ISO/IEC 42001
International · AI management systems · Voluntary standard
What it governs
Requirements for establishing, implementing, maintaining, and continually improving an AI management system.
Why it matters for AI agents
AI risk management, impact assessment, governance, lifecycle controls, monitoring, and continual improvement.
Riverfront coverage
Behavioral testing of whether deployed AI systems behave consistently with the risks, controls, and intended outcomes defined by the management system. Not ISO certification.
What ISO/IEC 42001 actually requires from an AI management system
ISO/IEC 42001, published December 18, 2023, is the first international standard for an AI management system, usually shortened to AIMS. It follows the same structure as ISO 27001 for information security and ISO 9001 for quality, which is a deliberate choice: if your organization has already been through one of those certifications, 42001 will feel familiar in shape, even though what it governs is different. Certification is voluntary, and ISO itself does not perform it: independent bodies, accredited by national accreditation bodies, assess organizations against the standard and issue certificates.
At its core, ISO/IEC 42001 combines the management-system requirements in Clauses 4 through 10 with a reference set of AI controls in Annex A. Annex A is a reference set of controls an organization draws from, selected based on its own risk assessment, not applied wholesale. Together they describe a process for managing AI risk responsibly. They do not describe, or test, what a specific deployed system actually does.
What clauses 4 through 10 actually require
Context (Clause 4). Define what the AIMS covers, which systems, which business units, which use cases, and document why that scope was chosen.
Leadership (Clause 5). Top management has to commit to this formally: a documented AI policy stating the organization's position on responsible AI, and named roles and responsibilities for running the system, not a policy that lives in a folder nobody owns.
Planning (Clause 6). This is where the standard's real substance sits. Organizations have to establish AI risk criteria and run a repeatable risk assessment process, producing an AI risk register; select and justify risk treatments, comparing them against Annex A's recommended controls and documenting the result in a Statement of Applicability; set AI objectives that are specific and measurable; and conduct an AI system impact assessment covering the potential consequences of the system's development, deployment, intended use, and reasonably foreseeable misuse for individuals, groups, and society. The clause requires that assessment's findings be fed back into the risk assessment process above, rather than filed as a standalone document.
Support (Clause 7). Adequate resourcing, competent people making AI decisions, organizational awareness, a communications plan, and a defined set of documents that must exist: the AIMS scope, the policy, and records of the assessments above.
Operation (Clause 8). The plan becomes practice. Risk assessments run on a defined cadence, risk treatments actually get implemented, and impact assessments happen with their results kept on record, not just performed once and filed away.
Performance evaluation (Clause 9). The organization has to monitor whether the AIMS itself is working, run internal audits by people independent of what they're auditing, and hold management reviews that actually examine audit findings and system changes.
Improvement (Clause 10). When something does not conform, it has to be investigated, corrected, and prevented from recurring, with continual improvement built into the system rather than treated as a one-time certification event.
What Annex A actually covers
Annex A holds 38 reference controls organized under nine control areas, spanning AI-related policies, internal organization, resourcing, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. An organization does not implement every control. It selects the ones relevant to its own risk assessment and documents that selection, and the reasoning for any exclusions, in the Statement of Applicability, the same mechanism ISO 27001 uses for security controls.
The overlap with the EU AI Act, and where it stops
ISO/IEC 42001 and the EU AI Act overlap in areas such as risk management, documentation, governance, human oversight, and impact assessment. But they do different jobs. ISO/IEC 42001 is a management-system standard; the EU AI Act is law. Certification to ISO/IEC 42001 does not by itself establish compliance with the Act's system-specific legal requirements, including conformity assessment for particular high-risk categories and registration in an EU database. The Act's own mechanics are covered separately in this series.
The more precise way to put the distinction: ISO 42001 certifies that an organization has a working process for managing AI risk. It does not certify that the process caught everything, or that the specific system in front of a specific user, on a specific day, behaved the way the process assumed it would.
The gap between a certified process and a verified system
This is the distinction worth holding onto, because it is easy to lose in a compliance conversation. An organization can be genuinely, legitimately ISO 42001 certified: real risk assessments on file, a real Statement of Applicability, real internal audits that pass. None of that is direct evidence about whether a specific customer-facing agent, deployed under that management system, behaved the way its own risk assessment assumed it would the last time a real user pushed it somewhere unexpected.
A risk assessment might conclude an agent will refuse to give financial advice. Whether it actually refuses, consistently, under a persistent or cleverly worded request, is a behavioral question a management-system audit is not built to answer, because an audit examines whether the process exists and runs, not what the system said in a specific conversation. The management system is the scaffolding. It is not the proof that what was built on top of it holds up.
What this means if you are implementing 42001
If your organization is pursuing 42001 certification, or has already achieved it, the certification itself is real evidence of a functioning governance process, and it is worth having. What it is not is a substitute for checking whether the systems that process runs on actually behave the way the risk assessments underneath it assumed. Two things are worth doing alongside the certification work rather than after it: make sure the impact assessments required under Clause 6 describe testable, specific behavior rather than general intentions, and then check, through the system's actual interface, whether that behavior holds.
This is one layer of a compliance program, not a substitute for one, and it does not constitute legal advice. Riverfront tests agent behavior against the obligations in frameworks like this one; it does not certify compliance with them.
Sources: ISO/IEC 42001:2023, "AI management systems," iso.org/standard/42001, for scope, abstract, publication date (December 18, 2023), and the standard's certification model. ISO, "ISO/IEC 42001 explained" (iso.org), for the standard's stated structure and the point that ISO itself does not certify organizations, accredited certification bodies do. Clause-by-clause detail, including the Clause 6.1.4 AI system impact assessment requirement and the Statement of Applicability process, cross-checked across multiple independent ISO 42001-focused guides: Konfirmity, Glocert International, Cyberzoni, and WatchDog Security. The Annex A structure (38 controls across nine control areas, A.2 through A.10) cross-checked across Vanta, Konfirmity, and Glocert International. Comparative analysis of ISO/IEC 42001 and the EU AI Act per Trustible, ISMS.online, and Vanta. ISO's own standard text is behind ISO's paywall and was not accessed directly for the clause-by-clause or Annex A detail in this pass.