Customers are starting to ask Indian technology companies a new question in security reviews: how do you govern the AI in your product? ISO/IEC 42001:2023 is the standard designed to answer it. Published in December 2023, it specifies requirements for an AI management system — the policies, roles, processes and controls an organisation uses to develop, provide or use AI systems responsibly. This article explains what ISO/IEC 42001 requires, how it fits alongside ISO/IEC 27001, and who should be considering it now.
What an AI management system under ISO/IEC 42001 is
ISO/IEC 42001 follows the same harmonised structure as ISO 9001 and ISO/IEC 27001, with requirements in clauses 4 to 10. It applies to any organisation, of any size, that provides or uses products or services involving AI systems. It is deliberately technology-neutral: it does not tell you which models or techniques to use, but requires you to manage the risks and impacts of the AI systems within your scope across their life cycle.
A useful early step is determining your role. The standard recognises that organisations may act as AI providers, AI producers or developers, AI customers or users, or partners in the AI supply chain, and often more than one of these at once. Your role shapes which risks are yours to manage and which controls are relevant.
The requirements that are specific to AI
Much of ISO/IEC 42001 will be familiar to anyone who has implemented another management system standard: context, leadership, policy, objectives, competence, documented information, internal audit, management review and improvement. The distinctive requirements sit mainly in planning and operation.
AI risk assessment and risk treatment
Clause 6.1 requires an AI risk assessment process and an AI risk treatment process. As in ISO/IEC 27001, risk treatment leads to the selection of controls, comparison with a reference set of controls in Annex A, and a Statement of Applicability that justifies the inclusion and exclusion of each control.
AI system impact assessment
The requirement with no real equivalent in other management system standards is the AI system impact assessment. The organisation must assess the potential consequences of its AI systems for individuals, groups of individuals and societies — not only for the organisation itself. This is where issues such as fairness, transparency, safety and effects on people’s rights are formally considered. Separate guidance on conducting these assessments is provided in ISO/IEC 42005.
Annex A controls
Annex A sets out reference control objectives and controls. They are grouped under topics including:
- Policies related to AI
- Internal organisation, including roles, responsibilities and reporting of concerns
- Resources for AI systems — data, tooling, computing and human resources
- Assessing impacts of AI systems on individuals, groups and society
- The AI system life cycle, from requirements and design through verification, deployment, operation and monitoring
- Data for AI systems, including data quality, provenance and preparation
- Information for interested parties about the AI system
- Use of AI systems, including intended use and responsible use processes
- Third-party and customer relationships across the AI supply chain
Annex B provides implementation guidance for these controls, Annex C lists potential AI-related organisational objectives and risk sources, and Annex D discusses use of the management system across domains and sectors.
How ISO/IEC 42001 relates to ISO/IEC 27001
The two standards are complementary rather than overlapping. ISO/IEC 27001 addresses the confidentiality, integrity and availability of information. ISO/IEC 42001 addresses a wider set of concerns specific to AI — how models behave, what data they are trained on, whether outcomes are explainable and fair, and how systems affect the people subject to them. An AI system can be perfectly secure and still produce harmful or biased outcomes.
Because both use the same structure, an organisation with a working ISMS can extend its existing context analysis, risk process, internal audit and management review to cover AI, rather than build a second system. Integrated certification of the two is possible where the integration is genuine.
The regulatory context
ISO/IEC 42001 is a voluntary standard; certification demonstrates that a management system is in place, not that any particular law is complied with. It is nonetheless useful evidence of governance where regulation applies. The European Union’s Artificial Intelligence Act, Regulation (EU) 2024/1689, imposes obligations on providers and deployers of AI systems placed on or used in the EU market, which is relevant to Indian companies serving European customers. In India, the Digital Personal Data Protection Act, 2023 applies where AI systems process digital personal data, and sector regulators have issued their own expectations for particular uses. An AI management system gives you a structured place to identify and track those obligations.
Who should consider ISO/IEC 42001 now
- SaaS and product companies whose products include AI features, particularly those selling to enterprise or regulated customers
- IT services and analytics firms that build or fine-tune AI systems for clients
- Banks, NBFCs and insurers using AI in credit, fraud, underwriting or customer service decisions
- Healthcare and health-technology organisations using AI in clinical or diagnostic support
- HR technology and recruitment platforms, where automated decisions affect individuals directly
- Any organisation already certified to ISO/IEC 27001 whose customers are asking about AI governance
Getting started
- Inventory the AI systems you develop, provide and use — including third-party AI services embedded in your products and internal tools
- Determine your role for each and define the scope of the management system
- Establish an AI policy and assign responsibilities, including who can raise and resolve concerns
- Define your AI risk assessment and impact assessment methods and apply them to the systems in scope
- Select controls, prepare the Statement of Applicability and implement the gaps
- Operate the system, then complete an internal audit and management review before seeking certification
If your organisation is considering ISO/IEC 42001 certification, or integrating it with an existing ISO/IEC 27001 certificate, talk to our team about scope and the certification process.