ISO/IEC 42001:2023
A certifiable management system standard for artificial intelligence. It sets out what an organisation must put in place to govern the AI systems it develops or uses: scope, leadership, objectives, risk and impact assessment, operational controls, monitoring and improvement.
- Duties mapped
- 89
- Mappings
- 89
- Jurisdictions
- 13
- Clauses used
- 9
- Controls
- 26
- Evidence types
- 23
- Risk areas
- 21
- Recorded incidents
- 1,494
Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.
How it is structured
Requirements sit in clauses 4 to 10, following the harmonised structure shared by other ISO management system standards. Annex A lists reference controls that an organisation selects from and justifies.
Because it is certifiable, ISO/IEC 42001 is what most organisations are audited against. Knowing which legal duties a clause already covers tells you how much of a statute your existing certification evidence reaches.
Legal duties by clause
A duty appears under every clause its mapping cites, so the totals below exceed the 89 distinct duties. References that name no single clause are grouped at the end rather than dropped.
Clause 4 4 duties
-
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
EU AI Act · European Union · cites Clause 4.1; Annex A.10.2
Determining the organisation's role and allocating responsibilities along the chain.
-
Establish AI governance policies, roles and accountability (Govern)
NIST AI RMF · United States (voluntary) · cites Clauses 4–5 and 7
Original editorial mapping: leadership, context and support.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
EU AI Act · European Union · cites Clause 4.2; Annex A.8.3
Interested-party requirements and external reporting.
Clause 5 10 duties
-
Establish AI governance policies, roles and accountability (Govern)
NIST AI RMF · United States (voluntary) · cites Clauses 4–5 and 7
Original editorial mapping: leadership, context and support.
-
Establish accountability and governance for AI
UK AI regulation framework · United Kingdom (voluntary) · cites Clause 5 Leadership
Original editorial mapping.
-
Establish accountability processes and a risk-management process (guardrails 1 and 2)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites Clauses 5 and 6
The standard states it is aligned with ISO/IEC 42001 and the NIST AI RMF.
-
Establish internal governance structures and measures for AI
Singapore Model AI Governance Framework · Singapore (voluntary) · cites Clause 5 Leadership
Original editorial mapping.
-
Foreign AI business operators above the threshold must designate a domestic representative in Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 5.3; Annex A.10.2
Allocation of responsibilities to an external party.
-
Frontier developers must protect employees who report catastrophic-risk concerns
California SB 53 · California (United States) · cites Clause 5.1, 7.4; Annex A.3.2
Leadership, communication and roles.
-
Non-EU providers must appoint an EU authorised representative for high-risk AI
EU AI Act · European Union · cites Clause 5.3; Annex A.10.2
Allocation of responsibilities to an external party.
-
Non-EU providers of GPAI models must appoint an EU authorised representative
EU AI Act · European Union · cites Clause 5.3; Annex A.10.2
Responsibilities allocated to an external party.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Providers must meet the full set of provider duties for high-risk AI
EU AI Act · European Union · cites Clause 5.3; Annex A.3.2
Original editorial mapping to roles, responsibilities and authorities.
Clause 6 19 duties
-
Carry out a data protection impact assessment for high-risk AI processing
ICO AI guidance · United Kingdom · cites Clause 6.1.4 AI system impact assessment
Original editorial mapping.
-
Carry out a fundamental rights impact assessment before deployment
EU AI Act · European Union · cites Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment
Original editorial mapping.
-
Conduct a data protection impact assessment for high-risk processing using new technologies
UAE PDPL · United Arab Emirates · cites Clause 6.1.4 AI system impact assessment
Original editorial mapping.
-
Deployers must complete impact assessments for high-risk AI
Colorado AI Act · Colorado (United States) · cites Clause 6.1.4 AI system impact assessment
Original editorial mapping.
-
Deployers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites Clause 6.1.2; Annex A.9.2
Risk assessment and responsible-use processes.
-
Deployers must use the provider's transparency information in their data protection impact assessment
EU AI Act · European Union · cites Clause 6.1.4; Annex A.5.2
AI system impact assessment process.
-
Developers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites Clause 6.1.2, 6.1.3
AI risk assessment and treatment.
