ISO/IEC 42001 AI Management System
Obligations Covered
AI Risk Management System #
Requirements
| Requirement | Details |
|---|---|
| Risk assessment | Establish processes to identify and assess AI-related risks |
| Risk treatment | Implement controls to treat identified risks |
| Objectives | Set measurable AI management objectives |
| Leadership commitment | Top management must demonstrate commitment to the AI management system |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | Voluntary — certification-based, no direct penalties |
AI Data Governance #
Requirements
| Requirement | Details |
|---|---|
| Data quality | Establish processes for ensuring AI training and operational data quality |
| Data provenance | Document data sources and lineage |
| Data lifecycle | Manage data throughout the AI system lifecycle |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | Voluntary — certification-based |
AI Documentation and Record-Keeping #
Requirements
| Requirement | Details |
|---|---|
| Documented information | Maintain documented information required by the AI management system |
| Performance evaluation | Monitor, measure, analyze, and evaluate AI system performance |
| Internal audit | Conduct internal audits at planned intervals |
| Management review | Top management must review the AI management system at planned intervals |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | Voluntary — certification-based |