Now that you know what ISO/IEC 42001 is at a high level, let me open the document with you and show you what is actually inside. Most students I coach do not do this. They read blog articles about the standard, they read commentary. They rarely read the standard itself. That is a mistake. The standard is not long — the core normative text is about forty pages, plus the annexes. You will save yourself weeks of confusion by reading it once in full early. This lesson is a guided walk through what you will find when you open it.
The ten clauses
ISO/IEC 42001:2023 uses the ISO Annex SL Harmonised Structure. That is the same structure ISO 27001 uses, ISO 9001 uses, ISO 22301 uses. If you have run any of those, the shape will be familiar. If you have not, this is the shape:
| Clause | Title | What it does |
|---|---|---|
| 0 | Introduction | Non-normative context. Explains why the standard exists. |
| 1 | Scope | Says what the standard is meant to cover. |
| 2 | Normative references | Points to ISO/IEC 22989 for terminology. |
| 3 | Terms and definitions | Additional AIMS-specific terms not in 22989. |
| 4 | Context of the organization | Understand your context, identify interested parties, determine the AIMS scope, run the AIMS. |
| 5 | Leadership | Top management commitment, AI policy, roles and responsibilities. |
| 6 | Planning | Address AI risks and opportunities, run AI risk assessment, plan risk treatment, set AI objectives, plan changes. |
| 7 | Support | Resources, competence, awareness, communication, documented information. |
| 8 | Operation | Operational planning and control, execute AI risk assessment and treatment, run AI impact assessment. |
| 9 | Performance evaluation | Monitor and measure, internal audit, management review. |
| 10 | Improvement | Continual improvement, handle nonconformity, corrective action. |
Clauses 0 through 3 are the prologue. The certifiable, normative text is Clauses 4 through 10. When your auditor sits across from you at Stage 1 and Stage 2, they will systematically walk each of Clauses 4 through 10 with you. Not because they are being pedantic — because that is what the standard requires them to do. Every clause requires the organisation to have done something specific. The auditor asks to see the evidence.
The Annexes
After Clause 10 comes the Annexes. This is where ISO 42001 diverges from ISO 27001 in a way you must understand.
ISO 27001 has one normative Annex — Annex A — listing 93 controls. If you have run 27001, you already know that Annex A of 27001 is not optional. Every control gets an Include / Exclude decision in your Statement of Applicability.
ISO 42001 has four Annexes and the roles are different:
- Annex A (normative) — 38 AI-specific controls organised across 9 control groups from A.2 to A.10. Just like in 27001, every A control gets an Include / Exclude decision in your Statement of Applicability.
- Annex B (informative) — implementation guidance for the Annex A controls. This is where the standard explains how to actually operationalise each control. Read it alongside Annex A. Auditors do not require you to follow Annex B, but they will read your evidence expecting it to look like something derived from Annex B guidance.
- Annex C (informative) — potential AI-related organisational objectives and risk sources. A catalogue of the sort of things that end up on your AI risk register (data quality, bias, transparency, accountability, safety, security, environmental impact, and so on).
- Annex D (informative) — using the AIMS across specific domains. Notes on how the AIMS applies in healthcare, defence, finance, education, and so on.
So when you build your AIMS, you certify against the clauses and against Annex A. You use Annex B, C and D as informative reading. That is the shape.
The 9 control groups of Annex A
Annex A is where the AI-specific requirements live. This is what makes ISO 42001 an AI standard rather than an ISMS. Let me list the 9 control groups. Modules 4 and 5 of this course walk each one in detail. For now, just know the shape:
| Group | Title | Approx. no. of controls |
|---|---|---|
| A.2 | Policies related to AI | 3 |
| A.3 | Internal organisation | 2 |
| A.4 | Resources for AI systems | 5 |
| A.5 | Assessing impacts of AI systems on individuals or groups and societies | 4 |
| A.6 | AI system life cycle | 9 |
| A.7 | Data for AI systems | 4 |
| A.8 | Information for interested parties | 4 |
| A.9 | Use of AI systems | 3 |
| A.10 | Third-party and customer relationships | 3 |
Total: 38 controls. Some published summaries say 39 because they count differently — the standard groups sub-controls into a parent-and-child structure in a few places. The right number for your Statement of Applicability is 38.
The ISO family — what else you will meet
You cannot run an ISO 42001 programme in isolation. There are five other ISO standards you will meet in this work. Let me walk them because it will save you weeks of confusion later.
| Standard | Purpose | Certifiable? |
|---|---|---|
| ISO/IEC 22989:2022 | AI concepts and terminology. The dictionary. When the standard uses a word like "AI system" or "training data" or "inference," it means what 22989 says it means. | No |
| ISO/IEC 23053:2022 | Framework for AI systems using machine learning. A reference architecture. Useful for describing your AI systems in the AIIA. | No |
| ISO/IEC 23894:2023 | Guidance on AI risk management. Companion to Clause 6.1.2 of ISO 42001. This is where the AI risk methodology comes from. | No |
| ISO/IEC 42001:2023 | The AIMS Requirements standard. The certifiable one. | Yes |
| ISO/IEC 42005:2025 | AI system impact assessment. Companion to Annex A.5 of ISO 42001. This is where the AIIA methodology comes from. | No |
| ISO/IEC TR 24028:2020 | Overview of trustworthiness in artificial intelligence. Technical report. | No |
Notice the pattern. You certify to 42001. You use the vocabulary from 22989. You describe systems using 23053. You do risk assessment guided by 23894. You do the impact assessment guided by 42005. Only 42001 leads to a certificate — the rest are companions.
How ISO 42001 connects to ISO 27001 and ISO 27701
Most Indian organisations that come to ISO 42001 already have ISO 27001. Some also have ISO 27701 for privacy. So a natural question is: do you build a separate AIMS, or does the AIMS sit on top of the ISMS?
The answer is: you can do it either way, but the sensible way is to integrate. Because 27001 and 42001 both use the Annex SL Harmonised Structure, Clauses 4 through 10 map cleanly across. Your existing ISO 27001 Clause 4 (context), Clause 5 (leadership), Clause 6 (planning), Clause 7 (support), Clause 9 (audit) and Clause 10 (improvement) processes can be extended to cover the AIMS with modest additional content. What is new for 42001 is Annex A (which is entirely different from ISO 27002 controls) and the AI Impact Assessment obligation under Annex A.5 and the AI-specific interested parties (which include affected individuals, not only customers).
In a well-run programme, the same top-management committee governs both ISMS and AIMS. The same internal audit programme covers both, with different sample controls. The same management review agenda includes both. This is what auditors call an Integrated Management System. It is cheaper to build, cheaper to audit and cheaper to maintain than two parallel systems. Module 6 of this course walks the integration pattern in detail.
If you also have ISO 27701 for privacy, the integration extends further. Your DPDP compliance and your ISO 27701 PIMS become the privacy limb of a broader trust posture — ISMS for security, PIMS for privacy, AIMS for AI governance. Together they answer three of the biggest customer questions on any enterprise vendor questionnaire.
Next lesson, I want to compare ISO 42001 to NIST AI RMF and the EU AI Act — because these three names get thrown around interchangeably in board conversations, and they are not interchangeable at all. Knowing the difference will save you from committing your organisation to the wrong programme.