ISO/IEC 42001:2023
ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
Annex A AIMS controls - A.10 Third-party and customer relationships
| Code | Title |
|---|---|
| A.10.2 | Confidentiality obligations of personnel |
| A.10.3 | Restriction of creation of hardcopy material |
| A.10.4 | Control and logging of data restoration |
Annex A AIMS controls - A.2 Policies related to AI
| Code | Title |
|---|---|
| A.2.2 | AI policy |
| A.2.3 | Alignment with other organizational policies |
| A.2.4 | Review of the AI policy |
Annex A AIMS controls - A.3 Internal organization
| Code | Title |
|---|---|
| A.3.2 | AI roles and responsibilities |
| A.3.3 | Reporting of concerns |
Annex A AIMS controls - A.4 Resources for AI systems
| Code | Title |
|---|---|
| A.4.2 | Resource documentation |
| A.4.3 | Data resources |
| A.4.4 | Tooling resources |
| A.4.5 | System and computing resources |
| A.4.6 | Human resources |
Annex A AIMS controls - A.5 Assessing impacts of AI systems
| Code | Title |
|---|---|
| A.5.2 | AI system impact assessment process |
| A.5.3 | Documentation of AI system impact assessments |
| A.5.4 | Assessing AI system impact on individuals or groups |
| A.5.5 | Assessing societal impacts of AI systems |
Annex A AIMS controls - A.6 AI system life cycle
| Code | Title |
|---|---|
| A.6.1.1 | Objectives for responsible development of AI systems |
| A.6.1.2 | Processes for responsible AI system design and development |
| A.6.2.2 | AI system requirements and specification |
| A.6.2.3 | Documentation of AI system design and development |
| A.6.2.4 | AI system verification and validation |
| A.6.2.5 | AI system deployment |
| A.6.2.6 | AI system operation and monitoring |
| A.6.2.7 | AI system technical documentation |
| A.6.2.8 | AI system event logging |
Annex A AIMS controls - A.7 Data for AI systems
| Code | Title |
|---|---|
| A.7.2 | Data for development and enhancement of AI systems |
| A.7.3 | Acquisition of data |
| A.7.4 | Quality of data for AI systems |
| A.7.5 | Data provenance |
| A.7.6 | Data preparation |
Annex A AIMS controls - A.8 Information for interested parties of AI systems
| Code | Title |
|---|---|
| A.8.2 | System documentation and information for users |
| A.8.3 | External reporting |
| A.8.4 | Communication of incidents |
| A.8.5 | Information for interested parties |
Annex A AIMS controls - A.9 Use of AI systems
| Code | Title |
|---|---|
| A.9.2 | Processes for responsible use of AI systems |
| A.9.3 | Objectives for responsible use of AI system |
| A.9.4 | Intended use of the AI system |
Annex SL management section
Clause A – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.10 | Third-party and customer relationships |
| iso-iec-42001-2023::A.2 | Policies related to AI |
| iso-iec-42001-2023::A.3 | Internal organization |
| iso-iec-42001-2023::A.4 | Resources for AI systems |
| iso-iec-42001-2023::A.5 | Assessing impacts of AI systems |
| iso-iec-42001-2023::A.6 | AI system life cycle |
| iso-iec-42001-2023::A.7 | Data for AI systems |
| iso-iec-42001-2023::A.8 | Information for interested parties of AI systems |
| iso-iec-42001-2023::A.9 | Use of AI systems |
Context of the organization – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::4.1 | Understanding the organization and its context |
| iso-iec-42001-2023::4.2 | Understanding the needs and expectations of interested parties |
| iso-iec-42001-2023::4.3 | Determining the scope of the management system |
| iso-iec-42001-2023::4.4 | Management system |
Improvement – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::10.1 | Continual improvement |
| iso-iec-42001-2023::10.2 | Nonconformity and corrective action |
Leadership – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::5.1 | Leadership and commitment |
| iso-iec-42001-2023::5.2 | Policy |
| iso-iec-42001-2023::5.3 | Roles, responsibilities and authorities |
Operation – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::8.1 | Operational planning and control |
| iso-iec-42001-2023::8.2 | AI system impact assessment |
| iso-iec-42001-2023::8.3 | AI system lifecycle management |
| iso-iec-42001-2023::8.4 | Data for AI systems |
| iso-iec-42001-2023::8.5 | Information for interested parties of AI systems |
| iso-iec-42001-2023::8.6 | Use of AI systems |
| iso-iec-42001-2023::8.7 | Third-party and customer relationships |
Performance evaluation – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::9.1 | Monitoring, measurement, analysis and evaluation |
| iso-iec-42001-2023::9.2 | Internal audit |
| iso-iec-42001-2023::9.3 | Management review |
Planning – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::6.1 | Actions to address risks and opportunities |
| iso-iec-42001-2023::6.1.1 | General |
| iso-iec-42001-2023::6.1.2 | Risk assessment |
| iso-iec-42001-2023::6.1.3 | Risk treatment |
| iso-iec-42001-2023::6.1.4 | AI system impact assessment |
| iso-iec-42001-2023::6.2 | Objectives and planning to achieve them |
Support – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::7.1 | Resources |
| iso-iec-42001-2023::7.2 | Competence |
| iso-iec-42001-2023::7.3 | Awareness |
| iso-iec-42001-2023::7.4 | Communication |
| iso-iec-42001-2023::7.5 | Documented information |
| iso-iec-42001-2023::7.5.1 | General |
| iso-iec-42001-2023::7.5.2 | Creating and updating |
| iso-iec-42001-2023::7.5.3 | Control of documented information |
Your Compliance Coverage
If you comply with ISO/IEC 42001:2023, you already cover:
ISO 22301:2019
41%
33 controls mapped
Compare →ISO 9001:2015
39%
31 controls mapped
Compare →ISO 22000:2018
39%
31 controls mapped
Compare →+ 122 more: ISO 14001:2015 (38%), ISO 37001:2016 (38%)
See all 125 mapped frameworks ↓Maps to 125 other frameworks
Frequently Asked Questions
What is ISO/IEC 42001:2023?
ISO/IEC 42001:2023 is a compliance framework from International with 18 domains and 80 controls. ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 42001:2023 have?
ISO/IEC 42001:2023 has 80 controls organised across 18 domains. The largest domains are Annex A AIMS controls - A.6 AI system life cycle (9 controls), Clause A – ISO/IEC 42001:2023 (9 controls), Support – ISO/IEC 42001:2023 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 42001:2023 map to?
ISO/IEC 42001:2023 maps to 125 other compliance frameworks. The top mapping partners are ISO 22301:2019 (41% coverage), ISO 9001:2015 (39% coverage), ISO 22000:2018 (39% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 42001:2023 compliance?
Start your ISO/IEC 42001:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 42001:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 80 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required