Expertise · ISO/IEC 42001

Governing artificial intelligence

Design, deploy and steer AI systems responsibly — integrating specific risks, ethical obligations and regulatory requirements into a structured, auditable management system.

From promise to management system

Artificial intelligence generates value — and risks of a new nature. Algorithmic bias, opaque decision-making, vulnerability to adversarial attacks, dependence on third-party model providers, impacts on individuals and society: these risks cannot be managed with the classic instruments of risk management. They require a specific framework, built for the reality of AI systems.

ISO/IEC 42001:2023 — the first international certification standard for an Artificial Intelligence Management System (AIMS) — provides that framework. It does not prescribe which AI systems to deploy or how to design them technically. It requires the organisation to demonstrate that it has established a policy, assessed risks, defined objectives, put in place control processes and committed to continual improvement — for every AI system it develops or uses.

Key concept · Artificial Intelligence Management System (AIMS)

A structured set of policies, processes and arrangements that allow an organisation to develop, deploy and use artificial intelligence systems responsibly, transparently and in an auditable manner — consistent with its values, ethical commitments and regulatory obligations. The AIMS is integrated into the organisation's existing governance framework; it does not replace it.

For a board of directors or executive leadership, ISO/IEC 42001 provides a concrete answer to a governance question: how can the organisation demonstrate, verifiably, that it controls the risks associated with the AI it uses or develops? The standard provides the framework. Certification provides the defensible proof.

Risks specific to artificial intelligence

AI risk assessment differs fundamentally from classic IT or organisational risk management. AI systems present risk categories that are specific to their nature, and that must be identified, qualified and treated within the AIMS.

Bias and discrimination

Decisions that are systematically unfavourable to certain groups because of biased training data or inadequate design choices.

Opacity and inexplicability

Inability to explain the decisions produced — a critical issue for systems subject to the transparency requirements of the GDPR or the EU AI Act.

Model drift

Progressive degradation of a deployed model's performance as real-world data diverges from the training data.

Adversarial attacks

Deliberate manipulation of an AI system's inputs to induce erroneous behaviour or bypass its control mechanisms.

Provider dependence

Concentration of risk on third-party model or data providers — availability, unilateral changes, continuity of service.

Societal impact

Consequences for individuals, jobs, the environment or society, at a scale that is difficult to predict at the deployment stage.

ISO/IEC 23894 — Managing risks specific to AI

ISO/IEC 23894:2023 is the complementary standard dedicated to assessing and treating risks specific to AI systems. It aligns with ISO 31000 for the general framework and with ISO/IEC 42001 for integration into the AIMS. Mastering it is essential for building an AI risk assessment process that is genuinely adapted to the nature of these systems — rather than a transposition of methods designed for other contexts.

The pillars of the AIMS — from policy to continual improvement

ISO/IEC 42001 follows the High Level Structure (HLS) common to major international management system standards — the same architecture as ISO/IEC 27001 and ISO 22301. This structural consistency makes it easier to integrate the AIMS into an existing management system and enables combined audits.

AI policy and objectives

The organisation's AI policy defines its commitments to responsible development and use of AI systems — transparency, fairness, respect for fundamental rights, accountability. It is approved by leadership and constitutes the framework within which all AI-related objectives and decisions are made. It is not a communications document: it is an operational, defensible commitment.

AI system impact assessment

Before any deployment, an AI-specific impact assessment is carried out: which individuals or groups are affected by the system's decisions? What are the potential impacts on their rights, their employment, their safety? This assessment — distinct from the GDPR's DPIA but aligned with it — conditions deployment decisions and the control measures to be implemented. It is documented, revisable and auditable.

AI system lifecycle

The AIMS applies to every phase of an AI system's lifecycle: design and specification, data collection and preparation, model training and validation, deployment and monitoring, decommissioning. Each phase carries its own requirements for control, documentation and verification. Governance of the lifecycle is what distinguishes an organisation that uses AI under control from one that merely endures it.

