Artificial intelligence generates value — and risks of a new nature. Algorithmic bias, opaque decision-making, vulnerability to adversarial attacks, dependence on third-party model providers, impacts on individuals and society: these risks cannot be managed with the classic instruments of risk management. They require a specific framework, built for the reality of AI systems.
ISO/IEC 42001:2023 — the first international certification standard for an Artificial Intelligence Management System (AIMS) — provides that framework. It does not prescribe which AI systems to deploy or how to design them technically. It requires the organisation to demonstrate that it has established a policy, assessed risks, defined objectives, put in place control processes and committed to continual improvement — for every AI system it develops or uses.
Key concept · Artificial Intelligence Management System (AIMS)
A structured set of policies, processes and arrangements that allow an organisation to develop, deploy and use artificial intelligence systems responsibly, transparently and in an auditable manner — consistent with its values, ethical commitments and regulatory obligations. The AIMS is integrated into the organisation's existing governance framework; it does not replace it.
For a board of directors or executive leadership, ISO/IEC 42001 provides a concrete answer to a governance question: how can the organisation demonstrate, verifiably, that it controls the risks associated with the AI it uses or develops? The standard provides the framework. Certification provides the defensible proof.
AI risk assessment differs fundamentally from classic IT or organisational risk management. AI systems present risk categories that are specific to their nature, and that must be identified, qualified and treated within the AIMS.
Bias and discrimination
Decisions that are systematically unfavourable to certain groups because of biased training data or inadequate design choices.
Opacity and inexplicability
Inability to explain the decisions produced — a critical issue for systems subject to the transparency requirements of the GDPR or the EU AI Act.
Model drift
Progressive degradation of a deployed model's performance as real-world data diverges from the training data.
Adversarial attacks
Deliberate manipulation of an AI system's inputs to induce erroneous behaviour or bypass its control mechanisms.
Provider dependence
Concentration of risk on third-party model or data providers — availability, unilateral changes, continuity of service.
Societal impact
Consequences for individuals, jobs, the environment or society, at a scale that is difficult to predict at the deployment stage.
ISO/IEC 23894 — Managing risks specific to AI
ISO/IEC 23894:2023 is the complementary standard dedicated to assessing and treating risks specific to AI systems. It aligns with ISO 31000 for the general framework and with ISO/IEC 42001 for integration into the AIMS. Mastering it is essential for building an AI risk assessment process that is genuinely adapted to the nature of these systems — rather than a transposition of methods designed for other contexts.
ISO/IEC 42001 follows the High Level Structure (HLS) common to major international management system standards — the same architecture as ISO/IEC 27001 and ISO 22301. This structural consistency makes it easier to integrate the AIMS into an existing management system and enables combined audits.
AI policy and objectives
The organisation's AI policy defines its commitments to responsible development and use of AI systems — transparency, fairness, respect for fundamental rights, accountability. It is approved by leadership and constitutes the framework within which all AI-related objectives and decisions are made. It is not a communications document: it is an operational, defensible commitment.
AI system impact assessment
Before any deployment, an AI-specific impact assessment is carried out: which individuals or groups are affected by the system's decisions? What are the potential impacts on their rights, their employment, their safety? This assessment — distinct from the GDPR's DPIA but aligned with it — conditions deployment decisions and the control measures to be implemented. It is documented, revisable and auditable.
AI system lifecycle
The AIMS applies to every phase of an AI system's lifecycle: design and specification, data collection and preparation, model training and validation, deployment and monitoring, decommissioning. Each phase carries its own requirements for control, documentation and verification. Governance of the lifecycle is what distinguishes an organisation that uses AI under control from one that merely endures it.
Management of AI system providers
Most organisations deploy AI systems developed or trained by third parties — model providers, platforms, data providers. ISO/IEC 42001 requires structured management of these relationships: provider assessment, contractual AI governance requirements, ongoing monitoring, and management of changes and incidents. The organisation's responsibility towards its stakeholders cannot be delegated to its providers.
Measurement, audit and continual improvement
The AIMS relies on a continuous steering cycle: performance indicators for AI systems, monitoring of bias and drift, management review, internal audit, corrective actions. Continual improvement is structural — it incorporates lessons learned, regulatory developments (the EU AI Act, normative updates) and newly identified threats to deployed systems.
