Live 16 practitioner certifications live · First lesson free on every course Back to main site →

The structure of ISO/IEC 42001 and where it sits in the ISO family

Now that you know what ISO 42001 is, let me walk you through what is inside the document and how it connects to the other ISO standards you will meet on this journey — 27001, 27701, 23894 and 42005. If you do not know the family, you will build an AIMS that duplicates work you have already done under 27001.

Free preview 13 min read Under review
Legal basis
ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.

Now that you know what ISO/IEC 42001 is at a high level, let me open the document with you and show you what is actually inside. Most students I coach do not do this. They read blog articles about the standard, they read commentary. They rarely read the standard itself. That is a mistake. The standard is not long — the core normative text is about forty pages, plus the annexes. You will save yourself weeks of confusion by reading it once in full early. This lesson is a guided walk through what you will find when you open it.

The ten clauses

ISO/IEC 42001:2023 uses the ISO Annex SL Harmonised Structure. That is the same structure ISO 27001 uses, ISO 9001 uses, ISO 22301 uses. If you have run any of those, the shape will be familiar. If you have not, this is the shape:

ClauseTitleWhat it does
0IntroductionNon-normative context. Explains why the standard exists.
1ScopeSays what the standard is meant to cover.
2Normative referencesPoints to ISO/IEC 22989 for terminology.
3Terms and definitionsAdditional AIMS-specific terms not in 22989.
4Context of the organizationUnderstand your context, identify interested parties, determine the AIMS scope, run the AIMS.
5LeadershipTop management commitment, AI policy, roles and responsibilities.
6PlanningAddress AI risks and opportunities, run AI risk assessment, plan risk treatment, set AI objectives, plan changes.
7SupportResources, competence, awareness, communication, documented information.
8OperationOperational planning and control, execute AI risk assessment and treatment, run AI impact assessment.
9Performance evaluationMonitor and measure, internal audit, management review.
10ImprovementContinual improvement, handle nonconformity, corrective action.

Clauses 0 through 3 are the prologue. The certifiable, normative text is Clauses 4 through 10. When your auditor sits across from you at Stage 1 and Stage 2, they will systematically walk each of Clauses 4 through 10 with you. Not because they are being pedantic — because that is what the standard requires them to do. Every clause requires the organisation to have done something specific. The auditor asks to see the evidence.

The Annexes

After Clause 10 comes the Annexes. This is where ISO 42001 diverges from ISO 27001 in a way you must understand.

ISO 27001 has one normative Annex — Annex A — listing 93 controls. If you have run 27001, you already know that Annex A of 27001 is not optional. Every control gets an Include / Exclude decision in your Statement of Applicability.

ISO 42001 has four Annexes and the roles are different:

  • Annex A (normative) — 38 AI-specific controls organised across 9 control groups from A.2 to A.10. Just like in 27001, every A control gets an Include / Exclude decision in your Statement of Applicability.
  • Annex B (informative) — implementation guidance for the Annex A controls. This is where the standard explains how to actually operationalise each control. Read it alongside Annex A. Auditors do not require you to follow Annex B, but they will read your evidence expecting it to look like something derived from Annex B guidance.
  • Annex C (informative) — potential AI-related organisational objectives and risk sources. A catalogue of the sort of things that end up on your AI risk register (data quality, bias, transparency, accountability, safety, security, environmental impact, and so on).
  • Annex D (informative) — using the AIMS across specific domains. Notes on how the AIMS applies in healthcare, defence, finance, education, and so on.

So when you build your AIMS, you certify against the clauses and against Annex A. You use Annex B, C and D as informative reading. That is the shape.

The 9 control groups of Annex A

Annex A is where the AI-specific requirements live. This is what makes ISO 42001 an AI standard rather than an ISMS. Let me list the 9 control groups. Modules 4 and 5 of this course walk each one in detail. For now, just know the shape:

GroupTitleApprox. no. of controls
A.2Policies related to AI3
A.3Internal organisation2
A.4Resources for AI systems5
A.5Assessing impacts of AI systems on individuals or groups and societies4
A.6AI system life cycle9
A.7Data for AI systems4
A.8Information for interested parties4
A.9Use of AI systems3
A.10Third-party and customer relationships3

Total: 38 controls. Some published summaries say 39 because they count differently — the standard groups sub-controls into a parent-and-child structure in a few places. The right number for your Statement of Applicability is 38.

The ISO family — what else you will meet

You cannot run an ISO 42001 programme in isolation. There are five other ISO standards you will meet in this work. Let me walk them because it will save you weeks of confusion later.