-
Do not deploy or provide AI for prohibited practices
EU AI Act · European Union · cites Clause 6.1.2 and Annex A control on AI system impact assessment
Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses.
-
Ensure AI systems are safe, secure and robust throughout their lifecycle
UK AI regulation framework · United Kingdom (voluntary) · cites Clause 6.1 and Annex A risk controls
Original editorial mapping.
-
Establish a risk management system for high-risk AI
EU AI Act · European Union · cites Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk
Original editorial mapping.
-
Establish accountability processes and a risk-management process (guardrails 1 and 2)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites Clauses 5 and 6
The standard states it is aligned with ISO/IEC 42001 and the NIST AI RMF.
-
Governmental entities must not use AI for social scoring
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Clause 6.1.4; Annex A.5.2
Impact assessment identifies detrimental treatment.
-
Map context, intended use and potential impacts (Map)
NIST AI RMF · United States (voluntary) · cites Clause 6.1.4 AI system impact assessment
Original editorial mapping.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Operators of AI above the compute threshold must run lifecycle risk management and report safety results
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 6.1.2, 6.1.3, 9.1
Risk assessment, treatment and monitoring.
-
Operators of high-impact AI must establish and operate a risk management plan
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 6.1.2, 6.1.3, 8.1
Risk assessment, treatment and operational planning.
-
Operators of high-impact AI should assess its impact on fundamental rights before use
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea (voluntary) · cites Clause 6.1.4; Annex A.5.2, A.5.4
AI system impact assessment on individuals and society.
-
Providers must document and register a conclusion that an Annex III system is not high-risk
EU AI Act · European Union · cites Clause 6.1.2; Annex A.6.2.7
Risk-based classification recorded in the technical documentation.
-
Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
India DPDP Act · India · cites Clause 6.1.4 AI system impact assessment
Original editorial mapping.
Clause 7 8 duties
-
Draw up technical documentation before placing a high-risk system on the market
EU AI Act · European Union · cites Clause 7.5 Documented information; Annex A control on system documentation
Original editorial mapping.
-
Ensure AI literacy of staff operating AI systems
EU AI Act · European Union · cites Clause 7.2 Competence and 7.3 Awareness
Original editorial mapping.
-
Establish AI governance policies, roles and accountability (Govern)
NIST AI RMF · United States (voluntary) · cites Clauses 4–5 and 7
Original editorial mapping: leadership, context and support.
-
Frontier developers must protect employees who report catastrophic-risk concerns
California SB 53 · California (United States) · cites Clause 5.1, 7.4; Annex A.3.2
Leadership, communication and roles.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 7.5; Annex A.6.2.7, A.9.3
Documented information, technical documentation and objectives for responsible use.
-
Providers must keep high-risk AI documentation for ten years
EU AI Act · European Union · cites Clause 7.5.3; Annex A.6.2.7
Control of documented information and technical documentation.
-
Providers must supply conformity evidence and log access to authorities on request
EU AI Act · European Union · cites Clause 7.5; Annex A.8.3
Documented information available for external reporting.
Clause 8 5 duties
-
Establish a risk management system for high-risk AI
EU AI Act · European Union · cites Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk
Original editorial mapping.
-
Manage data quality, model development and monitoring across the lifecycle
Singapore Model AI Governance Framework · Singapore (voluntary) · cites Clause 8 Operation; Annex A data controls
Original editorial mapping.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Operators of high-impact AI must establish and operate a risk management plan
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 6.1.2, 6.1.3, 8.1
Risk assessment, treatment and operational planning.
-
Prioritise, respond to and monitor AI risks (Manage)
NIST AI RMF · United States (voluntary) · cites Clauses 8 and 10
Operation and improvement.
Clause 9 8 duties
-
Complete conformity assessment, CE marking and EU database registration
EU AI Act · European Union · cites Clause 9 Performance evaluation; internal audit
Original editorial mapping; not a substitute for legal conformity assessment.
-
Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
EU AI Act · European Union · cites Clause 9.1; Annex A.6.2.6, A.8.4
Operation and monitoring; communication of incidents.
-
Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites Annex A.6.2.4; Clause 9.2
Verification and validation; independent audit.
-
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
California SB 53 · California (United States) · cites Clause 9.1; Annex A.8.3
Monitoring and external reporting.
