ISO 42001 is the first international management-system standard written specifically for AI. If you've implemented ISO 27001 before, the shape will feel familiar — a management system, a risk assessment, a set of controls — but several requirements are genuinely new, because AI introduces failure modes information security management never had to plan for.
What it actually asks for
Strip away the certification language, and ISO 42001 asks four things of any organization that builds or deploys AI systems:
- Know which AI systems you operate, and what each one is for.
- Assess the risk each system introduces before it ships, not after an incident.
- Keep a lifecycle record — training, changes, retraining — for every model in production.
- Give a human the ability to inspect, question, and override an AI-assisted decision.
ISO 42001 does not require every AI decision to be explainable in a technical sense. It requires that the organization can show what evidence a decision drew from — a different, more achievable bar.
The inventory problem
Most organizations underestimate how many AI systems they actually run — a fraud-scoring model, a support chatbot, an internal drafting assistant, and a vendor's embedded recommendation engine are all in scope. The first real work under ISO 42001 is almost always building the inventory, not writing the policy.
“We thought we had one AI system to govern. We had eleven, once we counted the vendor tools.”
A technology risk lead, describing a first inventory pass — illustrative
How AfriGRC approaches this internally
AfriGRC applies the same discipline to its own Copilot that ISO 42001 expects of a customer's AI systems — every answer links back to the control or evidence record it drew from. See the Responsible AI section of our Trust Centre for the detail.
Next steps
If your organization is scoping ISO 42001 for the first time, start with the inventory, not the gap analysis — you cannot assess the risk of a system you haven't named yet.
Want this as a PDF?
Request a downloadable version via the Resource Request Portal.