Skip to main content
Argitron
Menu

Framework

ISO/IEC 42001:2023

The first international, certifiable AI Management System standard. Structured like ISO 27001 (clauses 4–10 plus Annex A) so it integrates cleanly with an existing ISMS — most certified organisations are getting both.

9 control objectives ~38 controls Published December 2023 NIST AI RMF crosswalk published

Annex A — 9 areas

AreaThemeWhat it covers
A.2AI policiesDocumented direction for responsible AI
A.3Internal organisationRoles and responsibilities for AI
A.4Resources for AI systemsData, tooling, compute, human resources
A.5Assessing impactsImpacts on individuals, groups, society
A.6AI system lifecycleDesign, develop, verify, deploy, operate, retire
A.7Data for AI systemsProvenance, quality, preparation
A.8Information for interested partiesStakeholder transparency
A.9Use of AI systemsResponsible deployment and operation
A.10Third-party + customer relationshipsSupply-chain AI risk

Like 27001, Annex A is selectively applied; the Statement of Applicability must justify inclusions and exclusions.

Why it matters now

ISO 42001 maps directly to the EU AI Act's management-system and risk-governance obligations. NIST has published a formal crosswalk between the AI RMF and ISO/IEC 42001. CSA and EU AI Compass analyses suggest implementing 42001 + NIST AI RMF gets organisations roughly 60–70% of the way to EU AI Act compliance for the management-system side, with the remaining 30–40% being EU-specific regulatory artefacts (conformity assessments, registration, post-market monitoring).

Boards and CISOs are using 42001 as the "show your work" answer to AI Act readiness.

Real adopters

AWS

First major hyperscaler with accredited 42001, announced November 2024. Scope: Amazon Bedrock, Q Business, Textract, Transcribe.

Anthropic

Certified by Schellman, effective January 6, 2025.

Workday

Public certificate dated 2025.

Synthesia, Cognizant, i-PRO

Among early-mover names certified via BSI / other accredited bodies.

Adoption is in the early-mover phase: roughly 25 certified organisations worldwide as of mid-2025. Schellman (ANAB-accredited) and BSI are the most-cited certification bodies.

What Argitron delivers

AreaCoverage
AI-system inventoryFirst-class data model
A.5 impact assessmentsTemplated DPIA + fundamental-rights + ethics workflows
A.6 lifecycle controlsStage gates from design to retirement
A.7 data governanceLineage records + policy templates
AI policies (A.2) + roles (A.3)Templated; tailoring required
A.10 supply-chain AIVendor-risk workflow extended for AI suppliers
EU AI Act crosswalkBuilt into the control library

Bring an AIMS into the same operating model as your ISMS.

One Statement of Applicability covers ISO 27001 + ISO 42001. One auditor visit. One signed bundle.