01The standard: HLS clauses 4–10 and Annex A controls
ISO/IEC 42001:2023 follows the High Level Structure: clauses 4 to 10 govern the context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds 38 reference controls in nine thematic groups (A.2 to A.10) — from the AI policy through resources, impact assessments and the AI lifecycle to data, transparency, responsible use and third parties; Annex B provides the corresponding implementation guidance. The terminology is based on ISO/IEC 22989:2022.
02The AIMS documentation landscape
A certifiable AIMS rests on clearly layered documentation: the AIMS policy as the governing document with principles for responsible AI, a manual covering the requirements of clauses 4–10 including audit checklists, and the Statement of Applicability (SoA) as the central evidence document that justifies every control decision and assigns supporting evidence. It is complemented by supporting documents along ten governance domains — governance structure, roles and lifecycle responsibility, data governance, model governance, risk management, security & privacy, human oversight & ethical control, supplier & third-party governance, continuous improvement & CAPA, and management review.
03Synergies with ISO 27001: an integrated management system
If you already operate an ISMS in accordance with ISO/IEC 27001, you do not have to run the AIMS alongside it — you can integrate it: a shared asset register for IT, data and AI systems, a uniform risk methodology, a supplier process with AI clauses, combined internal audits and a joint management review. Incident management, training and the policy framework can also be maintained jointly for both sets of requirements. The starting point is a gap analysis that shows which ISMS building blocks can be reused and where AI-specific additions become necessary.
04Roles and responsibility across the AI lifecycle
Clause 5 of the standard anchors the responsibility of top management: it establishes the AI policy, integrates the AIMS into the business strategy and assigns roles, responsibilities and authorities. In practice, a governance model has proven effective that consists of an AI Governance Board for strategic steering and approvals, an AI Compliance Officer for legal and ethical requirements, and an AIMS lead for operational implementation. Controls A.3.2 and A.3.3 require documented roles across the entire AI lifecycle — for example via a RACI matrix and a role register — as well as defined reporting channels for raising concerns.
05Risk management and AI Impact Assessment
The core of the AIMS consists of three interlocking processes: the AI risk assessment (clause 8.2), AI risk treatment (clause 8.3) and the AI system impact assessment (clauses 6.1.4 and 8.4). What sets it apart from classic security risk management: it evaluates not only risks to the organization but explicitly also impacts on individuals, groups and society. Controls A.5.2 to A.5.5 require a documented impact assessment process including reports — up to and including the assessment of societal impacts.
06The road to certification: project phases
A phased approach has proven effective: first a context and baseline analysis with an AI inventory and a gap analysis against the existing ISMS, then the establishment of the governance model and documentation, followed by implementation of the processes along the AI lifecycle — from risk analysis and training data management to deployment, monitoring and incident handling. This is followed by training and awareness for all roles in the AIMS, an internal audit and a management review as a dress rehearsal, and then the certification audit. The SoA is subsequently updated on a regular basis as part of the management review.