standard

ISO 42001:2023

WHAT IS ISO 42001:2023 AND WHY IS IT IMPORTANT?

ISO 42001:2023 is the first international standard for Artificial Intelligence Management Systems (AIMS). It provides a framework for organisations to manage the risks and opportunities associated with AI, ensuring responsible development, deployment, and use of AI systems. ISO 42005:2025 complements this by guiding organisations through the process of assessing the impact of AI systems on individuals, groups, and society.

ISO 14001 More Info
More information...
Scroll down

ANNEX A 42001:2023 – WHAT IS IT?

Annex A offers a comprehensive reference for organisations implementing ISO 42001. Its primary purpose is to provide a structured catalogue of AI governance controls that help manage risks and ensure responsible AI practices. These controls are designed to:

  • Support risk treatment and help organisations select measures to address risks identified during AI impact assessments.
  • Promote transparency, accountability, and fairness in AI governance.
  • Provide guidance for tailoring controls to organisational context, scale, and risk profile.
  • Enable audit and certification, aligning with ISO 42001 requirements.
  • Strengthen governance using globally recognised AI principles.
  • Integrate with other management systems (such as ISO 9001 or ISO 27001).

WHAT DOES ISO 42001:2023 MEAN FOR YOUR ORGANISATION?

ISO 42001 helps organisations demonstrate responsible AI use, manage risks, and build trust with stakeholders. It supports compliance with emerging regulations and provides a streamlined approach to AI governance policies and procedures.

WHAT ARE THE CONTROLS IN ISO 42001:2023 ANNEX A?

ISO 42001 Annex A groups controls into the following domains (as per the standard):

  • Policies related to AI
  • Internal organisation
  • Resources for AI systems
  • Assessing impacts of AI systems
  • AI system life cycle
  • Data for AI systems
  • Information for interested parties of AI systems
  • Use of AI systems
  • Third-party and customer relationships

Each domain contains specific controls to help organisations manage AI risks and responsibilities.

ask a question

If you would like to know more about ISO Standards, Certification and the value of a good management system you can add to your business we would love to hear from you: Kent: 01892 800476 | London: 02037 458 476 | info@avisoconsultancy.co.uk

By filling out this form, you agree to the terms laid out in our privacy policy
Thank you!
Your submission has been received, one of our team members will be in touch soon.
Oops! Something went wrong while submitting the form.
ISO consultants kent

CHOOSE 42001:2023 CONTROLS

ISO 42001:2023 provides a set of controls to help organisations demonstrate compliance and best practice in AI management. At AvISO, we have created pages for each domain, with explained purpose and implementation guidance. Select a control domain to view details:

As part of ISO 42001:2023, Annex A lays out a set of controls that organisations can use to demonstrate compliance and responsible AI practices. A Statement of Applicability (SoA) lists the controls your organisation will implement to meet the requirements of the standard, including justification for inclusion or exclusion and confirmation of implementation.

ASK our AGENT
By clicking “Continue To Site”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts. View our Privacy Policy for more information.