ISO/IEC 42001:2023 follows the High Level Structure: clauses 4 to 10 govern the context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds 38 reference controls in nine thematic groups (A.2 to A.10) — from the AI policy through resources, impact assessments and the AI lifecycle to data, transparency, responsible use and third parties; Annex B provides the corresponding implementation guidance. The terminology is based on ISO/IEC 22989:2022.
ISO/IEC 42001 in practice: building the AI management system
With ISO/IEC 42001:2023, an international, certifiable standard for an Artificial Intelligence Management System (AIMS) exists for the first time. What the standard requires, what the documentation landscape looks like — and how you can efficiently integrate an AIMS into your existing ISMS.
38reference controls in Annex A
9thematic groups (A.2 to A.10)
10governance domains for supporting documents
3interlocking processes at the core of the AIMS
Organizations that develop or deploy AI must ensure that these systems act lawfully, securely, traceably and in an ethically responsible manner — toward their own organization, but also toward affected individuals, groups and society. ISO/IEC 42001:2023 defines the requirements for an Artificial Intelligence Management System (AIMS): a structured framework that covers the entire lifecycle of AI systems and brings together ethical, legal, technical and organizational dimensions. Because the standard is based on the High Level Structure (HLS) familiar from ISO/IEC 27001, ISO 9001 and ISO/IEC 27701, the AIMS can be integrated into existing management systems and draws on their proven principles of risk management, accountability, documentation and continual improvement. The EU AI Act adds further relevance with its requirements for risk classification, transparency, human oversight and technical documentation. This page shows which building blocks a certifiable AIMS needs in practice.
The Essentials at a Glance
Six topic blocks — tap to expand.
The road to certification
The proven phased approach from baseline analysis to the certification audit — tap a phase.
- Context and baseline analysis with an AI inventory and a gap analysis against the existing ISMS.
AI inventoryGap analysisExisting ISMS
- Establishment of the governance model and documentation.
Governance modelDocumentation
- Implementation of the processes along the AI lifecycle — from risk analysis and training data management to deployment, monitoring and incident handling.
Risk analysisTraining data managementDeploymentMonitoringIncident handling
- Training and awareness for all roles in the AIMS.
- Internal audit and management review as a dress rehearsal, followed by the certification audit.
- The SoA is subsequently updated on a regular basis as part of the management review.
Internal auditManagement reviewCertification auditSoA
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/IEC 42001:2023 — Artificial Intelligence Management System
Defines the requirements for an AIMS in clauses 4–10 as well as the reference controls in Annex A, with implementation guidance in Annex B.
ISO/IEC 22989:2022 — Artificial Intelligence — Concepts and Terminology
Terminological foundation of ISO/IEC 42001 and the AIMS documentation.
Verordnung über künstliche Intelligenz (EU AI Act)
Regulatory frame of reference for the AIMS, with requirements for risk classification, transparency, human oversight and technical documentation in accordance with Annex IV.
AIMS-Dokumentationsframework nach ISO/IEC 42001 (Policy, Handbuch Kap. 4–10, SoA, mitgeltende Dokumente)
Field-proven documentation structure for an AIMS, with audit checklists for all clauses of the standard and a complete Statement of Applicability covering the 38 Annex A controls.
Umsetzungskonzept zur Integration eines KI-Managementsystems in das ISMS gemäß AI Act & ISO/IEC 42001
Phase model for building an AIMS within an existing ISMS — from context analysis and governance model through the AI lifecycle to preparation for external certifications.
ISMS-AIMS-Synergieanalyse (Roadmap zur AI Act und NIS2 Readiness)
Comparison of 19 management system areas — from asset management and risk methodology to testing and ethics board — with the respective synergies between ISMS and AIMS.
Related Services
Your path to a certifiable AIMS
VamiSec is itself certified to ISO/IEC 27001; founder Valeri Milke is a Lead Auditor for ISO 27001 and ISO 42001. We support you with gap analyses, the development of AIMS documentation and governance, training and audit support — get in touch.