Book an Appointment

ISO/IEC 42001 in practice: building the AI management system

With ISO/IEC 42001:2023, an international, certifiable standard for an Artificial Intelligence Management System (AIMS) exists for the first time. What the standard requires, what the documentation landscape looks like — and how you can efficiently integrate an AIMS into your existing ISMS.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

38reference controls in Annex A
9thematic groups (A.2 to A.10)
10governance domains for supporting documents
3interlocking processes at the core of the AIMS

Organizations that develop or deploy AI must ensure that these systems act lawfully, securely, traceably and in an ethically responsible manner — toward their own organization, but also toward affected individuals, groups and society. ISO/IEC 42001:2023 defines the requirements for an Artificial Intelligence Management System (AIMS): a structured framework that covers the entire lifecycle of AI systems and brings together ethical, legal, technical and organizational dimensions. Because the standard is based on the High Level Structure (HLS) familiar from ISO/IEC 27001, ISO 9001 and ISO/IEC 27701, the AIMS can be integrated into existing management systems and draws on their proven principles of risk management, accountability, documentation and continual improvement. The EU AI Act adds further relevance with its requirements for risk classification, transparency, human oversight and technical documentation. This page shows which building blocks a certifiable AIMS needs in practice.

The Essentials at a Glance

Six topic blocks — tap to expand.

The road to certification

The proven phased approach from baseline analysis to the certification audit — tap a phase.

Phase 1
  • Context and baseline analysis with an AI inventory and a gap analysis against the existing ISMS.
AI inventoryGap analysisExisting ISMS

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2023

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Defines the requirements for an AIMS in clauses 4–10 as well as the reference controls in Annex A, with implementation guidance in Annex B.

ISO/IEC · 2022

ISO/IEC 22989:2022 — Artificial Intelligence — Concepts and Terminology

Terminological foundation of ISO/IEC 42001 and the AIMS documentation.

Europäische Union · 2024

Verordnung über künstliche Intelligenz (EU AI Act)

Regulatory frame of reference for the AIMS, with requirements for risk classification, transparency, human oversight and technical documentation in accordance with Annex IV.

VamiSec GmbH — Projektmaterial · 2025

AIMS-Dokumentationsframework nach ISO/IEC 42001 (Policy, Handbuch Kap. 4–10, SoA, mitgeltende Dokumente)

Field-proven documentation structure for an AIMS, with audit checklists for all clauses of the standard and a complete Statement of Applicability covering the 38 Annex A controls.

VamiSec GmbH · 2025

Umsetzungskonzept zur Integration eines KI-Managementsystems in das ISMS gemäß AI Act & ISO/IEC 42001

Phase model for building an AIMS within an existing ISMS — from context analysis and governance model through the AI lifecycle to preparation for external certifications.

VamiSec GmbH · 2025

ISMS-AIMS-Synergieanalyse (Roadmap zur AI Act und NIS2 Readiness)

Comparison of 19 management system areas — from asset management and risk methodology to testing and ethics board — with the respective synergies between ISMS and AIMS.

Your path to a certifiable AIMS

VamiSec is itself certified to ISO/IEC 27001; founder Valeri Milke is a Lead Auditor for ISO 27001 and ISO 42001. We support you with gap analyses, the development of AIMS documentation and governance, training and audit support — get in touch.