-
Measure and test trustworthiness characteristics (Measure)
NIST AI RMF · United States (voluntary) · cites Clause 9 Performance evaluation; Annex A verification controls
Original editorial mapping.
-
Operate a post-market monitoring system
EU AI Act · European Union · cites Clause 9.1 Monitoring, measurement, analysis and evaluation
Original editorial mapping.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Operators of AI above the compute threshold must run lifecycle risk management and report safety results
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 6.1.2, 6.1.3, 9.1
Risk assessment, treatment and monitoring.
Clause 10 6 duties
-
Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites Clause 10.2; Annex A.8.4
Corrective action and incident communication.
-
Operate a quality management system
EU AI Act · European Union · cites Whole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
-
Prioritise, respond to and monitor AI risks (Manage)
NIST AI RMF · United States (voluntary) · cites Clauses 8 and 10
Operation and improvement.
-
Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
EU AI Act · European Union · cites Clause 10.2; Annex A.8.4
Nonconformity and corrective action; communication of incidents.
-
Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
EU AI Act · European Union · cites Clause 10.2; Annex A.8.4
Corrective action and incident communication.
-
Report serious incidents to market surveillance authorities
EU AI Act · European Union · cites Clause 10 Improvement; Annex A control on incident handling
Original editorial mapping.
Annex A 71 duties
-
AI business operators must label generative AI output and clearly flag realistic synthetic media
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Annex A.8.2, A.8.5
System documentation and information for interested parties.
-
AI business operators must notify users in advance that a product or service runs on high-impact or generative AI
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Annex A.8.5
Information for interested parties.
-
Achieve appropriate accuracy, robustness and cybersecurity
EU AI Act · European Union · cites Annex A controls on AI system verification and validation
Original editorial mapping.
-
Apply data governance and quality criteria to training, validation and testing data
EU AI Act · European Union · cites Annex A controls on data for AI systems
Original editorial mapping.
-
Carry out a fundamental rights impact assessment before deployment
EU AI Act · European Union · cites Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment
Original editorial mapping.
-
Collect and use personal information only with consent and for the stated purpose
Nepal Privacy Act 2075 · Nepal · cites Annex A controls on data for AI systems
Original editorial mapping.
-
Deployers and developers must disclose to consumers that they are interacting with an AI system
Colorado AI Act · Colorado (United States) · cites Annex A.8.5
Information for interested parties.
-
Deployers must disclose deepfakes and AI-generated text published on matters of public interest
EU AI Act · European Union · cites Annex A.9.2, A.8.5
Responsible-use processes and information to interested parties.
-
Deployers must ensure input data they control is relevant and representative
EU AI Act · European Union · cites Annex A.7.4, A.7.6
Data quality and data preparation.
-
Deployers must explain individual decisions taken with high-risk AI on request
EU AI Act · European Union · cites Annex A.8.5, A.9.2
Information for interested parties and responsible-use processes.
-
Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
EU AI Act · European Union · cites Clause 9.1; Annex A.6.2.6, A.8.4
Operation and monitoring; communication of incidents.
-
Deployers must notify the Attorney General of discovered algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites Annex A.8.4
Communication of incidents.
-
Deployers must publish a statement about the high-risk AI systems they use
Colorado AI Act · Colorado (United States) · cites Annex A.8.5
Information for interested parties.
-
Deployers must tell natural persons that a high-risk AI system is used in decisions about them
EU AI Act · European Union · cites Annex A.8.5
Information for interested parties.
-
Deployers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites Clause 6.1.2; Annex A.9.2
Risk assessment and responsible-use processes.
-
Deployers must use the provider's transparency information in their data protection impact assessment
EU AI Act · European Union · cites Clause 6.1.4; Annex A.5.2
AI system impact assessment process.
-
Deployers of emotion recognition or biometric categorisation must inform exposed persons
EU AI Act · European Union · cites Annex A.8.5
Information for interested parties.
-
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
EU AI Act · European Union · cites Clause 4.1; Annex A.10.2
Determining the organisation's role and allocating responsibilities along the chain.
-
Design high-risk systems to log events automatically
EU AI Act · European Union · cites Annex A control on event logging
Original editorial mapping.
-
Developers and deployers must not use AI to incite self-harm, harm to others or crime
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Annex A.9.4, A.6.1.2
Intended use and system objectives.
