A Security Professional’s Guide to the New Standard for AI Management Systems

ISO 42001, published in December 2023, is the world’s first international standard for Artificial Intelligence (AI) Management Systems (AIMS).
Published by ISO & IEC (the International Organization for Standardization and the International Electrotechnical Commission), the standard was authored over more than two years by working groups containing highly credentialed members from 50+ countries, concluding with a public comment period prior to finalization.
The organization of the new standard mirrors other, more established ISO Management System standards such as ISO 27001 (Security), ISO 27701 (Privacy), and ISO 9001 (Quality), and focuses on deploying AI systems that are both effective and appropriately managed.
The framework provides a familiar structure for responsibly developing, implementing, and maintaining AI systems, easing the daunting task of building a governance program around a shiny, new AI system.
In this article, we’ll go over:
- Who should care about this (so you can decide if you need to keep reading)
- Detail the core components of this new standard
- Explain the certification process you’ll need to undergo
For all you Doers and Hard Chargers, you can stop there to go forth and conquer. For those on more of an academic journey, I’ll include some postscript below the conclusion with a few more details on each of the above sections, then pontificate on some benefits of adopting this standard and some challenges you may face, and close by ideating on the future of AI compliance and regulations.
Let’s dive in.
Executive Summary
Who Should Care About ISO 42001?
In short: Those who build an AI model, have integrated someone else’s AI model into their product, or use the term “AI” anywhere in their marketing collateral.
Core Components of ISO 42001
The standard is divided into 10 clauses and 4 annexes, the most important are:
| Clauses 4 -10 |
Contains the information required to form the AIMS. |
| Annex A |
Lists the specific controls ISO/IEC think you should implement (or, at the very least, explain why you didn’t implement). |
| Annex B |
Context and guidance on how to implement the controls from Annex A. |
The core ideas and concepts the standard explores are:
- Leadership & Goal Setting – What’s important to your business and your unique competitive environment? (Clauses 4, 5, 6, 7; Annex A.2, A.3; Annex B.2, B.3; Annex C)
- The AIMS – How do you document what’s important to you, and how do you keep an eye on your AI? (Clauses 7, 8, 9, 10; Annex A.4; Annex B.4; Annex D)
- AI Risk Assessment – How to identify and respond to things that will keep you from achieving your goals. (Clauses 6.1.2, 6.1.3, 8.2, 8.3; Annex C)
- AI Impact Assessment – How to consider what effects your AI system will have on the rest of the world. (Clauses 6.1.4, 8.4; Annex A.5; Annex B.5)
- Data Protection & AI Security – What policies you should have, what foundational security practices you should be implementing, and how you’re keeping track of the data feeding into and being generated by your AI system. (Annex A, Annex B)
Implementation & Certification Process
The ISO 42001 certification process follows the same basic process as other popular ISO standards. The basic steps are:
- Build and document your AIMS.
- Consider if you should harmonize your AIMS with an existing management system, such as an ISMS, PIMS, or QMS.
- Find an audit partner. The IAF maintains a directory of all certification bodies to simplify your search.
- Perform and document an internal audit (steps 2 and 3 don’t have to happen sequentially).
- Undergo an external audit (Stage 1 and Stage 2) from the partner you selected.
- After certification, you’ll need to undergo surveillance audits in years 2 & 3, and recertification in year 4 – so expect audits annually as long as you’d like to remain certified.
How to Get Started
ISO 42001 provides a framework you can follow to establish and document an AI management system that enables you to effectively address the risks associated with the development, implementation, and management of an AI system. Below are the steps to get started.
- Purchase the official standard (~$225)
- Gap Assessment/Internal Audit (consider an outsourced internal audit)
- Build your AIMS and Statement of Applicability
- Perform an AI risk assessment and an AI impact assessment (these are new concepts so are most likely to be gaps).
- Engage a certification body
- Complete remediation efforts on all identified gaps (we can help)
A Deeper Look at ISO 42001
If you’re still here, it’s because you need more research before you can make your decisions. Great! Let’s take another look.
