ISO/IEC 42001:2023
ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard.
ISO/IEC 42001:2023 is a compliance framework from International with 17 domains and 83 controls that map to 67 other frameworks. The largest domains are Annex A AIMS controls - A.6 AI system life cycle (9 controls), Clause A – ISO/IEC 42001:2023 (9 controls), Performance evaluation – ISO/IEC 42001:2023 (8 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Annex A AIMS controls - A.10 Third-party and customer relationships
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.10.2 | Allocating responsibilities |
| iso-iec-42001-2023::A.10.3 | Suppliers |
| iso-iec-42001-2023::A.10.4 | Customers |
Annex A AIMS controls - A.2 Policies related to AI
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.2.2 | AI policy |
| iso-iec-42001-2023::A.2.3 | Alignment with other organizational policies |
| iso-iec-42001-2023::A.2.4 | Review of the AI policy |
Annex A AIMS controls - A.3 Internal organization
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.3.2 | AI roles and responsibilities |
| iso-iec-42001-2023::A.3.3 | Reporting of concerns |
Annex A AIMS controls - A.4 Resources for AI systems
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.4.2 | Resource documentation |
| iso-iec-42001-2023::A.4.3 | Data resources |
| iso-iec-42001-2023::A.4.4 | Tooling resources |
| iso-iec-42001-2023::A.4.5 | System and computing resources |
| iso-iec-42001-2023::A.4.6 | Human resources |
Annex A AIMS controls - A.5 Assessing impacts of AI systems
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.5.2 | AI system impact assessment process |
| iso-iec-42001-2023::A.5.3 | Documentation of AI system impact assessments |
| iso-iec-42001-2023::A.5.4 | Assessing AI system impact on individuals or groups |
| iso-iec-42001-2023::A.5.5 | Assessing societal impacts of AI systems |
Annex A AIMS controls - A.6 AI system life cycle
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.6.1.2 | Objectives for responsible development of AI systems |
| iso-iec-42001-2023::A.6.1.3 | Processes for responsible design and development of AI systems |
| iso-iec-42001-2023::A.6.2.2 | AI system requirements and specification |
| iso-iec-42001-2023::A.6.2.3 | Documentation of AI system design and development |
| iso-iec-42001-2023::A.6.2.4 | AI system verification and validation |
| iso-iec-42001-2023::A.6.2.5 | AI system deployment |
| iso-iec-42001-2023::A.6.2.6 | AI system operation and monitoring |
| iso-iec-42001-2023::A.6.2.7 | AI system technical documentation |
| iso-iec-42001-2023::A.6.2.8 | AI system event logging |
Annex A AIMS controls - A.7 Data for AI systems
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.7.2 | Data for development and enhancement of AI systems |
| iso-iec-42001-2023::A.7.3 | Acquisition of data |
| iso-iec-42001-2023::A.7.4 | Quality of data for AI systems |
| iso-iec-42001-2023::A.7.5 | Data provenance |
| iso-iec-42001-2023::A.7.6 | Data preparation |
Annex A AIMS controls - A.8 Information for interested parties of AI systems
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.8.2 | System documentation and information for users |
| iso-iec-42001-2023::A.8.3 | External reporting |
| iso-iec-42001-2023::A.8.4 | Communication of incidents |
| iso-iec-42001-2023::A.8.5 | Information for interested parties |
Annex A AIMS controls - A.9 Use of AI systems
| Code | Title |
|---|---|
| iso-iec-42001-2023::A.9.2 | Processes for responsible use of AI systems |
| iso-iec-42001-2023::A.9.3 | Objectives for responsible use of AI system |
| iso-iec-42001-2023::A.9.4 | Intended use of the AI system |
Clause A – ISO/IEC 42001:2023
Context of the organization – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::4.1 | Understanding the organization and its context |
| iso-iec-42001-2023::4.2 | Understanding the needs and expectations of interested parties |
| iso-iec-42001-2023::4.3 | Determining the scope of the management system |
| iso-iec-42001-2023::4.4 | Management system |
Improvement – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::10.1 | Continual improvement |
| iso-iec-42001-2023::10.2 | Nonconformity and corrective action |
Leadership – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::5.1 | Leadership and commitment |
| iso-iec-42001-2023::5.2 | Policy |
| iso-iec-42001-2023::5.3 | Roles, responsibilities and authorities |
Operation – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::8.1 | Operational planning and control |
| iso-iec-42001-2023::8.2 | AI risk assessment |
| iso-iec-42001-2023::8.3 | AI risk treatment |
| iso-iec-42001-2023::8.4 | AI system impact assessment |
Performance evaluation – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::9.1 | Monitoring, measurement, analysis and evaluation |
| iso-iec-42001-2023::9.2 | Internal audit |
| iso-iec-42001-2023::9.2.1 | General |
| iso-iec-42001-2023::9.2.2 | Internal audit programme |
| iso-iec-42001-2023::9.3 | Management review |
| iso-iec-42001-2023::9.3.1 | General |
| iso-iec-42001-2023::9.3.2 | Management review inputs |
| iso-iec-42001-2023::9.3.3 | Management review results |
Planning – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::6.1 | Actions to address risks and opportunities |
| iso-iec-42001-2023::6.1.1 | General |
| iso-iec-42001-2023::6.1.2 | Risk assessment |
| iso-iec-42001-2023::6.1.3 | Risk treatment |
| iso-iec-42001-2023::6.1.4 | AI system impact assessment |
| iso-iec-42001-2023::6.2 | Objectives and planning to achieve them |
| iso-iec-42001-2023::6.3 | Planning of changes |
Support – ISO/IEC 42001:2023
| Code | Title |
|---|---|
| iso-iec-42001-2023::7.1 | Resources |
| iso-iec-42001-2023::7.2 | Competence |
| iso-iec-42001-2023::7.3 | Awareness |
| iso-iec-42001-2023::7.4 | Communication |
| iso-iec-42001-2023::7.5 | Documented information |
| iso-iec-42001-2023::7.5.1 | General |
| iso-iec-42001-2023::7.5.2 | Creating and updating |
| iso-iec-42001-2023::7.5.3 | Control of documented information |
Your Compliance Coverage
If you comply with ISO/IEC 42001:2023, you already cover:
NIST AI Risk Management Framework (AI RMF 1.0)
100%
38 controls mapped
Compare →EU AI Act
100%
38 controls mapped
Compare →ISO 27001:2022
87%
33 controls mapped
Compare →+ 64 more: ISO 27002:2022 (84%), NIST SP 800-53 Rev 5 (82%)
See all 67 mapped frameworks ↓Maps to 67 other frameworks
What is ISO/IEC 42001:2023 and who does it apply to?
ISO/IEC 42001:2023 is a compliance framework from International with 17 domains and 83 controls. ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 42001:2023 actually require?
ISO/IEC 42001:2023 has 83 controls organised across 17 domains. The largest domains are Annex A AIMS controls - A.6 AI system life cycle (9 controls), Clause A – ISO/IEC 42001:2023 (9 controls), Performance evaluation – ISO/IEC 42001:2023 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 42001:2023 do I already cover?
ISO/IEC 42001:2023 maps to 67 other compliance frameworks. The top mapping partners are NIST AI Risk Management Framework (AI RMF 1.0) (100% coverage), EU AI Act (100% coverage), ISO 27001:2022 (87% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 42001:2023?
Start your ISO/IEC 42001:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 42001:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 83 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required