ISO/IEC 42001:2023 — AI Management System (AIMS) Skill
Purpose
This skill provides audit-grade guidance on ISO/IEC 42001:2023. All responses must:
- Cite exact clause or Annex references (e.g., "Clause 6.1.2", "A.7.4", "B.5.2")
- Distinguish shall (mandatory requirement) from should (implementation guidance/recommendation)
- Never conflate normative Annex A or B content with informative Annex C or D content
- Be verifiable against the source document
Standard Overview
Full title: ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system
Edition: First, December 2023
Scope (Clause 1): Requirements and guidance for establishing, implementing, maintaining and continually improving an AI management system (AIMS) within any organization — regardless of size, type or nature — that provides or uses products or services utilizing AI systems.
Normative reference (Clause 2): ISO/IEC 22989:2022 (AI concepts and terminology)
Document Structure
| Section |
Type |
Content |
| Clauses 1-3 |
Normative |
Scope, references, definitions |
| Clauses 4-10 |
Normative |
AIMS requirements (Plan-Do-Check-Act) |
| Annex A |
Normative |
Reference control objectives and controls |
| Annex B |
Normative |
Implementation guidance for AI controls |
| Annex C |
Informative |
Potential AI-related organizational objectives and risk sources |
| Annex D |
Informative |
Use of AIMS across domains or sectors |
CRITICAL: Annex A and Annex B are normative. Annex C and D are informative (advisory only).
AIMS Clause Structure (Clauses 4-10)
The standard follows the ISO harmonized structure (High Level Structure):
Clause 4 — Context of the Organization
- 4.1 Understanding the organization and its context (external/internal issues; AI roles)
- 4.2 Understanding needs and expectations of interested parties
- 4.3 Determining scope of the AIMS
- 4.4 Establishing, implementing, maintaining and documenting the AIMS
Clause 5 — Leadership
- 5.1 Leadership and commitment (top management obligations)
- 5.2 AI policy (documented; communicated; reviewed; aligned to objectives)
- 5.3 Roles, responsibilities and authorities
Clause 6 — Planning
- 6.1 Actions to address risks and opportunities
- 6.1.1 General (AI risk criteria; domain/application context)
- 6.1.2 AI risk assessment (consistent, valid, comparable; consequence + likelihood + level)
- 6.1.3 AI risk treatment (Annex A comparison; statement of applicability; residual risk approval)
- 6.1.4 AI system impact assessment (individuals, groups, societies; technical + societal context)
- 6.2 AI objectives and planning (measurable; monitored; documented; who/what/when/how)
- 6.3 Planning of changes
Clause 7 — Support
- 7.1 Resources
- 7.2 Competence (education, training or experience; documented evidence)
- 7.3 Awareness (AI policy; contribution; implications of non-conformity)
- 7.4 Communication (what/when/with whom/how)
- 7.5 Documented information (7.5.1 General; 7.5.2 Creating/updating; 7.5.3 Control)
Clause 8 — Operation
- 8.1 Operational planning and control (criteria; controls from 6.1.3; external provision)
- 8.2 AI risk assessment (at planned intervals or on significant change)
- 8.3 AI risk treatment (implement plan; verify effectiveness; update if ineffective)
- 8.4 AI system impact assessment (at planned intervals or on significant change)
Clause 9 — Performance Evaluation
- 9.1 Monitoring, measurement, analysis and evaluation (what/methods/when/results)
- 9.2 Internal audit (9.2.1 General; 9.2.2 Programme — frequency/methods/responsibilities)
- 9.3 Management review (9.3.1 General; 9.3.2 Inputs; 9.3.3 Results — documented)
Clause 10 — Improvement
- 10.1 Continual improvement (suitability, adequacy, effectiveness)
- 10.2 Nonconformity and corrective action (react; evaluate cause; implement; review effectiveness; document)
Key Definitions (Clause 3)
| Term |
Definition |
Ref |
| AI system impact assessment |
Formal documented process to identify, evaluate and address impacts on individuals, groups or societies |
3.24 |
| Statement of applicability |
Documentation of all necessary controls and justification for inclusion or exclusion |
3.26 |
| Data quality |
Characteristic that data meet the organization's data requirements for a specific context |
3.25 |
| Control |
Measure that maintains and/or modifies risk |
3.21 |
| Governing body |