The ISO 42001 framework is incredibly new. It was released in draft form in November 2022 and was only formally published in December 2023—and the infrastructure around the program is still very much being built.
Most countries don’t even have certifying bodies that can issue certificates yet, and most security professionals are just starting to gain familiarity with these concepts. Few organizations know what’s listed in the standard—but if you market AI, they all want to know how you’re governing it.
Who Should Care
ISO standards are entirely voluntary, and no governing body has currently mandated the adoption of ISO 42001; however, the standard’s broad guidelines and flexibility make it appropriate for organizations of any size, type, and industry that are involved in building, providing, or even just using AI-based products or services.
The standard is relevant across all economic sectors, from businesses to non-profits to governmental agencies.
If you’re one of the following, you should be pursuing adoption as quickly as possible:
- Actively training an AI model
- Begun integrating AI into your product
- Have any sort of autonomous decision-making going on (yes, that includes machine learning)
- Have an AI product offering in a crowded landscape, and you need to stand out
The market expects stability and trust. If you’ve integrated AI into your offerings in any capacity, you should be prepared to tell your “AI Story” by next year at the latest or risk being caught flat-footed.
5 Core Components of ISO 42001
1. Leadership & Goal Setting
In the introduction to the standard itself, ISO acknowledges the need to balance governance and innovation, as the potential uses of the technology are legion.
This tension is what necessitates management’s involvement, and management’s involvement is why the ISO standards have such an enduring appeal: the standards provide enough guidance to drive action but leave enough room for interpretation in how they’re implemented that they can be used quite broadly.
To effectively drive the AIMS, management’s involvement must extend to:
- Defining your role relative to the AI system. The standard, borrowing from ISO/IEC 22989, defines the following roles:
- AI Provider – A company bringing an AI system to the market.
- AI Producer – All those in the supply chain of bringing an AI system to the market.
- AI Customer – A user of an AI system, such as having a product with integrated API calls to an OpenAI interface.
- AI Partner – Those who work with or provide AI services to a company implementing an AIMS, including services such as AI risk assessments, supporting deployments of AI-enabled services, or simply providing an AI-powered tool to a company. These AI Partners are expected to support their partners’ AIMSs by adhering to the principles defined in the standard.
- AI Subject – A party who is (or could be) affected by the AI system. They could be data subjects whose data is directly being fed into the system, or simply users who will be affected by decisions the AI system makes; regardless, they must be considered in any AI risk or impact assessment.
- AI Regulator/Policymaker – Any party able to publish enforceable standards related to the use of AI.
- Defining the organizational context of the AIMS:
- What internal and external factors are important to you
- What stakeholders’ input should be considered (including parties as broad as “society”)
- Who (by name) is the management team responsible for the AI system
- Establishing and ratifying AI policies aligned with the organizational strategy previously identified and monitoring the system to ensure it’s operating as was intended.
- Allocating necessary resources to the AIMS and ensuring integration into business processes.
- Defining measurable objectives for the AIMS.
2. Elements of the Standard
The standard is divided into several major sections and looks very familiar to anyone well-versed in other ISO publications.
| Clause 1 – Scope |
A very basic and unimportant intro |
| Clause 2 – Normative References |
Lists any other documents that contain specific text that’s critical to understanding this standard (in this case, only ISO 22989:2022) |
| Clause 3 – Terms & Definitions |
A glossary of major terms referenced elsewhere in the standard |
| Clause 4 – Context of the Organization |
Understanding the factors influencing information security |
| Clause 5 – Leadership |
Displaying your commitment to information security |
| Clause 6 – Planning |
Identifying and addressing risks to your AIMS |
| Clause 7 – Support |
Ensuring your AIMS has the necessary resources |
| Clause 8 – Operation |
Implementing the necessary processes and controls |
| Clause 9 – Performance Evaluation |
Monitoring and measuring the AIMS to ensure it meets its objectives, to include a formal internal audit |
| Clause 10 – Improvement |
Continuously enhancing the AIMS based on performance evaluations and changing conditions |
| Annex A |
Lists the specific controls ISO/IEC think you should implement (or, at the very least, explain why you didn’t implement). |
| Annex B |
Context and guidance on how to implement the controls from Annex A. |
| Annex C |
Some potential objectives and risk sources you can use to help define your objectives and risk exposure. |
| Annex D |
How to apply the standard across business sectors and how to integrate your new AIMS with other management systems. |
To summarize each major section:
- Clauses 1-3 are relevant but don’t contain any prescriptive guidance.
