A CERT-In Empanelled Auditing Organization
Home/Blog/AI Governance
AI Governance

Building an AI Management System (AIMS) with ISO/IEC 42001

AI is no longer a side project. It sits inside products you ship and tools your teams use every day, and with it comes a new class of risk: opaque decisions, biased outputs, leaked data and a growing stack of regulation. An AI Management System (AIMS) is how you bring that under control, the same way an ISMS brought order to information security.

The standard for an AIMS is ISO/IEC 42001:2023, the first certifiable management-system standard for artificial intelligence. This post explains what an AIMS is, what the standard asks for, and how to build one.

What an AIMS is

An AIMS is a structured, auditable framework for governing AI across its life cycle: the policies, roles, risk assessments, controls and reviews that make sure the AI your organisation builds or uses is responsible, safe and accountable. ISO/IEC 42001 follows the same high-level structure as ISO 27001 and ISO 9001, so if you already run a management system, the shape will feel familiar.

Why build one now

Three forces are converging: regulation is arriving (the EU AI Act reaches well beyond Europe, and India’s DPDP regime governs the personal data AI feeds on), customers are starting to ask how you govern AI in security and procurement reviews, and “shadow AI” is already in your organisation whether you have sanctioned it or not. An AIMS gives you one credible, independent answer to all three.

What ISO/IEC 42001 asks for

Like other ISO management systems, 42001 is built around seven clauses (4 to 10). Together they form the management cycle an auditor will check.

Context (Clause 4)Define the scope of the AIMS and which AI systems and uses it covers.
Leadership (Clause 5)Top-management commitment and an AI policy with clear roles.
Planning (Clause 6)AI risk assessment and AI system impact assessment, with objectives.
Support (Clause 7)Resources, competence, awareness, communication and documentation.
Operation (Clause 8)Run the controls across the AI life cycle, day to day.
Performance evaluation (Clause 9)Monitoring, measurement, internal audit and management review.
Improvement (Clause 10)Corrective action and continual improvement of the system.

The Annex A control themes

Alongside the clauses, Annex A sets out the control areas you choose from, in proportion to your risk, and record in a Statement of Applicability.

Policies related to AIA documented position on how AI is developed and used.
Internal organisationRoles, responsibilities and accountability for AI.
Resources for AI systemsData, tooling, compute and competent people.
Assessing impactsImpacts of AI systems on individuals and society.
AI system life cycleResponsible development, deployment and retirement.
Data for AI systemsQuality, provenance and governance of training and operational data.
Information for interested partiesTransparency to users, regulators and the public.
Responsible use of AIControls around how AI systems are actually used.
Third-party relationshipsManaging AI risk across suppliers and customers.

How to build your AIMS

You do not need to boil the ocean. A proportionate AIMS can be stood up in a handful of deliberate steps.

1

Scope & context

Decide which AI systems and uses are in scope, and whether you are a developer, a user, or both.

2

Leadership & AI policy

Secure management commitment, set an AI policy, and assign clear ownership.

3

AI risk & impact assessment

Assess risk to the organisation and impact on people, then plan treatment.

4

Apply Annex A controls

Select proportionate controls and record them in a Statement of Applicability.

5

Operate across the life cycle

Embed data governance, documentation and supplier controls into how you build and use AI.

6

Audit, review & improve

Run internal audits and management reviews, fix gaps, and certify when ready.

The payoff

Done well, an AIMS turns AI from an unmanaged liability into a governed capability: you can show a regulator, a board and a customer exactly how AI is controlled, and you catch problems, bias, data leakage, drift, before they become incidents. Certification to ISO/IEC 42001 makes that credible to people who were not in the room.

The bottom line

If your organisation builds or uses AI, an AI Management System is the structure that keeps it safe, lawful and trusted. ISO/IEC 42001 gives you a recognised framework to build it on, and a certificate to prove it.

Keep reading

Related insights

AI Governance

Shadow AI: the governance risk hiding in your organisation

Your staff are already using AI tools you may not know about. What shadow AI is, the risks it creates, and how to bring it into the light.

3 min read
AI Governance

The EU AI Act, explained for organisations outside Europe

The EU AI Act can reach organisations well beyond Europe. What it is, why it might apply to you, and how its phased, risk-based rules work.

5 min read
AI Governance

Writing an AI acceptable-use policy for your organisation

The simplest, highest-impact AI governance step: a clear acceptable-use policy. What to put in it, and how to make it stick.

3 min read

Have a question this raised?

Our team turns guidance like this into working compliance and security programmes. Tell us where you are, we’ll help you plan the next step.