AI Governance

What ISO/IEC 42001 actually asks of your leadership team

ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence. Most of the work it creates does not sit with your data scientists — it sits with the executive team that has to own it.

14 July 2026 · 7 min read

It is a management system, not a model checklist

ISO/IEC 42001 defines requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS). Structurally it follows the same Annex SL clause pattern as ISO/IEC 27001 — context, leadership, planning, support, operation, performance evaluation, improvement — so if you already hold 27001, the scaffolding is familiar and reusable.

The practical consequence is that certification is judged on governance evidence: defined scope, assigned accountability, documented risk and impact assessments, controls with owners, and records showing the cycle actually runs. A technically excellent model with no surrounding management system does not pass.

The five obligations that land on leadership

Clause 5 places specific, non-delegable duties on top management. In our experience these are where readiness assessments most often fail:

  • An AI policy that states intended use, prohibited use and risk appetite — not a values statement.
  • Defined roles, responsibilities and authorities for AI risk decisions, including who can approve a high-impact system into production.
  • Objectives for the AIMS that are measurable and reviewed, so performance evaluation has something to evaluate.
  • Resourcing and competence: named accountable owners with the time and skills to do the work.
  • Management review at a defined cadence, minuted, with decisions and actions recorded.

Two assessments, not one

42001 distinguishes AI risk assessment — risk to the organisation and to the objectives of the system — from AI system impact assessment, which considers consequences for individuals, groups and society. Boards frequently conflate the two and end up with a register that describes model accuracy but says nothing about who could be harmed and how a complaint would be handled.

Both are expected to be repeatable, documented and revisited when the system, data or context changes. Annex A gives the control set and Annex B the implementation guidance; Annex C catalogues objectives and risk sources you can use to test whether your register is genuinely complete.

Where it meets the EU AI Act

42001 is a voluntary management standard; the EU AI Act is law with staged obligations and penalties. They are not interchangeable — conformity with the standard is not automatic legal compliance — but the overlap is substantial. Risk management, data governance, technical documentation, logging, human oversight and post-market monitoring are all demanded by both.

For most organisations the efficient sequence is to build the AIMS once and map it to both, rather than run an ISO programme and an AI Act programme in parallel with two registers and two sets of evidence.

A defensible 90-day starting point

You do not need a full certification programme to make progress that survives scrutiny. A pragmatic first quarter looks like this:

  • Weeks 1–3: inventory every AI and machine learning system in use, including embedded vendor features and tools adopted without approval.
  • Weeks 4–6: classify by impact, agree risk appetite and prohibited use, and draft the AI policy for board approval.
  • Weeks 7–9: run risk and impact assessments on the highest-impact systems and assign control owners against Annex A.
  • Weeks 10–12: stand up the reporting pack and hold the first management review, so the cycle is demonstrably running before an auditor asks.

Book Assessment

Navigate Risk. Build Confidence.

A focused executive session to establish where you stand across AI, cyber and business risk.