- Clauses 4-10 are the most important sections to help you define the scope and structure of your AIMS.
- Annex A and B should be digested together and provide a list of controls you should implement, along with guidance on how to do so; they’re integral to building your AIMS and should not be overlooked.
- Annex C is quite useful as a starting point for both your AIMS and your AI risk assessment, read through it if you’ve got writer’s block. ISO 23894 builds further on the concepts detailed in Annex C.
- Annex D is a good reference if you want to integrate your AIMS with an Information Security Management System, Privacy Management System, or Quality Management System.
3. Other Applicable ISO Standards
- ISO/IEC 22989 – Establishes terminology and describes concepts in the field of AI.
- ISO/IEC 23053 – Establishes a framework for describing a generic AI system using machine learning technology.
- ISO/IEC 23894 – Provides AI risk management guidance.
4. AIMS & Statement Of Applicability (SoA)
As do many other ISO standards, ISO 42001 creates a management system, making the framework “future-proof” and compatible with almost any other regulation or framework.
What controls you implement are based on how you define the intended use of your AI system, what the internal and external context facing your company are, and the goals you have for the program. Once you’ve defined those broader aspects, you must create a Statement of Applicability (SoA) (as described in Clause 6.1.3(f)) and be able to provide evidence showing you’ve implemented all the controls included in the SoA.
Unless you’ve custom built your own control set that addresses identified risks (not common), each control in Annex A has to be addressed by the SoA; you will need to justify both the inclusion and exclusion of every control.
The AIMS is the formally documented—on paper and in a specific document—summation of the goals, policies, and oversight procedures of management regarding the AI system.
5. AI Security vs. AI Safety
As you’re implementing this framework, a concept to consider is the idea of AI security versus AI safety. AI security contains very familiar ideas, and most security practitioners are likely to already understand the concept. AI safety is a relatively new idea (not introduced in ISO 42001, but new to the compliance space more broadly) and it’s distinct in that your focus is less on protecting your system, but rather on controlling your system.
An AI Risk Assessment falls under the category of AI security. In this case, you’re attempting to protect your system/product/business from the multitude of bad actors who are, at their most fundamental level, trying to steal your money.
An AI Impact Assessment is an example of AI safety, and it differs in its focus; identifying who and how you or your system could hurt, rather than identifying who or what could hurt your system.
A simple way to think about it is:
- AI Security is protecting your AI product from the world,
- AI Safety is protecting the world from your AI product.
AI Risk Assessment
The standard emphasizes the importance of identifying, assessing, and managing risks associated with AI systems. To align with their methodology, you should:
- Conduct thorough risk assessments tailored to your AI systems at a regular cadence as defined by your policies. Each AI risk assessment should be performed in a similar way and be able to produce similar results, to identify when changes to factors lead to the identification of actual risks. Always retain formal documentation of each risk assessment, including when it occurred, who was involved, what risks were identified, who owns each risk, what their treatment plans are, and rescoring when treatment plans are carried out.
- Develop treatment strategies for identified risks. You should reference Annex A and Annex B. You can decide to apply controls in Annex A in contextual ways to develop risk treatment plans and identify opportunities to consolidate activities.
- Remember: Risks are present due to the combination of threats and vulnerabilities those threats may exploit. Controls are applied to reduce either the impact or likelihood of occurrence of a particular risk.
- Regularly review and update risk treatment plans and even processes. This is why carefully considered risk scores are so important, because you need to be able to know if your risk treatment actions (and investments) are actually working and reducing risk.

AI Impact Assessments
ISO 42001 introduces the concept of an AI Impact Assessment and encourages you to perform them repeatedly during the development of AI systems and upon. These function similarly to a risk assessment but have a slightly more narrowed focus. During an AI Impact Assessment, you should systematically define:
- The parties your system affects, namely, specific individuals, groups, and society at large.
- The effects your system will have on each party, including their physical or emotional wellbeing, the exercising of their human rights, how the legal system views them, or, most dramatically, on their life. Any automated decision points should be closely evaluated at this stage, as they bear the highest likelihood of unintended consequences.
- The results those effects will cause (based on the likelihood and severity of occurrence) and the appropriate treatment decisions taken after scoring the results.
This is a very broad concept and can be taken in almost innumerable ways, so we recommend keeping the focus as tight as possible until best practices emerge throughout the industry.
Harmonizing Your AI Management Systems Saves Money
As alluded to previously, ISO 42001 creates a Management System standard similar to those in other ISO standards. This synergy creates an easy method to establish an Integrated Management System by combining an existing management system (such as security, privacy, or quality) with your AIMS and reaping the efficiency benefits of strategic alignment.
If you’ve got an existing management system in place, you can save significant time and capital by integrating your management systems and undergoing synchronized audits.
ISO 42001 Implementation & Certification Process
Prior to engaging with an external auditor, you should familiarize yourself with the standard you’re pursuing and begin to close any gaps in your AI management program.
- Visit the ISO/IEC website and purchase the official standard. This’ll set you back about $225, but no amount of online research will replace simply having the standard.
- Conduct a current state analysis and gap assessment. Determine how close you are to already achieving compliance and create a list of action items or areas in which you’ll need to improve prior to inviting an auditor to rummage through your things.
- Develop and implement your AIMS.
- Perform your first internal audit of the AIMS in accordance with Clause 9.2 of the standard. Document the results of the audit and start working on fixing any weak areas identified during the audit.
- This is where risk3sixty comes in. Allow our certified and experienced experts to give you an opportunity for a pre-test to make sure you’ll pass when all the chips are down.
To formally receive your ISO 42001 certification, you’ll need to undergo an external audit from an accredited certification body. To do so:
- Search the directory to find an audit partner in your region.
- Schedule and complete the Stage 1 External Audit with your selected auditor.
- The Stage 1 checks if you’re ready for the full Stage 2 audit; it’ll focus on the design of your program – policies and documentation such as your AIMS, AI Risk Assessment, and Statement of Applicability.
- Schedule and complete the Stage 2 External Audit.
- You’ll need to provide evidence showing you’ve established an AIMS and have implemented all the controls from Annex A.
- Receive the certification. The cert is good for 3 years from that date, but…
- To maintain certification, you’ll need to undergo surveillance audits at 12-month intervals post-certification and complete a full recertification audit 36 months after initial certification.
- Surveillance audits are abbreviated as compared to certification audits and only examine about half of the Annex A controls each year.
Benefits of ISO 42001 Certification
Enhanced Trust and Reputation Leading to Revenue Generation and Cost Containment
Achieving an ISO 42001 certification signals to stakeholders that your organization takes AI governance seriously. This can lead to:
- Increased customer confidence in your AI-powered products and services. The ISO seal is taken seriously across the world and your customers will know your AI program is well-founded, even without having to know every part of the standard.
- Enhanced reputation as a responsible AI user that will improve relationships with partners and suppliers.
- Transparent accountability. The standard provides for the creation of governance structures around your AI system that facilitate accountability for decisions and outputs made by the system.
- Competitive Advantage. In a market so coiled with the tension between the excitement about the potential uses and apprehension regarding the perceived risks of the technology, being a first mover in the compliance space will help you stand out from the crowd of buzzword-laden offerings.
- Harmonization. Adopting an ISO standard is a modular building block that can be neatly integrated with other management systems. You can add AI into any other existing management systems you have, and you can build other management systems on top of the AIMS.
Improved Risk Management
The standard provides a structured approach to managing AI-related risks. This results in:
- Better identification and mitigation of potential AI system failures, including faulty inputs and biased algorithms.
- Reduced likelihood of ethical breaches or unintended consequences.
- Enhanced organizational resilience through ongoing surveillance and continual reassessments of the risks posed by and threatening your AI system.
- Flexibility. The standard’s relative open-ended nature allows your compliance program to grow with the organization and adapt to your market strategy around AI.
Challenges in ISO 42001 Implementation
While the benefits of adoption are significant, organizations may face challenges in implementation, such as:
- Resource constraints – What compliance program has an extra pair of hands to throw at another audit framework? Setting aside time and capital to pursue the certification will be difficult for some organizations just trying to catch their stride in the breakneck pace of business. Solely accounting for annual external audit fees, you’re probably going to want to allocate at least $20,000-$40,000, and that doesn’t consider the hidden costs being placed on your compliance team while they work to understand and implement this new governance program.
- Cultural Resistance – This framework is somewhat attempting to slow the pace of development of your AI system in exchange for a more stable foundation on which to build. Many people resist compliance instinctively, so it’s important to hear and acknowledge their concerns and emphasize the benefits of creating a trustworthy program.
- It’s new and confusing – AI systems necessitate extremely technically complex and enigmatic development processes. Especially if your product is already on the market, going back to build guiderails around the system may prove challenging.
To overcome these challenges, consider:
- Prioritizing a phased implementation approach. As mentioned earlier, not everyone needs to jump in and acquire this certification right away. Assuming you don’t have a financial imperative, take your time and roll out the program correctly the first time. We can help with this.
- Leveraging compliance management tools to streamline processes. At risk3sixty, we’ve created a purpose-built platform, fullCircle GRC, to simplify complex compliance situations. Having a tool can help lay track in front of you while you build your program, and help you show off your program when the time comes.
- Engaging expert consultants for guidance. If you’re not super comfortable with these technologies or compliance frameworks, there are plenty of firms willing to help. Before you make a financial investment in someone’s advice, make sure your consultants of choice have cache in the industry, have experience doing this before, and can articulate a clear path to your success.
Future of AI Compliance
Governments and industry trade groups across the world are grappling with how to approach AI. A few current examples are:
- European Union – With the passage of the EU AI Act, the European Union was the first to ratify a comprehensive AI regulation, but their law has a phased rollout, and the first phase only went into effect in August 2024. Read more on the EU AI Act here.
- U.S. State AI Laws – As of June 2024, 21 U.S. states have already enacted legislation addressing AI, and another 13 (plus the District of Columbia) have had lawmakers propose legislation. The scope of these laws varies wildly, so I encourage you to study which regulations apply to the states in which you do business. BCLP Group has a comprehensive tracker I’ve found to be very useful.
- U.S. Federal – At the federal level, it’s unlikely we come to a consensus anytime soon. If the 20-plus-year history of American privacy regulation is an indicator, we will likely not see a federal law governing AI. The responsibility for agreeing on a standard approach will fall on companies and the industry more broadly.
- Brazil, Canada & China – All of these countries are actively working on comprehensive AI regulations but have yet to finalize anything. It’s worth keeping an eye on their progress.
There will undoubtedly be a multitude of AI-centric compliance and risk management frameworks that arise as we progress. Our recommendation is to focus on where these regulations have crossover, as those areas of agreement are likely to continue to remain the center of the AI discussion.
Get Ahead in AI Governance with ISO 42001
ISO 42001 is one of the few options you have if considering how to demonstrate AI governance; thankfully, the framework is broad enough to be highly useful across industries and is a large step forward in establishing global standards for responsible AI development and use.
By embracing this standard, you can leap to the front of the market in the AI field and can leverage your compliance program as a strategic differentiator and revenue driver.
Ready to take the plunge? At risk3sixty, we simplify compliance and help you audit, implement, and manage streamlined compliance programs that align with your business objectives.
We provide everything from policy templates and risk management tools to internal audits and full program implementations, all backed by our purpose-built software, fullCircle GRC. We’ve even released a full ISO 42001 course for FREE.
Our team of certified experts would love to meet you, get to understand your business, and discover how we can help you. Contact us today to speak with an expert and start your journey towards an AI compliance program.
Jeremy Sharp
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)