsible development of AI systems |
| A.6.1.2 | Processes for responsible AI system design and development |
| A.6.2.2 | AI system requirements and specification |
| A.6.2.3 | Documentation of AI system design and development |
| A.6.2.4 | AI system verification and validation |
| A.6.2.5 | AI system deployment |
| A.6.2.6 | AI system operation and monitoring |
| A.6.2.7 | AI system technical documentation |
| A.6.2.8 | AI system event logging |
Annex A AIMS controls - A.7 Data for AI systems
| Code | Title |
|---|---|
| A.7.2 | Data for development and enhancement of AI systems |
| A.7.3 | Acquisition of data |
| A.7.4 | Quality of data for AI systems |
| A.7.5 | Data provenance |
| A.7.6 | Data preparation |
Annex A AIMS controls - A.8 Information for interested parties of AI systems
| Code | Title |
|---|---|
| A.8.2 | System documentation and information for users |
| A.8.3 | External reporting |
| A.8.4 | Communication of incidents |
| A.8.5 | Information for interested parties |
Annex A AIMS controls - A.9 Use of AI systems
| Code | Title |
|---|---|
| A.9.2 | Processes for responsible use of AI systems |
| A.9.3 | Objectives for responsible use of AI system |
| A.9.4 | Intended use of the AI system |
Annex SL management section
| Code | Title |
|---|---|
| 10.1 | Risk monitoring and review |
| 10.2 | Risk reporting |
| 4.1 | Password Policy |
| 4.2 | Multi-Factor Authentication |
| 4.3 | Determining Scope of SMS |
| 4.4 | Service Management System |
| 5.1 | Logical Access Control |
| 5.2 | Token Management |
| 5.3 | Determining and Evaluating Audit Programme Risks |
| 6.1.1 | Information security roles and responsibilities (cloud guidance) |
| 6.1.2 | Environmental Aspects |
| 6.1.3 | Compliance Obligations |
| 6.1.4 | Planning Action |
| 6.2 | Approach selection |
| 6.3 | Information security awareness, education and training |
| 7.1 | Cyber Incident Response Planning |
| 7.2 | Security Training and Awareness |
| 7.3 | Risk evaluation |
| 7.4 | Asset valuation |
| 7.5 | Threat assessment |
| 8.1 | Risk treatment selection |
| 8.2 | Risk treatment plan |
| 8.3 | Statement of Applicability linkage |
| 8.4 | Residual risk acceptance |
| 9.1 | Risk communication and consultation |
| 9.2 | Internal Audit |
| 9.3 | Management Review |
Your Compliance Coverage
If you comply with ISO/IEC 42001:2023, you already cover:
SWIFT CSCF
12%
8 controls mapped
Compare →CIS Controls v8
12%
8 controls mapped
Compare →NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
12%
8 controls mapped
Compare →+ 566 more: ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence (12%), AS9100D - Aerospace Quality Management System (12%)
See all 569 mapped frameworks ↓Maps to 569 other frameworks
Frequently Asked Questions
What is ISO/IEC 42001:2023?
ISO/IEC 42001:2023 is a compliance framework from International with 10 domains and 65 controls. ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 42001:2023 have?
ISO/IEC 42001:2023 has 65 controls organised across 10 domains. The largest domains are Annex SL management section (27 controls), Annex A AIMS controls - A.6 AI system life cycle (9 controls), Annex A AIMS controls - A.4 Resources for AI systems (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 42001:2023 map to?
ISO/IEC 42001:2023 maps to 569 other compliance frameworks. The top mapping partners are SWIFT CSCF (12% coverage), CIS Controls v8 (12% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 42001:2023 compliance?
Start your ISO/IEC 42001:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 42001:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 65 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required