StandardPurposeCertifiable?
ISO/IEC 22989:2022AI concepts and terminology. The dictionary. When the standard uses a word like "AI system" or "training data" or "inference," it means what 22989 says it means.No
ISO/IEC 23053:2022Framework for AI systems using machine learning. A reference architecture. Useful for describing your AI systems in the AIIA.No
ISO/IEC 23894:2023Guidance on AI risk management. Companion to Clause 6.1.2 of ISO 42001. This is where the AI risk methodology comes from.No
ISO/IEC 42001:2023The AIMS Requirements standard. The certifiable one.Yes
ISO/IEC 42005:2025AI system impact assessment. Companion to Annex A.5 of ISO 42001. This is where the AIIA methodology comes from.No
ISO/IEC TR 24028:2020Overview of trustworthiness in artificial intelligence. Technical report.No

Notice the pattern. You certify to 42001. You use the vocabulary from 22989. You describe systems using 23053. You do risk assessment guided by 23894. You do the impact assessment guided by 42005. Only 42001 leads to a certificate — the rest are companions.

How ISO 42001 connects to ISO 27001 and ISO 27701

Most Indian organisations that come to ISO 42001 already have ISO 27001. Some also have ISO 27701 for privacy. So a natural question is: do you build a separate AIMS, or does the AIMS sit on top of the ISMS?

The answer is: you can do it either way, but the sensible way is to integrate. Because 27001 and 42001 both use the Annex SL Harmonised Structure, Clauses 4 through 10 map cleanly across. Your existing ISO 27001 Clause 4 (context), Clause 5 (leadership), Clause 6 (planning), Clause 7 (support), Clause 9 (audit) and Clause 10 (improvement) processes can be extended to cover the AIMS with modest additional content. What is new for 42001 is Annex A (which is entirely different from ISO 27002 controls) and the AI Impact Assessment obligation under Annex A.5 and the AI-specific interested parties (which include affected individuals, not only customers).

In a well-run programme, the same top-management committee governs both ISMS and AIMS. The same internal audit programme covers both, with different sample controls. The same management review agenda includes both. This is what auditors call an Integrated Management System. It is cheaper to build, cheaper to audit and cheaper to maintain than two parallel systems. Module 6 of this course walks the integration pattern in detail.

If you also have ISO 27701 for privacy, the integration extends further. Your DPDP compliance and your ISO 27701 PIMS become the privacy limb of a broader trust posture — ISMS for security, PIMS for privacy, AIMS for AI governance. Together they answer three of the biggest customer questions on any enterprise vendor questionnaire.

