Why the standard covers it by design
ISO 42001 attaches to your role and your systems, not to any model architecture. If you develop, provide, or use AI, the requirements apply: inventory, risk assessment, impact assessment, lifecycle controls, data management, transparency, and supplier management. A company fine-tuning open models, one calling a commercial API, and one training foundation models all fall in scope; their Statements of Applicability simply weight the controls differently.
What generative AI changes in practice
- Impact assessment gets harder and more important. Open-ended outputs mean open-ended failure modes: fabricated facts presented confidently, unsafe advice, biased or harmful generations, and misuse by users. Assessments must reason about output categories and worst cases, not a fixed decision boundary.
- Data management extends to provenance and rights. Training and fine-tuning data provenance, licensing, and personal data content become control points, along with what user inputs you retain and whether they feed further training.
- The supplier relationship becomes the system. Building on a provider's model makes their practices part of your risk surface: model updates that change behavior under you, usage policies, data handling, and availability. ISO 42001's third-party controls do heavy lifting here: contracts, due diligence, and monitoring of provider changes.
- Operational monitoring shifts to outputs and use. Content filtering effectiveness, jailbreak and prompt-injection attempts, drift in behavior after provider updates, and user feedback loops become the evidence auditors sample.
- Transparency duties sharpen. Disclosing AI interaction and AI-generated content to users is both an Annex A concern and, increasingly, a legal one under regimes like the EU AI Act.
What an auditor asks a generative AI company
Show me your system inventory including every model dependency and version. Show me the impact assessment for this product, and what you decided about hallucination in this use case. Show me the evaluation results that supported deployment, and the ones after the last model swap. Show me how a user reports a harmful output and what happened to the last ten reports. Show me the human oversight that is real rather than nominal. Companies with genuine engineering discipline usually possess most of this evidence already; the AIMS organizes it into something certifiable, and the certificate turns it into something sellable.