Why ISO 42001
ISO/IEC 42001:2023 is the first certifiable management-system standard for Artificial Intelligence. It sits alongside ISO 27001 and ISO 27701 in the same Annex SL structure, so most organisations can extend existing ISMS governance rather than start from scratch.
Regulators in the UAE, KSA and EU now reference ISO 42001 as evidence of responsible AI deployment.
What the standard requires
- Documented AI policy approved by top management
- AI risk and impact assessments — covering ethical, legal and societal risk
- An AI system lifecycle covering design, data, deployment and decommissioning
- Human oversight and incident response specific to AI systems
- Supplier and third-party AI controls
How it relates to ISO 27001 and the EU AI Act
| Theme | ISO 42001 | ISO 27001 | EU AI Act |
|---|---|---|---|
| Governance | Clauses 4-10 | Clauses 4-10 | Articles 16-29 |
| Risk | 6.1, Annex A.5 | 6.1 | Articles 9, 15 |
| Data | Annex A.7 | A.5.12 – A.5.14 | Article 10 |
| Transparency | Annex A.8 | A.5.34 | Articles 13, 50 |
| Human oversight | Annex A.9 | — | Article 14 |
A 90-day implementation plan
Days 1-30 — Inventory and policy
- Inventory every AI/ML system in production or development
- Classify by use case, data sensitivity and regulatory exposure
- Draft the AI policy and oversight charter
Days 31-60 — Risk and lifecycle
- Run AI impact assessments for the top use cases
- Define the AI lifecycle workflow with mandatory gates
- Add AI-specific clauses to vendor contracts
Days 61-90 — Operational evidence
- Stand up monitoring for drift, bias and incident telemetry
- Train AI owners and reviewers on the new process
- Run an internal audit against Annex A
Next step
MAST is helping clients in financial services and healthcare extend their ISMS to cover ISO 42001 in a single integrated audit. Talk to the AI governance lead.