# Iso 42001 Aims

> Expert guidance on ISO/IEC 42001:2023 — the international standard for AI Management Systems (AIMS). Use this skill whenever a user asks about ISO 42001, AI management systems, AIMS audits, AI governance frameworks, AI risk assessments under ISO standards, gap assessments against ISO 42001, clause interpretation, Annex A controls, Annex B implementation guidance, corrective actions, statement of applicability, or responsible AI governance. Also triggers for questions about AI policy requirements, AI system impact assessments, AI risk treatment plans, or certification readiness for ISO 42001. This skill is audit-grade — always cite clause numbers and use precise normative language (shall/should).

- Skill: `gosulashivakumar/iso-42001-aims` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add gosulashivakumar/iso-42001-aims`
- Raw SKILL.md: https://api.skillmd.com/api/skills/gosulashivakumar/iso-42001-aims/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: GosulaShivaKumar (https://skillmd.com/u/gosulashivakumar)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/gosulashivakumar/iso-42001-aims

---


# ISO/IEC 42001:2023 — AI Management System (AIMS) Skill

## Purpose

This skill provides audit-grade guidance on ISO/IEC 42001:2023. All responses must:
- Cite exact clause or Annex references (e.g., "Clause 6.1.2", "A.7.4", "B.5.2")
- Distinguish **shall** (mandatory requirement) from **should** (implementation guidance/recommendation)
- Never conflate normative Annex A or B content with informative Annex C or D content
- Be verifiable against the source document

---

## Standard Overview

**Full title:** ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system  
**Edition:** First, December 2023  
**Scope (Clause 1):** Requirements and guidance for establishing, implementing, maintaining and continually improving an AI management system (AIMS) within any organization — regardless of size, type or nature — that provides or uses products or services utilizing AI systems.  
**Normative reference (Clause 2):** ISO/IEC 22989:2022 (AI concepts and terminology)

---

## Document Structure

| Section | Type | Content |
|---|---|---|
| Clauses 1-3 | Normative | Scope, references, definitions |
| Clauses 4-10 | Normative | AIMS requirements (Plan-Do-Check-Act) |
| Annex A | **Normative** | Reference control objectives and controls |
| Annex B | **Normative** | Implementation guidance for AI controls |
| Annex C | Informative | Potential AI-related organizational objectives and risk sources |
| Annex D | Informative | Use of AIMS across domains or sectors |

> CRITICAL: Annex A and Annex B are **normative**. Annex C and D are **informative** (advisory only).

---

## AIMS Clause Structure (Clauses 4-10)

The standard follows the ISO harmonized structure (High Level Structure):

### Clause 4 — Context of the Organization
- **4.1** Understanding the organization and its context (external/internal issues; AI roles)
- **4.2** Understanding needs and expectations of interested parties
- **4.3** Determining scope of the AIMS
- **4.4** Establishing, implementing, maintaining and documenting the AIMS

### Clause 5 — Leadership
- **5.1** Leadership and commitment (top management obligations)
- **5.2** AI policy (documented; communicated; reviewed; aligned to objectives)
- **5.3** Roles, responsibilities and authorities

### Clause 6 — Planning
- **6.1** Actions to address risks and opportunities
  - **6.1.1** General (AI risk criteria; domain/application context)
  - **6.1.2** AI risk assessment (consistent, valid, comparable; consequence + likelihood + level)
  - **6.1.3** AI risk treatment (Annex A comparison; statement of applicability; residual risk approval)
  - **6.1.4** AI system impact assessment (individuals, groups, societies; technical + societal context)
- **6.2** AI objectives and planning (measurable; monitored; documented; who/what/when/how)
- **6.3** Planning of changes

### Clause 7 — Support
- **7.1** Resources
- **7.2** Competence (education, training or experience; documented evidence)
- **7.3** Awareness (AI policy; contribution; implications of non-conformity)
- **7.4** Communication (what/when/with whom/how)
- **7.5** Documented information (7.5.1 General; 7.5.2 Creating/updating; 7.5.3 Control)

### Clause 8 — Operation
- **8.1** Operational planning and control (criteria; controls from 6.1.3; external provision)
- **8.2** AI risk assessment (at planned intervals or on significant change)
- **8.3** AI risk treatment (implement plan; verify effectiveness; update if ineffective)
- **8.4** AI system impact assessment (at planned intervals or on significant change)

### Clause 9 — Performance Evaluation
- **9.1** Monitoring, measurement, analysis and evaluation (what/methods/when/results)
- **9.2** Internal audit (9.2.1 General; 9.2.2 Programme — frequency/methods/responsibilities)
- **9.3** Management review (9.3.1 General; 9.3.2 Inputs; 9.3.3 Results — documented)

