AIPolicyTracker
Certifiable ISO and IEC · 2023

ISO/IEC 42001:2023

A certifiable management system standard for artificial intelligence. It sets out what an organisation must put in place to govern the AI systems it develops or uses: scope, leadership, objectives, risk and impact assessment, operational controls, monitoring and improvement.

Duties mapped
89
Mappings
89
Jurisdictions
13
Clauses used
9
Evidence types
23
Risk areas
21
Recorded incidents
1,494

Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.

How it is structured

Requirements sit in clauses 4 to 10, following the harmonised structure shared by other ISO management system standards. Annex A lists reference controls that an organisation selects from and justifies.

Because it is certifiable, ISO/IEC 42001 is what most organisations are audited against. Knowing which legal duties a clause already covers tells you how much of a statute your existing certification evidence reaches.

Legal duties by clause

A duty appears under every clause its mapping cites, so the totals below exceed the 89 distinct duties. References that name no single clause are grouped at the end rather than dropped.

Clause 4 4 duties

Clause 5 10 duties

Clause 6 19 duties

Clause 7 8 duties

Clause 8 5 duties

Clause 9 8 duties

Clause 10 6 duties

Annex A 71 duties

Other references 1 duty

Controls that cite this standard

Each control is an original description of what an organisation operates. The reference is the clause it corresponds to, by number only.

Controls referencing ISO/IEC 42001
ControlClauseDuties servedEvidence
AI governance policy and accountability structure
Policy
Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.316AI policy, Board or executive approval of the AI policy, AI governance forum minutes
AI impact and fundamental-rights impact assessment
Process
Clause 6.1.4, 8.4; Annex A.511AI impact assessment, Impact assessment approval, Impact assessment procedure and template
AI incident management and regulatory reporting
Process
Clause 10.2; Annex A.8.3, A.8.414AI incident response playbook, AI incident record, Incident report to an authority
AI interaction and use disclosure notices
Process
Annex A.8.2, A.8.517AI interaction or use notice, Notice catalogue, Notice wording approval
AI literacy and role-based training programme
Training programme
Clause 7.2, 7.3; Annex A.4.64AI training completion records, Role-to-curriculum training matrix, AI training curriculum and materials
AI risk assessment and lifecycle risk register
Process
Clause 6.1.2, 6.1.3, 8.2, 8.312AI system risk assessment, Per-system AI risk register, Residual-risk acceptance
AI system inventory and classification
Process
Clause 4.1, 4.3, 8.1; Annex A.6.2.2, A.9.411AI system register, Risk-tier classification sign-off, AI intake and classification procedure
Accuracy, robustness, fairness and security testing
Technical measure
Annex A.6.2.415Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Adversarial and red-team testing for generative AI
Technical measure
Annex A.6.2.48Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker
Automatic event logging and record retention
Technical measure
Annex A.6.2.88AI system event logs, Log schema and retention standard, Log integrity and retention check
Conformity assessment, declaration and registration
Process
Clause 9.2; Annex A.6.2.74Declaration of conformity or certificate, Registration record in the relevant database, Conformity evidence pack
Contractual allocation of AI duties across the supply chain
Contractual term
Annex A.10.2, A.10.3, A.10.48AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register
Data governance and dataset documentation
Process
Annex A.7.2, A.7.3, A.7.4, A.7.68Dataset documentation sheet, Data quality and bias check report, Dataset approval for use
Decision explanation, human review and appeal route
Process
Annex A.8.2, A.8.3, A.9.210Adverse-decision explanation template, AI decision challenge and human review procedure, Challenge and reversal log
Frontier model safety and security framework
Policy
Clause 5.2, 6.1.2; Annex A.6.1.29Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Human oversight design and override procedure
Process
Annex A.6.2.5, A.9.2, A.9.311Human oversight and override procedure, Human-involvement design rationale, Overseer training completion
Model release and change-management gate
Process
Clause 8.1; Annex A.6.2.5, A.6.1.35Release or change approval record, Release and change-classification procedure
Post-deployment monitoring and drift detection
Technical measure
Clause 9.1; Annex A.6.2.610Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision
Privacy and data-protection controls for AI
Process
Annex A.7.2, A.7.3; Clause 6.1.413Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use
Prohibited and unacceptable-use screening gate
Process
Clause 6.1.4; Annex A.5.2, A.9.37Prohibited-use screening record, Screening list and escalation procedure
Public-sector AI use-case register and algorithmic transparency
Process
Clause 4.1; Annex A.8.56Public AI use-case inventory, Algorithmic transparency statement for one use case, Inventory review and publication sign-off
Quality management system for AI development and supply
Policy
Clause 4 to 103AI quality management system manual, Internal audit of the AI management system, Management review minutes
Synthetic content labelling and provenance marking
Technical measure
Annex A.8.2, A.9.35Content labelling and provenance standard, Watermark and provenance robustness test, Visible AI-generated content label
Technical documentation, model cards and instructions for use
Process
Clause 7.5; Annex A.6.2.3, A.6.2.7, A.8.213Technical documentation file, Model card or deployer information pack, Instructions for use
Training-data provenance and copyright register
Process
Annex A.7.3, A.7.54Training source register, Copyright and rights-reservation policy, Public summary of training content
Vendor and third-party AI due diligence
Process
Annex A.10.2, A.10.36AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

What is ISO/IEC 42001:2023?
A certifiable management system standard for artificial intelligence. It sets out what an organisation must put in place to govern the AI systems it develops or uses: scope, leadership, objectives, risk and impact assessment, operational controls, monitoring and improvement.
Does ISO/IEC 42001 make an organisation legally compliant?
No. Certification evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.