Book an Appointment

ISO/IEC 42001 in practice: building the AI management system

With ISO/IEC 42001:2023, an international, certifiable standard for an Artificial Intelligence Management System (AIMS) exists for the first time. What the standard requires, what the documentation landscape looks like — and how you can efficiently integrate an AIMS into your existing ISMS.

Organizations that develop or deploy AI must ensure that these systems act lawfully, securely, traceably and in an ethically responsible manner — toward their own organization, but also toward affected individuals, groups and society. ISO/IEC 42001:2023 defines the requirements for an Artificial Intelligence Management System (AIMS): a structured framework that covers the entire lifecycle of AI systems and brings together ethical, legal, technical and organizational dimensions. Because the standard is based on the High Level Structure (HLS) familiar from ISO/IEC 27001, ISO 9001 and ISO/IEC 27701, the AIMS can be integrated into existing management systems and draws on their proven principles of risk management, accountability, documentation and continual improvement. The EU AI Act adds further relevance with its requirements for risk classification, transparency, human oversight and technical documentation. This page shows which building blocks a certifiable AIMS needs in practice.

The Essentials at a Glance

01

The standard: HLS clauses 4–10 and Annex A controls

ISO/IEC 42001:2023 follows the High Level Structure: clauses 4 to 10 govern the context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds 38 reference controls in nine thematic groups (A.2 to A.10) — from the AI policy through resources, impact assessments and the AI lifecycle to data, transparency, responsible use and third parties; Annex B provides the corresponding implementation guidance. The terminology is based on ISO/IEC 22989:2022.

02

The AIMS documentation landscape

A certifiable AIMS rests on clearly layered documentation: the AIMS policy as the governing document with principles for responsible AI, a manual covering the requirements of clauses 4–10 including audit checklists, and the Statement of Applicability (SoA) as the central evidence document that justifies every control decision and assigns supporting evidence. It is complemented by supporting documents along ten governance domains — governance structure, roles and lifecycle responsibility, data governance, model governance, risk management, security & privacy, human oversight & ethical control, supplier & third-party governance, continuous improvement & CAPA, and management review.

03

Synergies with ISO 27001: an integrated management system

If you already operate an ISMS in accordance with ISO/IEC 27001, you do not have to run the AIMS alongside it — you can integrate it: a shared asset register for IT, data and AI systems, a uniform risk methodology, a supplier process with AI clauses, combined internal audits and a joint management review. Incident management, training and the policy framework can also be maintained jointly for both sets of requirements. The starting point is a gap analysis that shows which ISMS building blocks can be reused and where AI-specific additions become necessary.

04

Roles and responsibility across the AI lifecycle

Clause 5 of the standard anchors the responsibility of top management: it establishes the AI policy, integrates the AIMS into the business strategy and assigns roles, responsibilities and authorities. In practice, a governance model has proven effective that consists of an AI Governance Board for strategic steering and approvals, an AI Compliance Officer for legal and ethical requirements, and an AIMS lead for operational implementation. Controls A.3.2 and A.3.3 require documented roles across the entire AI lifecycle — for example via a RACI matrix and a role register — as well as defined reporting channels for raising concerns.

05

Risk management and AI Impact Assessment

The core of the AIMS consists of three interlocking processes: the AI risk assessment (clause 8.2), AI risk treatment (clause 8.3) and the AI system impact assessment (clauses 6.1.4 and 8.4). What sets it apart from classic security risk management: it evaluates not only risks to the organization but explicitly also impacts on individuals, groups and society. Controls A.5.2 to A.5.5 require a documented impact assessment process including reports — up to and including the assessment of societal impacts.

06

The road to certification: project phases

A phased approach has proven effective: first a context and baseline analysis with an AI inventory and a gap analysis against the existing ISMS, then the establishment of the governance model and documentation, followed by implementation of the processes along the AI lifecycle — from risk analysis and training data management to deployment, monitoring and incident handling. This is followed by training and awareness for all roles in the AIMS, an internal audit and a management review as a dress rehearsal, and then the certification audit. The SoA is subsequently updated on a regular basis as part of the management review.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2023

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Defines the requirements for an AIMS in clauses 4–10 as well as the reference controls in Annex A, with implementation guidance in Annex B.

ISO/IEC · 2022

ISO/IEC 22989:2022 — Artificial Intelligence — Concepts and Terminology

Terminological foundation of ISO/IEC 42001 and the AIMS documentation.

Europäische Union · 2024

Verordnung über künstliche Intelligenz (EU AI Act)

Regulatory frame of reference for the AIMS, with requirements for risk classification, transparency, human oversight and technical documentation in accordance with Annex IV.

VamiSec GmbH — Projektmaterial · 2025

AIMS-Dokumentationsframework nach ISO/IEC 42001 (Policy, Handbuch Kap. 4–10, SoA, mitgeltende Dokumente)

Field-proven documentation structure for an AIMS, with audit checklists for all clauses of the standard and a complete Statement of Applicability covering the 38 Annex A controls.

VamiSec GmbH · 2025

Umsetzungskonzept zur Integration eines KI-Managementsystems in das ISMS gemäß AI Act & ISO/IEC 42001

Phase model for building an AIMS within an existing ISMS — from context analysis and governance model through the AI lifecycle to preparation for external certifications.

VamiSec GmbH · 2025

ISMS-AIMS-Synergieanalyse (Roadmap zur AI Act und NIS2 Readiness)

Comparison of 19 management system areas — from asset management and risk methodology to testing and ethics board — with the respective synergies between ISMS and AIMS.

Your path to a certifiable AIMS

VamiSec is itself certified to ISO/IEC 27001; founder Valeri Milke is a Lead Auditor for ISO 27001 and ISO 42001. We support you with gap analyses, the development of AIMS documentation and governance, training and audit support — get in touch.