ISO/IEC 42001 (AI management system)
ISO/IEC 42001:2023 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS) within an organisation. Published in December 2023, it is the first certifiable management-system standard dedicated to AI, built on the same high-level structure as ISO 9001 (quality), ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management), which allows integration with existing certified systems.
The standard requires the organisation to understand its context and the expectations of interested parties, define an AI policy and objectives, assign roles and responsibilities (an AI Officer function in practice), assess and treat AI-specific risks and impacts, provide resources and competence, control the AI lifecycle from design through deployment and decommissioning, manage third-party components and data, monitor performance, conduct internal audits and management reviews, and drive continual improvement. Annex A lists 38 controls in areas such as AI policies, internal organisation, resources for AI systems, impact assessment, lifecycle management, data for AI systems, information for interested parties, use of AI systems and third-party relationships; Annex B gives implementation guidance, and the companion standards ISO/IEC 42005 (AI system impact assessment) and ISO/IEC 23894 (AI risk management) supply methods.
ISO/IEC 42001 is not a presumption of conformity with the EU AI Act, which will rely on harmonised European standards developed by CEN-CENELEC JTC 21, but it maps closely to the Act's quality management system requirement for providers of high-risk AI systems (Art. 17), to risk management (Art. 9), data governance (Art. 10), human oversight (Art. 14) and post-market monitoring, and it gives deployers a framework for their Art. 26 duties. For life sciences companies, certification demonstrates to regulators, notified bodies, partners and investors that AI governance is systematic, and integrates naturally with the MDR quality management system (ISO 13485) and the information security management system under ISO/IEC 27001. iliomad, itself ISO 27001 and 9001 certified, supports AIMS implementation as part of its AI compliance services.
