Back to Frameworks

ISO/IEC 42001:2023

International
v2023
17 domains
83 controls

ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard.

Verified

ISO/IEC 42001:2023 is a compliance framework from International with 17 domains and 83 controls that map to 67 other frameworks. The largest domains are Annex A AIMS controls - A.6 AI system life cycle (9 controls), Clause A – ISO/IEC 42001:2023 (9 controls), Performance evaluation – ISO/IEC 42001:2023 (8 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

Annex A AIMS controls - A.10 Third-party and customer relationships

3 controls
Controls in the Annex A AIMS controls - A.10 Third-party and customer relationships domain of ISO/IEC 42001:20233 controls
CodeTitle
iso-iec-42001-2023::A.10.2Allocating responsibilities
iso-iec-42001-2023::A.10.3Suppliers
iso-iec-42001-2023::A.10.4Customers

Annex A AIMS controls - A.2 Policies related to AI

3 controls
Controls in the Annex A AIMS controls - A.2 Policies related to AI domain of ISO/IEC 42001:20233 controls
CodeTitle
iso-iec-42001-2023::A.2.2AI policy
iso-iec-42001-2023::A.2.3Alignment with other organizational policies
iso-iec-42001-2023::A.2.4Review of the AI policy

Annex A AIMS controls - A.3 Internal organization

2 controls
Controls in the Annex A AIMS controls - A.3 Internal organization domain of ISO/IEC 42001:20232 controls
CodeTitle
iso-iec-42001-2023::A.3.2AI roles and responsibilities
iso-iec-42001-2023::A.3.3Reporting of concerns

Annex A AIMS controls - A.4 Resources for AI systems

5 controls
Controls in the Annex A AIMS controls - A.4 Resources for AI systems domain of ISO/IEC 42001:20235 controls
CodeTitle
iso-iec-42001-2023::A.4.2Resource documentation
iso-iec-42001-2023::A.4.3Data resources
iso-iec-42001-2023::A.4.4Tooling resources
iso-iec-42001-2023::A.4.5System and computing resources
iso-iec-42001-2023::A.4.6Human resources

Annex A AIMS controls - A.5 Assessing impacts of AI systems

4 controls
Controls in the Annex A AIMS controls - A.5 Assessing impacts of AI systems domain of ISO/IEC 42001:20234 controls
CodeTitle
iso-iec-42001-2023::A.5.2AI system impact assessment process
iso-iec-42001-2023::A.5.3Documentation of AI system impact assessments
iso-iec-42001-2023::A.5.4Assessing AI system impact on individuals or groups
iso-iec-42001-2023::A.5.5Assessing societal impacts of AI systems

Annex A AIMS controls - A.6 AI system life cycle

9 controls
Controls in the Annex A AIMS controls - A.6 AI system life cycle domain of ISO/IEC 42001:20239 controls
CodeTitle
iso-iec-42001-2023::A.6.1.2Objectives for responsible development of AI systems
iso-iec-42001-2023::A.6.1.3Processes for responsible design and development of AI systems
iso-iec-42001-2023::A.6.2.2AI system requirements and specification
iso-iec-42001-2023::A.6.2.3Documentation of AI system design and development
iso-iec-42001-2023::A.6.2.4AI system verification and validation
iso-iec-42001-2023::A.6.2.5AI system deployment
iso-iec-42001-2023::A.6.2.6AI system operation and monitoring
iso-iec-42001-2023::A.6.2.7AI system technical documentation
iso-iec-42001-2023::A.6.2.8AI system event logging

Annex A AIMS controls - A.7 Data for AI systems

5 controls
Controls in the Annex A AIMS controls - A.7 Data for AI systems domain of ISO/IEC 42001:20235 controls
CodeTitle
iso-iec-42001-2023::A.7.2Data for development and enhancement of AI systems
iso-iec-42001-2023::A.7.3Acquisition of data
iso-iec-42001-2023::A.7.4Quality of data for AI systems
iso-iec-42001-2023::A.7.5Data provenance
iso-iec-42001-2023::A.7.6Data preparation

Annex A AIMS controls - A.8 Information for interested parties of AI systems

4 controls
Controls in the Annex A AIMS controls - A.8 Information for interested parties of AI systems domain of ISO/IEC 42001:20234 controls
CodeTitle
iso-iec-42001-2023::A.8.2System documentation and information for users
iso-iec-42001-2023::A.8.3External reporting
iso-iec-42001-2023::A.8.4Communication of incidents
iso-iec-42001-2023::A.8.5Information for interested parties