Person or group accountable for performance and conformance of the organization |
3.22 |
| Nonconformity |
Non-fulfilment of a requirement |
3.16 |
| Corrective action |
Action to eliminate the cause(s) of a nonconformity and prevent recurrence |
3.17 |
Annex A — Control Categories (Normative)
For detailed control text, read: references/annex-a-controls.md
| Section |
Topic |
Controls |
| A.2 |
Policies related to AI |
A.2.2 AI policy; A.2.3 Alignment; A.2.4 Review |
| A.3 |
Internal organization |
A.3.2 AI roles/responsibilities; A.3.3 Reporting of concerns |
| A.4 |
Resources for AI systems |
A.4.2 Resource documentation; A.4.3 Data; A.4.4 Tooling; A.4.5 System/computing; A.4.6 Human |
| A.5 |
Assessing impacts of AI systems |
A.5.2 Impact assessment process; A.5.3 Documentation; A.5.4 Individual impacts; A.5.5 Societal impacts |
| A.6 |
AI system life cycle |
A.6.1.2 Objectives for responsible development; A.6.1.3 Processes; A.6.2.2-A.6.2.8 Life cycle stages |
| A.7 |
Data for AI systems |
A.7.2 Development data; A.7.3 Acquisition; A.7.4 Quality; A.7.5 Provenance; A.7.6 Preparation |
| A.8 |
Information for interested parties |
A.8.2 System documentation/users; A.8.3 External reporting; A.8.4 Incident communication; A.8.5 Obligations |
| A.9 |
Use of AI systems |
A.9.2 Responsible use processes; A.9.3 Responsible use objectives; A.9.4 Intended use |
| A.10 |
Third-party and customer relationships |
A.10.2 Allocating responsibilities; A.10.3 Suppliers; A.10.4 Customers |
Critical Audit Distinctions
Statement of Applicability (SoA) — Clause 6.1.3(f)
The organization shall produce an SoA containing:
- All necessary controls from Annex A (or justification for exclusion)
- Justification for each inclusion and exclusion
- Note: Organizations may also include controls beyond Annex A
AI Risk Assessment vs. AI System Impact Assessment
These are two distinct processes under the standard:
- AI risk assessment (6.1.2 / 8.2): Focuses on organizational risk; consequences + likelihood + risk level
- AI system impact assessment (6.1.4 / 8.4): Focuses on impacts to individuals, groups and societies; informs the risk assessment but is a separate documented process
Shall vs. Should
- Shall = audit-mandatory requirement (non-compliance = nonconformity)
- Should = implementation guidance in Annex B (not auditable as a "shall" unless adopted by the organization)
Common Audit Scenarios
For gap assessments: Load references/gap-assessment-guide.md
For Annex A control details: Load references/annex-a-controls.md
For Annex B implementation guidance: Load references/annex-b-guidance.md
For risk management specifics: Load references/risk-management.md
Integration with Other Standards (Annex D — Informative)
ISO/IEC 42001 uses the ISO harmonized high-level structure, enabling integration with:
- ISO/IEC 27001 (information security) — B.6.1.2 controls can integrate with ISMS
- ISO/IEC 27701 (privacy) — B.2.3 and B.5.4 controls integrate with PIMS
- ISO 9001 (quality) — complementary risk management and supply chain provisions
Response Protocol for Audit Queries
- Always cite the clause, sub-clause or Annex reference for every requirement stated
- Use "shall" only for normative requirements (Clauses 4-10 and Annex A)
- Use "should" for Annex B guidance — these are not independently auditable
- Flag if a question spans multiple clauses — cross-reference clearly
- Never assume a control is excluded — the SoA determines applicability
- Distinguish finding types: Major nonconformity (complete absence of a "shall" requirement) vs. minor nonconformity (partial implementation) vs. observation
1---2name: iso-42001-aims3description: Expert guidance on ISO/IEC 42001:2023 — the international standard for AI Management Systems (AIMS). Use this skill whenever a user asks about ISO 42001, AI management systems, AIMS audits, AI governance frameworks, AI risk assessments under ISO standards, gap assessments against ISO 42001, clause interpretation, Annex A controls, Annex B implementation guidance, corrective actions, statement of applicability, or responsible AI governance. Also triggers for questions about AI policy requirements, AI system impact assessments, AI risk treatment plans, or certification readiness for ISO 42001. This skill is audit-grade — always cite clause numbers and use precise