-
Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Annex A.6.1.2, A.9.4
Objectives and intended use recorded.
-
Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Annex A.9.4
Intended use of the AI system.
-
Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites Clause 10.2; Annex A.8.4
Corrective action and incident communication.
-
Disclose AI interaction and label synthetic content
EU AI Act · European Union · cites Annex A control on communication with interested parties
Original editorial mapping.
-
Do not deploy or provide AI for prohibited practices
EU AI Act · European Union · cites Clause 6.1.2 and Annex A control on AI system impact assessment
Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses.
-
Draw up technical documentation before placing a high-risk system on the market
EU AI Act · European Union · cites Clause 7.5 Documented information; Annex A control on system documentation
Original editorial mapping.
-
Employers and employment agencies must disclose the data collected and their retention policy for the tool
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites Annex A.7.2, A.8.5
Data management and information for interested parties.
-
Employers and employment agencies must let candidates request an alternative selection process or accommodation
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites Annex A.9.2
Processes for responsible use.
-
Employers and employment agencies must notify candidates and employees before an automated tool is used
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites Annex A.8.5
Information for interested parties.
-
Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites Annex A.6.2.4; Clause 9.2
Verification and validation; independent audit.
-
Employers and employment agencies must publish a summary of the bias audit results
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites Annex A.8.3, A.8.5
External reporting and information for interested parties.
-
Employers must inform workers and their representatives before using high-risk AI at work
EU AI Act · European Union · cites Annex A.8.5
Information for interested parties.
-
Enable and assign effective human oversight
EU AI Act · European Union · cites Annex A control on human oversight
Original editorial mapping.
-
Ensure AI systems are safe, secure and robust throughout their lifecycle
UK AI regulation framework · United Kingdom (voluntary) · cites Clause 6.1 and Annex A risk controls
Original editorial mapping.
-
Establish a risk management system for high-risk AI
EU AI Act · European Union · cites Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk
Original editorial mapping.
-
Foreign AI business operators above the threshold must designate a domestic representative in Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 5.3; Annex A.10.2
Allocation of responsibilities to an external party.
-
Frontier developers must protect employees who report catastrophic-risk concerns
California SB 53 · California (United States) · cites Clause 5.1, 7.4; Annex A.3.2
Leadership, communication and roles.
-
Frontier developers must publish a transparency report before deploying a new frontier model
California SB 53 · California (United States) · cites Annex A.8.2, A.8.3
System documentation and external reporting.
-
Government agencies must disclose to consumers that they are interacting with an AI system
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Annex A.8.5
Information for interested parties.
-
Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Annex A.5.2, A.7.3
Impact assessment and data acquisition.
-
Governmental entities must not use AI for social scoring
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Clause 6.1.4; Annex A.5.2
Impact assessment identifies detrimental treatment.
-
Health-care providers must disclose the use of AI in patient services
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites Annex A.8.5
Information for interested parties.
-
Identify consent or an applicable PDPA exception before using personal data in AI
PDPC AI advisory guidelines · Singapore · cites Annex A controls on data for AI systems
Original editorial mapping.
-
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
California SB 53 · California (United States) · cites Clause 9.1; Annex A.8.3
Monitoring and external reporting.
-
Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
EU AI Act · European Union · cites Annex A.9.2, A.9.4
Processes for responsible use and intended use.
-
Manage data quality, model development and monitoring across the lifecycle
Singapore Model AI Governance Framework · Singapore (voluntary) · cites Clause 8 Operation; Annex A data controls
Original editorial mapping.
-
Measure and test trustworthiness characteristics (Measure)
NIST AI RMF · United States (voluntary) · cites Clause 9 Performance evaluation; Annex A verification controls
Original editorial mapping.
-
Meet general-purpose AI model provider obligations
EU AI Act · European Union · cites Annex A controls on data provenance and documentation
Original editorial mapping.
-
Non-EU providers must appoint an EU authorised representative for high-risk AI
EU AI Act · European Union · cites Clause 5.3; Annex A.10.2
Allocation of responsibilities to an external party.
-
Non-EU providers of GPAI models must appoint an EU authorised representative
EU AI Act · European Union · cites Clause 5.3; Annex A.10.2
Responsibilities allocated to an external party.