### Clause 10 — Improvement
- **10.1** Continual improvement (suitability, adequacy, effectiveness)
- **10.2** Nonconformity and corrective action (react; evaluate cause; implement; review effectiveness; document)

---

## Key Definitions (Clause 3)

| Term | Definition | Ref |
|---|---|---|
| AI system impact assessment | Formal documented process to identify, evaluate and address impacts on individuals, groups or societies | 3.24 |
| Statement of applicability | Documentation of all necessary controls and justification for inclusion or exclusion | 3.26 |
| Data quality | Characteristic that data meet the organization's data requirements for a specific context | 3.25 |
| Control | Measure that maintains and/or modifies risk | 3.21 |
| Governing body | Person or group accountable for performance and conformance of the organization | 3.22 |
| Nonconformity | Non-fulfilment of a requirement | 3.16 |
| Corrective action | Action to eliminate the cause(s) of a nonconformity and prevent recurrence | 3.17 |

---

## Annex A — Control Categories (Normative)

For detailed control text, read: `references/annex-a-controls.md`

| Section | Topic | Controls |
|---|---|---|
| A.2 | Policies related to AI | A.2.2 AI policy; A.2.3 Alignment; A.2.4 Review |
| A.3 | Internal organization | A.3.2 AI roles/responsibilities; A.3.3 Reporting of concerns |
| A.4 | Resources for AI systems | A.4.2 Resource documentation; A.4.3 Data; A.4.4 Tooling; A.4.5 System/computing; A.4.6 Human |
| A.5 | Assessing impacts of AI systems | A.5.2 Impact assessment process; A.5.3 Documentation; A.5.4 Individual impacts; A.5.5 Societal impacts |
| A.6 | AI system life cycle | A.6.1.2 Objectives for responsible development; A.6.1.3 Processes; A.6.2.2-A.6.2.8 Life cycle stages |
| A.7 | Data for AI systems | A.7.2 Development data; A.7.3 Acquisition; A.7.4 Quality; A.7.5 Provenance; A.7.6 Preparation |
| A.8 | Information for interested parties | A.8.2 System documentation/users; A.8.3 External reporting; A.8.4 Incident communication; A.8.5 Obligations |
| A.9 | Use of AI systems | A.9.2 Responsible use processes; A.9.3 Responsible use objectives; A.9.4 Intended use |
| A.10 | Third-party and customer relationships | A.10.2 Allocating responsibilities; A.10.3 Suppliers; A.10.4 Customers |

---

## Critical Audit Distinctions

### Statement of Applicability (SoA) — Clause 6.1.3(f)
The organization **shall** produce an SoA containing:
- All necessary controls from Annex A (or justification for exclusion)
- Justification for each inclusion and exclusion
- Note: Organizations may also include controls beyond Annex A

### AI Risk Assessment vs. AI System Impact Assessment
These are **two distinct processes** under the standard:
- **AI risk assessment (6.1.2 / 8.2):** Focuses on organizational risk; consequences + likelihood + risk level
- **AI system impact assessment (6.1.4 / 8.4):** Focuses on impacts to individuals, groups and societies; informs the risk assessment but is a separate documented process

### Shall vs. Should
- **Shall** = audit-mandatory requirement (non-compliance = nonconformity)
- **Should** = implementation guidance in Annex B (not auditable as a "shall" unless adopted by the organization)

---

## Common Audit Scenarios

**For gap assessments:** Load `references/gap-assessment-guide.md`  
**For Annex A control details:** Load `references/annex-a-controls.md`  
**For Annex B implementation guidance:** Load `references/annex-b-guidance.md`  
**For risk management specifics:** Load `references/risk-management.md`

---

## Integration with Other Standards (Annex D — Informative)

ISO/IEC 42001 uses the ISO harmonized high-level structure, enabling integration with:
- **ISO/IEC 27001** (information security) — B.6.1.2 controls can integrate with ISMS
- **ISO/IEC 27701** (privacy) — B.2.3 and B.5.4 controls integrate with PIMS
- **ISO 9001** (quality) — complementary risk management and supply chain provisions

---

## Response Protocol for Audit Queries

1. **Always cite the clause, sub-clause or Annex reference** for every requirement stated
2. **Use "shall" only for normative requirements** (Clauses 4-10 and Annex A)
3. **Use "should" for Annex B guidance** — these are not independently auditable
4. **Flag if a question spans multiple clauses** — cross-reference clearly
5. **Never assume a control is excluded** — the SoA determines applicability
6. **Distinguish finding types:** Major nonconformity (complete absence of a "shall" requirement) vs. minor nonconformity (partial implementation) vs. observation

