Skip to content

ISO 42001

ISO 42001 as the fourth management system, alongside BCMS, ISMS and DSMS

AI lifecycle governance, impact assessments, AI-specific risks and EU AI Act mapping run in one AIMS, sharing the same data model as your information security, continuity and data protection systems.

Annex A controls pre-loaded
38
Lifecycle, impact, risk and audit on one management system
1 AIMS
The AIMS shares assets, risks and evidence with ISMS, BCMS and DSMS
1 data model

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • ISO 42001Requirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

AI lifecycle management

ISO 42001 requires organisations to govern AI systems across their full lifecycle, from design and development through deployment, monitoring, and decommissioning. KaitoSec provides lifecycle stage tracking for every AI system, with controls and documentation requirements surfaced at each stage.

02

AI risk management framework

The standard requires a systematic approach to identifying, assessing, and treating risks specific to AI, including model drift, bias, adversarial attacks, and explainability failures. KaitoSec's AI risk register extends your existing risk management process with AI-specific risk categories and treatment workflows.

03

EU AI Act pre-alignment

ISO 42001 certification is the strongest candidate for demonstrating conformity under the EU AI Act, especially for high-risk systems. KaitoSec maintains a mapping between ISO 42001 controls and EU AI Act obligations, so your AIMS work directly contributes to regulatory compliance.

The workflow

01

Track implementation per clause

A central view of your ISO 42001 AIMS, covering policy documentation, AI system inventory, risk register, objectives, and audit programme. The dashboard tracks implementation maturity across all clauses of the standard and shows how close you are to certification readiness.

02

Run structured AI impact assessments

Control area A.5 of ISO 42001 requires assessing the impacts of AI systems; Annex B explains implementation. KaitoSec implements structured AI impact assessments covering individual, societal, and environmental impacts, linked to your AI system records and updated whenever system scope changes.

03

Use the overlap across frameworks

For organisations managing ISO 42001 alongside the EU AI Act, GDPR, and ISO 27001, KaitoSec's cross-framework view shows which controls and evidence items serve multiple frameworks simultaneously, minimising duplication and keeping your team focused on genuine gaps.

FAQ

What is ISO 42001 and who published it?

ISO 42001 is the international standard for Artificial Intelligence Management Systems (AIMS), published by the International Organization for Standardization in December 2023. It provides a framework for establishing, implementing, maintaining, and continually improving AI governance within an organisation, applicable to any sector or size.

How does ISO 42001 relate to the EU AI Act?

ISO 42001 is the strongest candidate to become a recognised technical standard under the EU AI Act, meaning certification could serve as evidence of conformity for certain high-risk obligations. KaitoSec maintains a live mapping between ISO 42001 controls and EU AI Act requirements, so organisations building an AIMS are simultaneously making progress on regulatory compliance. The same cross-framework mapping is the point of resilience made easy.

Can we certify to ISO 42001 like we can with ISO 27001?

Yes. ISO 42001 is an auditable management system standard with the same high-level structure as ISO 27001, ISO 9001, and ISO 14001. Third-party certification bodies can perform audits against ISO 42001 and issue certificates. KaitoSec prepares your documentation and evidence to the level required by accredited certification bodies.

What is the difference between ISO 42001 and ISO 27001 for AI?

ISO 27001 covers information security management broadly and includes controls relevant to AI systems as assets. ISO 42001 is AI-specific and covers AI lifecycle management, impact assessment, responsible AI practices, and AI-specific risk categories that are outside the scope of ISO 27001. KaitoSec supports both standards and cross-maps overlapping controls.

What do AI Impact Assessments under ISO 42001 cover?

Impact assessment is anchored in Annex A of ISO 42001 as control area A.5; Annex B explains implementation, including impacts on individuals (such as bias and discrimination), society (such as displacement of jobs), and the environment (such as energy consumption). KaitoSec's impact assessment templates follow this structure and require documented decisions on each impact category for every AI system in scope.

Related frameworks