Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 42001, AI & CompliancePublished: 10 July 2026

ISO 42001 Requirements Explained: AIMS, Clauses 4–10 and Annex A

ISO 42001 requirements explained: AIMS, leadership, AI risk, impact assessment, operations, internal audits and Annex A controls.

ISO/IEC 42001:2023 specifies requirements for an artificial intelligence management system. It applies to organisations that develop, provide or use AI systems. Its focus extends beyond individual models to leadership, accountability, risk, impact, data, suppliers, monitoring and continual improvement.

What an AIMS governs

An Artificial Intelligence Management System creates repeatable rules for AI decisions. It connects business objectives and innovation with governance, risk management and reliable evidence.

ISO describes ISO/IEC 42001 as the world's first AI management-system standard. It follows Plan-Do-Check-Act and can therefore align with other management systems.

Clauses 4 to 10 at a glance

Table 1: ISO 42001 Requirements Explained: AIMS, Clauses 4–10 and Annex A
AreaPractical meaning
Context and scopeWhich AI activities, roles, products and units belong in the AIMS?
LeadershipWho approves policy, objectives, risks and resources?
PlanningHow are AI risks, opportunities, objectives and impacts assessed?
SupportWhich competence, communication and documentation are needed?
OperationHow are AI systems controlled through selection, development, use and change?
EvaluationWhich metrics, internal audits and management reviews demonstrate effectiveness?
ImprovementHow are incidents, nonconformities and new insights addressed?

How Annex A is used

Annex A provides reference controls for AI governance. Their selection should reflect scope, risk assessment, impacts and organisational obligations. Additional controls may also be necessary.

Avoid a checklist-only implementation. The essential link is between the AI inventory, risks, impacts, controls, owners and evidence.

Typical evidence

  • Approved AI policy and scope
  • AI inventory with roles and owners
  • Risk assessments and documented impact considerations
  • Approvals, testing and monitoring for relevant AI systems
  • Supplier and data governance
  • Training records, internal audit and management review

How Sternberg Consulting supports you

We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting.

Discuss your project

Frequently asked questions

Who can use ISO 42001?

Organisations of any size that develop, provide or use AI-based products or services.

Is every AI system automatically in scope?

No. Scope is defined and must fit the organisation, its activities and interfaces.

Does ISO 42001 replace the EU AI Act?

No. It supports governance and evidence but does not replace legal analysis of roles and duties.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.