-
Operators of high-impact AI must be able to explain outputs and the main criteria behind them
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Annex A.8.2, A.7.3
System documentation and data documentation.
-
Operators of high-impact AI must ensure human management and supervision
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Annex A.9.2
Processes for responsible use including human oversight.
-
Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites Clause 7.5; Annex A.6.2.7, A.9.3
Documented information, technical documentation and objectives for responsible use.
-
Operators of high-impact AI should assess its impact on fundamental rights before use
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea (voluntary) · cites Clause 6.1.4; Annex A.5.2, A.5.4
AI system impact assessment on individuals and society.
-
Process personal data only with valid consent or a legitimate use, after notice
India DPDP Act · India · cites Annex A controls on data for AI systems
Original editorial mapping.
-
Provide deployers with clear instructions for use
EU AI Act · European Union · cites Annex A controls on information for interested parties
Original editorial mapping.
-
Providers must document and register a conclusion that an Annex III system is not high-risk
EU AI Act · European Union · cites Clause 6.1.2; Annex A.6.2.7
Risk-based classification recorded in the technical documentation.
-
Providers must keep high-risk AI documentation for ten years
EU AI Act · European Union · cites Clause 7.5.3; Annex A.6.2.7
Control of documented information and technical documentation.
-
Providers must meet the full set of provider duties for high-risk AI
EU AI Act · European Union · cites Clause 5.3; Annex A.3.2
Original editorial mapping to roles, responsibilities and authorities.
-
Providers must retain automatically generated logs under their control
EU AI Act · European Union · cites Annex A.6.2.8
AI system recording of event logs.
-
Providers must supply conformity evidence and log access to authorities on request
EU AI Act · European Union · cites Clause 7.5; Annex A.8.3
Documented information available for external reporting.
-
Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
EU AI Act · European Union · cites Clause 10.2; Annex A.8.4
Nonconformity and corrective action; communication of incidents.
-
Providers of GPAI models must maintain technical documentation and inform downstream providers
EU AI Act · European Union · cites Annex A.6.2.7, A.8.2, A.10.4
Technical documentation, system documentation and information for customers.
-
Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
EU AI Act · European Union · cites Clause 4.2; Annex A.8.3
Interested-party requirements and external reporting.
-
Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
EU AI Act · European Union · cites Annex A.8.2, A.6.2.4
System documentation; verification and validation of the marking.
-
Providers of high-risk AI must have written agreements with suppliers of components, tools and services
EU AI Act · European Union · cites Annex A.10.3
Supplier relationships aligned with the organisation's AI responsibilities.
-
Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
EU AI Act · European Union · cites Clause 10.2; Annex A.8.4
Corrective action and incident communication.
-
Public authorities must register their use of high-risk AI and must not use unregistered systems
EU AI Act · European Union · cites Annex A.8.2, A.8.5
System documentation and information for interested parties.
-
Report serious incidents to market surveillance authorities
EU AI Act · European Union · cites Clause 10 Improvement; Annex A control on incident handling
Original editorial mapping.
-
Use high-risk AI as instructed, monitor it and inform affected people
EU AI Act · European Union · cites Annex A controls on responsible use of AI systems
Original editorial mapping.
-
Verify conformity before importing or distributing high-risk AI
EU AI Act · European Union · cites Annex A controls on third parties and suppliers
Original editorial mapping.
Other references 1 duty
-
Deployers must implement a risk management policy and programme
Colorado AI Act · Colorado (United States) · cites Whole management system (named in the statute)
The statute names ISO/IEC 42001 as a recognised framework.
Controls that cite this standard
Each control is an original description of what an organisation operates. The reference is the clause it corresponds to, by number only.