normative language (shall/should).4---56# ISO/IEC 42001:2023 — AI Management System (AIMS) Skill78## Purpose910This skill provides audit-grade guidance on ISO/IEC 42001:2023. All responses must:11- Cite exact clause or Annex references (e.g., "Clause 6.1.2", "A.7.4", "B.5.2")12- Distinguish **shall** (mandatory requirement) from **should** (implementation guidance/recommendation)13- Never conflate normative Annex A or B content with informative Annex C or D content14- Be verifiable against the source document1516---1718## Standard Overview1920**Full title:** ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system 21**Edition:** First, December 2023 22**Scope (Clause 1):** Requirements and guidance for establishing, implementing, maintaining and continually improving an AI management system (AIMS) within any organization — regardless of size, type or nature — that provides or uses products or services utilizing AI systems. 23**Normative reference (Clause 2):** ISO/IEC 22989:2022 (AI concepts and terminology)2425---2627## Document Structure2829| Section | Type | Content |30|---|---|---|31| Clauses 1-3 | Normative | Scope, references, definitions |32| Clauses 4-10 | Normative | AIMS requirements (Plan-Do-Check-Act) |33| Annex A | **Normative** | Reference control objectives and controls |34| Annex B | **Normative** | Implementation guidance for AI controls |35| Annex C | Informative | Potential AI-related organizational objectives and risk sources |36| Annex D | Informative | Use of AIMS across domains or sectors |3738> CRITICAL: Annex A and Annex B are **normative**. Annex C and D are **informative** (advisory only).3940---4142## AIMS Clause Structure (Clauses 4-10)4344The standard follows the ISO harmonized structure (High Level Structure):4546### Clause 4 — Context of the Organization47- **4.1** Understanding the organization and its context (external/internal issues; AI roles)48- **4.2** Understanding needs and expectations of interested parties49- **4.3** Determining scope of the AIMS50- **4.4** Establishing, implementing, maintaining and documenting the AIMS5152### Clause 5 — Leadership53- **5.1** Leadership and commitment (top management obligations)54- **5.2** AI policy (documented; communicated; reviewed; aligned to objectives)55- **5.3** Roles, responsibilities and authorities5657### Clause 6 — Planning58- **6.1** Actions to address risks and opportunities59 - **6.1.1** General (AI risk criteria; domain/application context)60 - **6.1.2** AI risk assessment (consistent, valid, comparable; consequence + likelihood + level)61 - **6.1.3** AI risk treatment (Annex A comparison; statement of applicability; residual risk approval)62 - **6.1.4** AI system impact assessment (individuals, groups, societies; technical + societal context)63- **6.2** AI objectives and planning (measurable; monitored; documented; who/what/when/how)64- **6.3** Planning of changes6566### Clause 7 — Support67- **7.1** Resources68- **7.2** Competence (education, training or experience; documented evidence)69- **7.3** Awareness (AI policy; contribution; implications of non-conformity)70- **7.4** Communication (what/when/with whom/how)71- **7.5** Documented information (7.5.1 General; 7.5.2 Creating/updating; 7.5.3 Control)7273### Clause 8 — Operation74- **8.1** Operational planning and control (criteria; controls from 6.1.3; external provision)75- **8.2** AI risk assessment (at planned intervals or on significant change)76- **8.3** AI risk treatment (implement plan; verify effectiveness; update if ineffective)77- **8.4** AI system impact assessment (at planned intervals or on significant change)7879### Clause 9 — Performance Evaluation80- **9.1** Monitoring, measurement, analysis and evaluation (what/methods/when/results)81- **9.2** Internal audit (9.2.1 General; 9.2.2 Programme — frequency/methods/responsibilities)82- **9.3** Management review (9.3.1 General; 9.3.2 Inputs; 9.3.3 Results — documented)8384### Clause 10 — Improvement85- **10.1** Continual improvement (suitability, adequacy, effectiveness)86- **10.2** Nonconformity and corrective action (react; evaluate cause; implement; review effectiveness; document)8788---8990## Key Definitions (Clause 3)9192| Term | Definition | Ref |93|---|---|---|94| AI system impact assessment | Formal documented process to identify, evaluate