ISO/IEC 42001 is the certification standard. It is part of a broader normative ecosystem, which covers AI governance at board level, the management of risks specific to AI systems, and the foundations of AI system trustworthiness. This training covers the whole of that corpus.
ISO/IEC 42001
Artificial Intelligence Management System — international reference certification standard · published in 2023
Associated standards and technical reports
ISO/IEC 42002
Guidance for the implementation of an AIMS · Interpretation and application of ISO/IEC 42001
ISO/IEC 23894
AI risk management · Assessment framework specific to AI systems
ISO/IEC TR 24028
Overview of AI system trustworthiness · Transparency, robustness, security, fairness
ISO/IEC 38507
Governance implications of the use of AI by organisations · Board and executive management level
Regulatory dimension · EU AI Act
The European regulation on artificial intelligence (EU AI Act), which entered into force in August 2024, imposes graduated obligations according to the risk level of AI systems — from unacceptable-risk systems (prohibited) to high-risk systems (reinforced requirements for documentation, transparency, human oversight and risk management). ISO/IEC 42001 and the EU AI Act are complementary: the standard provides the management system that enables an organisation to structurally meet the regulation's requirements. Organisations with a certified AIMS have a substantial advantage in their compliance efforts — and defensible proof of their diligence.
The EU AI Act's requirements applicable to high-risk AI systems come into full effect in August 2026. The compliance window is open now.The AIMS does not stand apart from the rest of the organisation's management system. It interacts with information security, data protection, risk management, business continuity and sector-specific regulatory obligations. Understanding these intersections is essential to building AI governance that is coherent with the existing architecture.
Governance frameworks
ISO/IEC 27001
Security of AI systems · Protection of training data · ISMS–AIMS integration · Security controls for AI
ISO/IEC 27701
Personal data protection · Automated decisions · AIMS–PIMS alignment · GDPR compliance
ISO 31000
Organisational risk management framework · Integration of AI risks into the overall risk map
Resilience and regulatory framework
ISO 22301
Business continuity · New dependencies created by critical AI systems · BIA integrating AI risks
NIS2 / DORA
AI in critical systems and financial infrastructure · Oversight and third-party AI risk management requirements
GDPR · Article 22
Automated decisions with a legal or significant effect · Right to explanation · Human oversight
AI as a new systemic risk within organisations
AI introduces a new category of dependency for organisations: systems whose behaviour can be difficult to predict, explain and control, and whose failure can have consequences for entire populations. ISO/IEC 27001 must be extended to cover the security of AI systems — protection of training data, model integrity, resistance to attacks. ISO 22301 must integrate critical AI systems into the BIA and continuity plans. ISO/IEC 27701 must address the implications of automated decisions for individuals' rights. NIS2 and DORA impose oversight and third-party risk management requirements that apply directly to AI system providers. A high-performing AIMS is the structured response to this convergence.
The governance of artificial intelligence is a discipline under rapid construction — both on the normative side, with the progressive development of the dedicated ISO/IEC corpus, and on the regulatory side, with the ramping up of the EU AI Act. Teaching ISO/IEC 42001 today means teaching a living discipline, whose contours are evolving and whose interactions with other frameworks are becoming clearer.
This training is designed for professionals who want to master AI governance in depth — not simply prepare for a certification. It is grounded in field practice acquired with organisations facing real digital governance and regulatory compliance challenges, in France, Luxembourg and Scandinavia.
It is delivered as part of the 51 PECB certifying curricula for which Dominique Bourra is accredited to train and assess — in French and English, in person and remotely.
Artificial intelligence is not merely an opportunity to seize or a risk to contain. It is a new frontier for governance. The organisations that build a structured management system today — policy, risk assessment, controls, audit — are the ones that will extract lasting value from it, and that will meet tomorrow's regulatory requirements with evidence, not declarations.
Going further
ISO/IEC 42001 takes on its full meaning when combined with other frameworks — particularly ISO/IEC 27001, to build a coherent information and AI governance offer. Discover how to design this trajectory → Strategic Capability Architecture