Next lesson, I want to compare ISO 42001 to NIST AI RMF and the EU AI Act — because these three names get thrown around interchangeably in board conversations, and they are not interchangeable at all. Knowing the difference will save you from committing your organisation to the wrong programme.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 42001:2023, ISO/IEC 42001:2023 (Dec 2023 first edition) (AI management systems Requirements) L2-C1
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. First edition published 18 December 2023 by ISO/IEC JTC 1/SC 42 (AI subcommittee). The worlds first international management-system standard specifically for artificial intelligence. Structure: ten main clauses (0 Introduction through 10 Improvement) following the Annex SL harmonised structure shared with ISO 27001 and ISO 9001, plus Annex A (38 controls across 9 control groups A.2 through A.10), Annex B (implementation guidance for Annex A controls), Annex C (potential AI-related organisational objectives and risk sources), and Annex D (using an AIMS in specific domains).
ISO/IEC 23894:2023, ISO/IEC 23894:2023 AI risk management (Guidance on AI risk management) L2-C2
ISO/IEC 23894:2023 provides guidance on how organisations that develop, produce, deploy or use AI systems can manage AI-related risks. Non-certifiable companion to ISO 42001. Builds on ISO 31000:2018 risk management framework but adapts it for AI-specific risk sources: data quality, model bias, opacity, robustness, adversarial manipulation, autonomy and human oversight. Referenced by ISO 42001 Clause 6.1.2 as the guidance an auditor expects a risk methodology to follow.
ISO/IEC 42005:2025, ISO/IEC 42005:2025 AI impact assessment (AI system impact assessment) L2-C3
ISO/IEC 42005:2025 provides guidance on conducting an AI system impact assessment (AIIA). Companion to ISO 42001 Annex A control A.5.2. Methodology covers stakeholder identification, impact identification across fairness, safety, transparency, privacy, security, human oversight, environmental impact and society-level impact; scoring; documentation; and lifecycle re-assessment.
ISO/IEC 23053:2022, ISO/IEC 23053:2022 ML framework (Framework for AI using ML) L2-C4
ISO/IEC 23053:2022 provides a framework for describing AI systems using machine learning. Reference architecture. Non-normative. Useful for AIIA and AIMS scope work when the organisation needs to describe what the AI system actually does at a functional level for the auditor.
ISO/IEC 22989:2022, ISO/IEC 22989:2022 AI terminology (AI concepts and terminology) L2-C5
ISO/IEC 22989:2022 defines AI concepts and terminology. Non-normative reference used across the ISO/IEC 42001 family. Sets the meaning of terms like AI system, machine learning, training data, model, that Clauses across 42001 assume.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: What ISO/IEC 42001 actually is, and why it turned into a procurement gate in 2026
Module 2: Reading Clauses 4, 5 and 6: Context, Leadership and Planning
  • Clauses 4.1 and 4.2: understanding your context and identifying interested parties
  • Clause 4.3: writing an AIMS Scope Statement that a certification body will accept
  • Clause 5: Leadership, AI Policy and Roles — where an AIMS becomes real
  • Clause 6.1: the AI risk assessment methodology — the beating heart of the AIMS
  • Clauses 6.2 and 6.3: AI objectives and planning of changes
Module 3: Reading Clauses 7, 8, 9 and 10: Support, Operation, Performance evaluation, Improvement
  • Clauses 7.1 to 7.4: Resources, Competence, Awareness, Communication
  • Clause 7.5: Documented information — what must be in writing, and how it is controlled
  • Clause 8: Operation — executing the risk methodology and running the AIIA
  • Clause 9: Performance evaluation — monitoring, internal audit, management review
  • Clause 10: Continual improvement, nonconformity and the CAPA process
Module 4: Annex A controls Part 1: A.2 Policies, A.3 Internal organisation, A.4 Resources, A.5 Impact assessment
  • Annex A.2 — Policies related to AI: three controls that anchor the AIMS
  • Annex A.3 — Internal organisation: AI roles and the concerns-reporting channel
  • Annex A.4 Part 1 — Data and tooling resources (A.4.2 and A.4.3)
  • Annex A.4 Part 2 — Compute, human and financial resources (A.4.4 to A.4.6)
  • Annex A.5 — AI Impact Assessment: the four controls that decide whether an AIMS is real
Module 5: Annex A controls Part 2: A.6 AI lifecycle, A.7 Data, A.8 Information, A.9 Use, A.10 Third-party
  • Annex A.6 Part 1 — AI lifecycle: requirements, design and development
  • Annex A.6 Part 2 — Verification, deployment, operation, monitoring and event logs
  • Annex A.7 — Data for AI systems: five controls with the DPDP overlay
  • Annex A.8 — Information for interested parties: where the IT Rules 2026 SGI obligations land
  • Annex A.9 and A.10 — Responsible use of AI systems and third-party relationships
Module 6: Building the AIMS end-to-end: inventory, impact assessment, risk assessment, Statement of Applicability, tooling
  • Building the AI system inventory — the foundation everything else hangs on
  • Running an AI Impact Assessment per ISO/IEC 42005:2025 — the operational template
  • Running the AI risk assessment methodology per ISO/IEC 23894:2023
  • Building the Statement of Applicability — the single most-audited document
  • GRC tooling landscape — buy versus build for an AIMS
Module 7: Certification body selection, Stage 1 audit, Stage 2 audit, certificate issuance
  • The accreditation chain — why the certificate means anything, and where NABCB stands on ISO 42001
  • CB selection — the RFP process, scoring criteria and negotiation
  • Stage 1 — the documentation review: what the auditor tests and how to pass first time
  • Stage 2 — the operating-effectiveness audit: sampling, interviews, evidence
  • The three-year sustain cycle — surveillance, recertification and living with the certificate
Module 8: The India overlay + the next five years: AI Governance Guidelines, IT Rules 2026, SEBI, RBI FREE-AI, DPDP, EU AI Act, NIST AI RMF
  • The India AI Governance Guidelines in operational depth — the seven sutras and six pillars, clause by clause
  • IT Amendment Rules 2026 SGI obligations in operational depth — the first binding AI law in India
  • Sector-specific overlays — SEBI 5-May-2026, RBI FREE-AI, and the wider sectoral picture
  • DPDP intersection with AI, and EU AI Act extraterritorial reach on Indian exporters
  • NIST AI RMF crosswalk and the next five years — closing the course