ReadSafety.com

ISO 42001 Questions, Answered

What are the requirements of ISO 42001?

Quick answer

ISO 42001 requires an AI management system built on clauses 4 to 10: understand your context and role in the AI value chain, lead with an AI policy, assess AI risks and impacts on people and society, resource the system, control the AI lifecycle and data, evaluate performance, and improve. Annex A supplies the AI-specific reference controls, selected and justified via a Statement of Applicability.

The management system layer (clauses 4 to 10)

  • Clause 4, Context. Internal and external issues, interested parties (including those affected by your AI, not only customers), your role as developer, provider, or user of AI, and the AIMS scope.
  • Clause 5, Leadership. Top management accountability, an AI policy setting principles for responsible development and use, and assigned roles and authorities.
  • Clause 6, Planning. The distinctive core: AI risk assessment, AI system impact assessment considering individuals and society, risk treatment against Annex A, measurable AIMS objectives, and planned changes.
  • Clause 7, Support. Resources (data, tooling, compute, and competent humans), awareness, communication, and documented information.
  • Clause 8, Operation. Executing the plans across the AI lifecycle and controlling changes; operationalizing impact assessments and treatments.
  • Clause 9, Performance evaluation. Monitoring and measurement of the AIMS and of AI system performance, internal audit, and management review.
  • Clause 10, Improvement. Nonconformity, corrective action, and continual improvement, fed by incidents and monitoring.

The Annex A control layer

Annex A provides reference controls across the AI-specific ground: AI policies and internal organization; resources for AI systems (data, tooling, human oversight); assessing impacts on individuals, groups, and society; AI system lifecycle management from requirements through retirement; data management for AI (provenance, quality, preparation); information and transparency for interested parties; responsible use; and third-party and supplier relationships in the AI chain. As in ISO 27001, controls are selected through your risk and impact assessments and documented in a Statement of Applicability with justifications.

Key factThe impact assessment requirement is what buyers and regulators care about most, and it is genuinely new territory for most management systems: you must consider consequences for people who never signed a contract with you, including fairness, safety, and societal effects, and feed those findings into your controls.

What an auditor traces

The audit thread runs: an AI system in your inventory, to its risk and impact assessments, to the SoA controls addressing them, to lifecycle evidence (design decisions, testing, human oversight in operation, monitoring for drift and misuse), to what happened when something went wrong. Organizations that already run ISO 27001 recognize the machinery; the new muscle is documenting AI-specific judgment: why this training data, why this level of human oversight, why this system was acceptable to deploy at all.

Ready to take the next step?

USQC - United Safety Quality Council is an ASC-accredited certification body providing third-party ISO 42001 and management system certification audits, internal and supplier audit services, and auditor training. Since 2015, USQC has automated audit planning, reporting, and decision support, cutting audit man-days that other certification bodies bill for and placing USQC pricing in the lower quartile, with highly experienced lead auditors on every audit.

Talk to USQC