| Control | Clause | Duties served | Evidence |
|---|---|---|---|
| AI governance policy and accountability structure Policy | Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3 | 16 | AI policy, Board or executive approval of the AI policy, AI governance forum minutes |
| AI impact and fundamental-rights impact assessment Process | Clause 6.1.4, 8.4; Annex A.5 | 11 | AI impact assessment, Impact assessment approval, Impact assessment procedure and template |
| AI incident management and regulatory reporting Process | Clause 10.2; Annex A.8.3, A.8.4 | 14 | AI incident response playbook, AI incident record, Incident report to an authority |
| AI interaction and use disclosure notices Process | Annex A.8.2, A.8.5 | 17 | AI interaction or use notice, Notice catalogue, Notice wording approval |
| AI literacy and role-based training programme Training programme | Clause 7.2, 7.3; Annex A.4.6 | 4 | AI training completion records, Role-to-curriculum training matrix, AI training curriculum and materials |
| AI risk assessment and lifecycle risk register Process | Clause 6.1.2, 6.1.3, 8.2, 8.3 | 12 | AI system risk assessment, Per-system AI risk register, Residual-risk acceptance |
| AI system inventory and classification Process | Clause 4.1, 4.3, 8.1; Annex A.6.2.2, A.9.4 | 11 | AI system register, Risk-tier classification sign-off, AI intake and classification procedure |
| Accuracy, robustness, fairness and security testing Technical measure | Annex A.6.2.4 | 15 | Pre-release test report, Test plan and acceptance criteria, Release test sign-off |
| Adversarial and red-team testing for generative AI Technical measure | Annex A.6.2.4 | 8 | Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker |
| Automatic event logging and record retention Technical measure | Annex A.6.2.8 | 8 | AI system event logs, Log schema and retention standard, Log integrity and retention check |
| Conformity assessment, declaration and registration Process | Clause 9.2; Annex A.6.2.7 | 4 | Declaration of conformity or certificate, Registration record in the relevant database, Conformity evidence pack |
| Contractual allocation of AI duties across the supply chain Contractual term | Annex A.10.2, A.10.3, A.10.4 | 8 | AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register |
| Data governance and dataset documentation Process | Annex A.7.2, A.7.3, A.7.4, A.7.6 | 8 | Dataset documentation sheet, Data quality and bias check report, Dataset approval for use |
| Decision explanation, human review and appeal route Process | Annex A.8.2, A.8.3, A.9.2 | 10 | Adverse-decision explanation template, AI decision challenge and human review procedure, Challenge and reversal log |
| Frontier model safety and security framework Policy | Clause 5.2, 6.1.2; Annex A.6.1.2 | 9 | Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority |
| Human oversight design and override procedure Process | Annex A.6.2.5, A.9.2, A.9.3 | 11 | Human oversight and override procedure, Human-involvement design rationale, Overseer training completion |
| Model release and change-management gate Process | Clause 8.1; Annex A.6.2.5, A.6.1.3 | 5 | Release or change approval record, Release and change-classification procedure |
| Post-deployment monitoring and drift detection Technical measure | Clause 9.1; Annex A.6.2.6 | 10 | Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision |
| Privacy and data-protection controls for AI Process | Annex A.7.2, A.7.3; Clause 6.1.4 | 13 | Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use |
| Prohibited and unacceptable-use screening gate Process | Clause 6.1.4; Annex A.5.2, A.9.3 | 7 | Prohibited-use screening record, Screening list and escalation procedure |
| Public-sector AI use-case register and algorithmic transparency Process | Clause 4.1; Annex A.8.5 | 6 | Public AI use-case inventory, Algorithmic transparency statement for one use case, Inventory review and publication sign-off |
| Quality management system for AI development and supply Policy | Clause 4 to 10 | 3 | AI quality management system manual, Internal audit of the AI management system, Management review minutes |
| Synthetic content labelling and provenance marking Technical measure | Annex A.8.2, A.9.3 | 5 | Content labelling and provenance standard, Watermark and provenance robustness test, Visible AI-generated content label |
| Technical documentation, model cards and instructions for use Process | Clause 7.5; Annex A.6.2.3, A.6.2.7, A.8.2 | 13 | Technical documentation file, Model card or deployer information pack, Instructions for use |
| Training-data provenance and copyright register Process | Annex A.7.3, A.7.5 | 4 | Training source register, Copyright and rights-reservation policy, Public summary of training content |
| Vendor and third-party AI due diligence Process | Annex A.10.2, A.10.3 | 6 | AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- What is ISO/IEC 42001:2023?
- A certifiable management system standard for artificial intelligence. It sets out what an organisation must put in place to govern the AI systems it develops or uses: scope, leadership, objectives, risk and impact assessment, operational controls, monitoring and improvement.
- Does ISO/IEC 42001 make an organisation legally compliant?
- No. Certification evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.