ISO/IEC 42001

Where an AI management system can support European governance work, and where AI Act analysis must remain separate.

What does ISO/IEC 42001 contribute in Europe?

ISO/IEC 42001 specifies an AI management system for organizations that develop, provide, or use AI. It creates a method for assigning responsibility, assessing risk and impact, controlling the AI lifecycle, checking performance, and improving decisions. For a company selling AI-enabled services across European markets, a consistent management system can make governance legible to customers and internal leadership.

The standard is an organizational framework. It does not, by itself, decide whether a particular use is prohibited, high risk, or subject to a specific EU AI Act duty. Nor is an ISO/IEC 42001 certificate a legal approval to place an AI system on the EU market.

Where must AI Act analysis remain separate?

The EU AI Act is risk based and assigns obligations according to the AI system and the organization’s role. An organization may be a provider, deployer, importer, distributor, or hold more than one role across its portfolio. Classification depends on the facts of a particular system, its intended purpose, and the rules that apply at the relevant time.

Keep a legal obligations register next to the AIMS. For each system, record intended purpose, affected persons, role, classification rationale, applicable requirements, owner, and evidence. Review this with qualified counsel, especially when a product or market changes. Regulatory guidance and implementation details evolve; the management system should make reassessment easy rather than encode one static answer.

How should the operating model be built?

Start with an AI inventory spanning customer products, employee tools, and third-party services. Assign an accountable owner and connect each use to its data, model or provider, decisions, and users. Set review gates for procurement, design, evaluation, release, monitoring, and retirement. Higher-impact uses need more rigorous review and clear escalation to legal, privacy, security, and product leaders.

Existing ISO/IEC 27001 routines for information security risk, supplier review, incidents, and improvement can be reused where they fit. The AIMS must also address the effects and behavior of AI systems, including the organization’s choices about oversight, evaluation, and change. A security audit alone cannot answer those questions.

What evidence helps both governance and buyer review?

Maintain the scope, policy, system inventory, risk and impact decisions, lifecycle records, monitoring results, exceptions, and management reviews. These records show how the organization reached a decision and whether its safeguards operate. Map them to customer questions and legal obligations without treating one mapping as proof of complete compliance.

Put it into practice

  • Inventory AI systems and record your role for each one.
  • Keep AI Act classification and legal duties in a separate, reviewed register.
  • Assign risk, impact, oversight, and change decisions to named owners.
  • Use AIMS records to support governance, customer review, and reassessment.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources