Skip to content
Book a Demo
BLG.ART / AI GOVERNANCE

What ISO 42001 Actually Requires: A Plain-Language Breakdown

The first management-system standard written for AI, broken into four things it actually asks an organization to do.

AI Governance Editorial Lead11 min read

Share

ISO 42001 is the first international management-system standard written specifically for AI. If you've implemented ISO 27001 before, the shape will feel familiar — a management system, a risk assessment, a set of controls — but several requirements are genuinely new, because AI introduces failure modes information security management never had to plan for.

What it actually asks for

Strip away the certification language, and ISO 42001 asks four things of any organization that builds or deploys AI systems:

  • Know which AI systems you operate, and what each one is for.
  • Assess the risk each system introduces before it ships, not after an incident.
  • Keep a lifecycle record — training, changes, retraining — for every model in production.
  • Give a human the ability to inspect, question, and override an AI-assisted decision.

ISO 42001 does not require every AI decision to be explainable in a technical sense. It requires that the organization can show what evidence a decision drew from — a different, more achievable bar.

The inventory problem

Most organizations underestimate how many AI systems they actually run — a fraud-scoring model, a support chatbot, an internal drafting assistant, and a vendor's embedded recommendation engine are all in scope. The first real work under ISO 42001 is almost always building the inventory, not writing the policy.

We thought we had one AI system to govern. We had eleven, once we counted the vendor tools.

A technology risk lead, describing a first inventory pass — illustrative

How AfriGRC approaches this internally

AfriGRC applies the same discipline to its own Copilot that ISO 42001 expects of a customer's AI systems — every answer links back to the control or evidence record it drew from. See the Responsible AI section of our Trust Centre for the detail.

Next steps

If your organization is scoping ISO 42001 for the first time, start with the inventory, not the gap analysis — you cannot assess the risk of a system you haven't named yet.

Want this as a PDF?

Request a downloadable version via the Resource Request Portal.

Request PDF

Related Articles

Risk

What a Board Actually Wants From a Risk Report

Translating a risk register into the four things a board and audit committee ask for every time.

Risk & Audit Editorial Lead7 min read

Coming Soon

AI Governance

AI Governance, Explained From First Principles

What governing an AI system actually means, before any specific framework enters the conversation.

AI Governance Editorial Lead10 min read

Coming Soon

ART.05 / STAY INFORMED

New articles, before anyone else sees them.

Knowledge Alerts

New guides, regulatory updates, and event invitations — direct to your inbox, as they publish.

What ISO 42001 Actually Requires: A Plain-Language Breakdown — AfriGRC Blog