← All frameworks
Standard
ISO/IEC 42001
ISO/IEC · Geneva, CH · effective Dec 2023
The certifiable AI Management System (AIMS) standard — the 'ISO 27001 for AI'. A Plan-Do-Check-Act management system organisations can be audited and certified against.
Your Council assistant — do it all here
You are interacting with an AI system.
Who must comply
- ▸Any org seeking certifiable AI governance
- ▸Vendors needing enterprise/procurement trust
Penalties
None — but certification is increasingly required in enterprise & public RFPs.
Key obligations
AI policy & objectives
Documented AIMS aligned to organisational context.
AI impact assessment
Assess impacts on individuals, groups and society.
Controls (Annex A)
Data, lifecycle, transparency, human oversight controls.
Continual improvement
Internal audit, management review, corrective action.
Sectors in scope
SaaS / technologyFinanceHealthcarePublic sectorManufacturing
Threats & cybersecurity it addresses
Ungoverned model lifecycleUndocumented data provenanceVendor trust gaps
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping
Charter Art. 2, 17, 21, 47
Governed MCP tools — open source, pip/npx install