ISO 42001 Requirements Explained: AIMS, Clauses 4–10 and Annex A
ISO 42001 requirements explained: AIMS, leadership, AI risk, impact assessment, operations, internal audits and Annex A controls.
ISO/IEC 42001:2023 specifies requirements for an artificial intelligence management system. It applies to organisations that develop, provide or use AI systems. Its focus extends beyond individual models to leadership, accountability, risk, impact, data, suppliers, monitoring and continual improvement.
What an AIMS governs
An Artificial Intelligence Management System creates repeatable rules for AI decisions. It connects business objectives and innovation with governance, risk management and reliable evidence.
ISO describes ISO/IEC 42001 as the world's first AI management-system standard. It follows Plan-Do-Check-Act and can therefore align with other management systems.
Clauses 4 to 10 at a glance
| Area | Practical meaning |
|---|---|
| Context and scope | Which AI activities, roles, products and units belong in the AIMS? |
| Leadership | Who approves policy, objectives, risks and resources? |
| Planning | How are AI risks, opportunities, objectives and impacts assessed? |
| Support | Which competence, communication and documentation are needed? |
| Operation | How are AI systems controlled through selection, development, use and change? |
| Evaluation | Which metrics, internal audits and management reviews demonstrate effectiveness? |
| Improvement | How are incidents, nonconformities and new insights addressed? |
How Annex A is used
Annex A provides reference controls for AI governance. Their selection should reflect scope, risk assessment, impacts and organisational obligations. Additional controls may also be necessary.
Avoid a checklist-only implementation. The essential link is between the AI inventory, risks, impacts, controls, owners and evidence.
Typical evidence
- Approved AI policy and scope
- AI inventory with roles and owners
- Risk assessments and documented impact considerations
- Approvals, testing and monitoring for relevant AI systems
- Supplier and data governance
- Training records, internal audit and management review
How Sternberg Consulting supports you
We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting.
Frequently asked questions
Who can use ISO 42001?
Organisations of any size that develop, provide or use AI-based products or services.
Is every AI system automatically in scope?
No. Scope is defined and must fit the organisation, its activities and interfaces.
Does ISO 42001 replace the EU AI Act?
No. It supports governance and evidence but does not replace legal analysis of roles and duties.