Annex A AIMS controls - A.9 Use of AI systems

3 controls
Controls in the Annex A AIMS controls - A.9 Use of AI systems domain of ISO/IEC 42001:20233 controls
CodeTitle
iso-iec-42001-2023::A.9.2Processes for responsible use of AI systems
iso-iec-42001-2023::A.9.3Objectives for responsible use of AI system
iso-iec-42001-2023::A.9.4Intended use of the AI system

Clause A – ISO/IEC 42001:2023

9 controls

Context of the organization – ISO/IEC 42001:2023

4 controls
Controls in the Context of the organization – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20234 controls
CodeTitle
iso-iec-42001-2023::4.1Understanding the organization and its context
iso-iec-42001-2023::4.2Understanding the needs and expectations of interested parties
iso-iec-42001-2023::4.3Determining the scope of the management system
iso-iec-42001-2023::4.4Management system

Improvement – ISO/IEC 42001:2023

2 controls
Controls in the Improvement – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20232 controls
CodeTitle
iso-iec-42001-2023::10.1Continual improvement
iso-iec-42001-2023::10.2Nonconformity and corrective action

Leadership – ISO/IEC 42001:2023

3 controls
Controls in the Leadership – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20233 controls
CodeTitle
iso-iec-42001-2023::5.1Leadership and commitment
iso-iec-42001-2023::5.2Policy
iso-iec-42001-2023::5.3Roles, responsibilities and authorities

Operation – ISO/IEC 42001:2023

4 controls
Controls in the Operation – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20234 controls
CodeTitle
iso-iec-42001-2023::8.1Operational planning and control
iso-iec-42001-2023::8.2AI risk assessment
iso-iec-42001-2023::8.3AI risk treatment
iso-iec-42001-2023::8.4AI system impact assessment

Performance evaluation – ISO/IEC 42001:2023

8 controls
Controls in the Performance evaluation – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20238 controls
CodeTitle
iso-iec-42001-2023::9.1Monitoring, measurement, analysis and evaluation
iso-iec-42001-2023::9.2Internal audit
iso-iec-42001-2023::9.2.1General
iso-iec-42001-2023::9.2.2Internal audit programme
iso-iec-42001-2023::9.3Management review
iso-iec-42001-2023::9.3.1General
iso-iec-42001-2023::9.3.2Management review inputs
iso-iec-42001-2023::9.3.3Management review results

Planning – ISO/IEC 42001:2023

7 controls
Controls in the Planning – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20237 controls
CodeTitle
iso-iec-42001-2023::6.1Actions to address risks and opportunities
iso-iec-42001-2023::6.1.1General
iso-iec-42001-2023::6.1.2Risk assessment
iso-iec-42001-2023::6.1.3Risk treatment
iso-iec-42001-2023::6.1.4AI system impact assessment
iso-iec-42001-2023::6.2Objectives and planning to achieve them
iso-iec-42001-2023::6.3Planning of changes

Support – ISO/IEC 42001:2023

8 controls
Controls in the Support – ISO/IEC 42001:2023 domain of ISO/IEC 42001:20238 controls
CodeTitle
iso-iec-42001-2023::7.1Resources
iso-iec-42001-2023::7.2Competence
iso-iec-42001-2023::7.3Awareness
iso-iec-42001-2023::7.4Communication
iso-iec-42001-2023::7.5Documented information
iso-iec-42001-2023::7.5.1General
iso-iec-42001-2023::7.5.2Creating and updating
iso-iec-42001-2023::7.5.3Control of documented information

Your Compliance Coverage

If you comply with ISO/IEC 42001:2023, you already cover:

Maps to 67 other frameworks

38 total controls
NIST AI Risk Management Framework (AI RMF 1.0)
38 source controls mapped|52 target controls covered
100%
EU AI Act
38 source controls mapped|42 target controls covered
100%
ISO 27001:2022
33 source controls mapped|32 target controls covered
87%
ISO 27002:2022
32 source controls mapped|29 target controls covered
84%
NIST SP 800-53 Rev 5
31 source controls mapped|49 target controls covered
82%
SOC 2
30 source controls mapped|38 target controls covered
79%
NIST Cybersecurity Framework 2.0
22 source controls mapped|32 target controls covered
58%
ASEAN Guide on AI Governance and Ethics
16 source controls mapped|24 target controls covered
42%
NIST SP 800-53 Rev 5 MODERATE
13 source controls mapped|18 target controls covered
34%
FedRAMP Moderate
13 source controls mapped|18 target controls covered
34%
NIST SP 800-53 Revision 5.1 HIGH
13 source controls mapped|18 target controls covered
34%
FedRAMP High
13 source controls mapped|18 target controls covered
34%
NIST SP 800-53 Rev 5 LOW
12 source controls mapped|15 target controls covered
32%
APPI
10 source controls mapped|9 target controls covered
26%
CIS Controls v8
10 source controls mapped|21 target controls covered
26%
NIST SP 800-218
9 source controls mapped|10 target controls covered
24%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
9 source controls mapped|11 target controls covered
24%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
7 source controls mapped|6 target controls covered
18%
Australia AI Ethics Framework
7 source controls mapped|7 target controls covered
18%
APRA CPS 234
6 source controls mapped|8 target controls covered
16%
PCI DSS 4.0
6 source controls mapped|7 target controls covered
16%
CMMC 2.0
6 source controls mapped|6 target controls covered
16%
AWS Well-Architected Security Pillar
5 source controls mapped|5 target controls covered
13%
NIST SP 800-171 Rev 3
3 source controls mapped|3 target controls covered
8%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|1 target controls covered
8%
Azure Security Benchmark
3 source controls mapped|3 target controls covered
8%
HIPAA Security Rule
2 source controls mapped|2 target controls covered
5%
NIST SP 800-66 Rev 2
2 source controls mapped|2 target controls covered
5%
ISO 13485:2016
2 source controls mapped|2 target controls covered
5%
ISO 37001:2016
2 source controls mapped|2 target controls covered
5%
ISO 37301
2 source controls mapped|2 target controls covered
5%
ISO 14004:2016
1 source controls mapped|1 target controls covered
3%
ISO 14001:2015
1 source controls mapped|1 target controls covered
3%
ISO 9001:2015
1 source controls mapped|1 target controls covered
3%
ISO 27701:2019
1 source controls mapped|1 target controls covered
3%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 37301:2021
1 source controls mapped|1 target controls covered
3%
ISO 55001:2014
1 source controls mapped|1 target controls covered
3%
ISO 22000:2018
1 source controls mapped|1 target controls covered
3%
ISO 22301:2019
1 source controls mapped|1 target controls covered
3%
ISO 45001:2018
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
3%
ISO 30401
1 source controls mapped|1 target controls covered
3%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 45001
1 source controls mapped|1 target controls covered
3%
DORA
1 source controls mapped|1 target controls covered
3%
ISO 56002
1 source controls mapped|1 target controls covered
3%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|1 target controls covered
3%
ISO 37002:2021 - Whistleblowing Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 39001:2012 - Road Traffic Safety Management
1 source controls mapped|1 target controls covered
3%
AICPA SOC 3
1 source controls mapped|1 target controls covered
3%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
1 source controls mapped|1 target controls covered
3%
ISO 22000
1 source controls mapped|1 target controls covered
3%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|1 target controls covered
3%
EASA Part-IS - Information Security in Aviation
1 source controls mapped|1 target controls covered
3%
ISO/IEC TR 24028:2020
1 source controls mapped|1 target controls covered
3%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
3%
Aged Care Quality Standards 2019 (repealed edition)
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
3%
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
1 source controls mapped|1 target controls covered
3%
ISO 22320:2018
1 source controls mapped|1 target controls covered
3%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
3%
NIST SP 800-88 Rev 1
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
3%
NIST SP 800-128
1 source controls mapped|1 target controls covered
3%
BCBS 239
1 source controls mapped|1 target controls covered
3%

What is ISO/IEC 42001:2023 and who does it apply to?

ISO/IEC 42001:2023 is a compliance framework from International with 17 domains and 83 controls. ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS), the first AI-specific ISO management system standard. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 42001:2023 actually require?

ISO/IEC 42001:2023 has 83 controls organised across 17 domains. The largest domains are Annex A AIMS controls - A.6 AI system life cycle (9 controls), Clause A – ISO/IEC 42001:2023 (9 controls), Performance evaluation – ISO/IEC 42001:2023 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 42001:2023 do I already cover?

ISO/IEC 42001:2023 maps to 67 other compliance frameworks. The top mapping partners are NIST AI Risk Management Framework (AI RMF 1.0) (100% coverage), EU AI Act (100% coverage), ISO 27001:2022 (87% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/IEC 42001:2023?

Start your ISO/IEC 42001:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 42001:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 83 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required