and address impacts on individuals, groups or societies | 3.24 |95| Statement of applicability | Documentation of all necessary controls and justification for inclusion or exclusion | 3.26 |96| Data quality | Characteristic that data meet the organization's data requirements for a specific context | 3.25 |97| Control | Measure that maintains and/or modifies risk | 3.21 |98| Governing body | Person or group accountable for performance and conformance of the organization | 3.22 |99| Nonconformity | Non-fulfilment of a requirement | 3.16 |100| Corrective action | Action to eliminate the cause(s) of a nonconformity and prevent recurrence | 3.17 |101102---103104## Annex A — Control Categories (Normative)105106For detailed control text, read: `references/annex-a-controls.md`107108| Section | Topic | Controls |109|---|---|---|110| A.2 | Policies related to AI | A.2.2 AI policy; A.2.3 Alignment; A.2.4 Review |111| A.3 | Internal organization | A.3.2 AI roles/responsibilities; A.3.3 Reporting of concerns |112| A.4 | Resources for AI systems | A.4.2 Resource documentation; A.4.3 Data; A.4.4 Tooling; A.4.5 System/computing; A.4.6 Human |113| A.5 | Assessing impacts of AI systems | A.5.2 Impact assessment process; A.5.3 Documentation; A.5.4 Individual impacts; A.5.5 Societal impacts |114| A.6 | AI system life cycle | A.6.1.2 Objectives for responsible development; A.6.1.3 Processes; A.6.2.2-A.6.2.8 Life cycle stages |115| A.7 | Data for AI systems | A.7.2 Development data; A.7.3 Acquisition; A.7.4 Quality; A.7.5 Provenance; A.7.6 Preparation |116| A.8 | Information for interested parties | A.8.2 System documentation/users; A.8.3 External reporting; A.8.4 Incident communication; A.8.5 Obligations |117| A.9 | Use of AI systems | A.9.2 Responsible use processes; A.9.3 Responsible use objectives; A.9.4 Intended use |118| A.10 | Third-party and customer relationships | A.10.2 Allocating responsibilities; A.10.3 Suppliers; A.10.4 Customers |119120---121122## Critical Audit Distinctions123124### Statement of Applicability (SoA) — Clause 6.1.3(f)125The organization **shall** produce an SoA containing:126- All necessary controls from Annex A (or justification for exclusion)127- Justification for each inclusion and exclusion128- Note: Organizations may also include controls beyond Annex A129130### AI Risk Assessment vs. AI System Impact Assessment131These are **two distinct processes** under the standard:132- **AI risk assessment (6.1.2 / 8.2):** Focuses on organizational risk; consequences + likelihood + risk level133- **AI system impact assessment (6.1.4 / 8.4):** Focuses on impacts to individuals, groups and societies; informs the risk assessment but is a separate documented process134135### Shall vs. Should136- **Shall** = audit-mandatory requirement (non-compliance = nonconformity)137- **Should** = implementation guidance in Annex B (not auditable as a "shall" unless adopted by the organization)138139---140141## Common Audit Scenarios142143**For gap assessments:** Load `references/gap-assessment-guide.md` 144**For Annex A control details:** Load `references/annex-a-controls.md` 145**For Annex B implementation guidance:** Load `references/annex-b-guidance.md` 146**For risk management specifics:** Load `references/risk-management.md`147148---149150## Integration with Other Standards (Annex D — Informative)151152ISO/IEC 42001 uses the ISO harmonized high-level structure, enabling integration with:153- **ISO/IEC 27001** (information security) — B.6.1.2 controls can integrate with ISMS154- **ISO/IEC 27701** (privacy) — B.2.3 and B.5.4 controls integrate with PIMS155- **ISO 9001** (quality) — complementary risk management and supply chain provisions156157---158159## Response Protocol for Audit Queries1601611. **Always cite the clause, sub-clause or Annex reference** for every requirement stated1622. **Use "shall" only for normative requirements** (Clauses 4-10 and Annex A)1633. **Use "should" for Annex B guidance** — these are not independently auditable1644. **Flag if a question spans multiple clauses** — cross-reference clearly1655. **Never assume a control is excluded** — the SoA determines applicability1666. **Distinguish finding types:** Major nonconformity (complete absence of a "shall" requirement) vs. minor nonconformity (partial implementation) vs. observation