Management of AI system providers

Most organisations deploy AI systems developed or trained by third parties — model providers, platforms, data providers. ISO/IEC 42001 requires structured management of these relationships: provider assessment, contractual AI governance requirements, ongoing monitoring, and management of changes and incidents. The organisation's responsibility towards its stakeholders cannot be delegated to its providers.

Measurement, audit and continual improvement

The AIMS relies on a continuous steering cycle: performance indicators for AI systems, monitoring of bias and drift, management review, internal audit, corrective actions. Continual improvement is structural — it incorporates lessons learned, regulatory developments (the EU AI Act, normative updates) and newly identified threats to deployed systems.

The normative corpus — beyond ISO/IEC 42001

ISO/IEC 42001 is the certification standard. It is part of a broader normative ecosystem, which covers AI governance at board level, the management of risks specific to AI systems, and the foundations of AI system trustworthiness. This training covers the whole of that corpus.

ISO/IEC 42001

Artificial Intelligence Management System — international reference certification standard · published in 2023

Associated standards and technical reports

ISO/IEC 42002

Guidance for the implementation of an AIMS · Interpretation and application of ISO/IEC 42001

ISO/IEC 23894

AI risk management · Assessment framework specific to AI systems

ISO/IEC TR 24028

Overview of AI system trustworthiness · Transparency, robustness, security, fairness

ISO/IEC 38507

Governance implications of the use of AI by organisations · Board and executive management level

Regulatory dimension · EU AI Act

The European regulation on artificial intelligence (EU AI Act), which entered into force in August 2024, imposes graduated obligations according to the risk level of AI systems — from unacceptable-risk systems (prohibited) to high-risk systems (reinforced requirements for documentation, transparency, human oversight and risk management). ISO/IEC 42001 and the EU AI Act are complementary: the standard provides the management system that enables an organisation to structurally meet the regulation's requirements. Organisations with a certified AIMS have a substantial advantage in their compliance efforts — and defensible proof of their diligence.

The EU AI Act's requirements applicable to high-risk AI systems come into full effect in August 2026. The compliance window is open now.
Intersections — the AIMS within an integrated governance

The AIMS does not stand apart from the rest of the organisation's management system. It interacts with information security, data protection, risk management, business continuity and sector-specific regulatory obligations. Understanding these intersections is essential to building AI governance that is coherent with the existing architecture.

Governance frameworks

ISO/IEC 27001

Security of AI systems · Protection of training data · ISMS–AIMS integration · Security controls for AI

ISO/IEC 27701

Personal data protection · Automated decisions · AIMS–PIMS alignment · GDPR compliance

ISO 31000

Organisational risk management framework · Integration of AI risks into the overall risk map

Resilience and regulatory framework

ISO 22301

Business continuity · New dependencies created by critical AI systems · BIA integrating AI risks

NIS2 / DORA

AI in critical systems and financial infrastructure · Oversight and third-party AI risk management requirements

GDPR · Article 22

Automated decisions with a legal or significant effect · Right to explanation · Human oversight

AI as a new systemic risk within organisations

AI introduces a new category of dependency for organisations: systems whose behaviour can be difficult to predict, explain and control, and whose failure can have consequences for entire populations. ISO/IEC 27001 must be extended to cover the security of AI systems — protection of training data, model integrity, resistance to attacks. ISO 22301 must integrate critical AI systems into the BIA and continuity plans. ISO/IEC 27701 must address the implications of automated decisions for individuals' rights. NIS2 and DORA impose oversight and third-party risk management requirements that apply directly to AI system providers. A high-performing AIMS is the structured response to this convergence.

International experience

The governance of artificial intelligence is a discipline under rapid construction — both on the normative side, with the progressive development of the dedicated ISO/IEC corpus, and on the regulatory side, with the ramping up of the EU AI Act. Teaching ISO/IEC 42001 today means teaching a living discipline, whose contours are evolving and whose interactions with other frameworks are becoming clearer.

This training is designed for professionals who want to master AI governance in depth — not simply prepare for a certification. It is grounded in field practice acquired with organisations facing real digital governance and regulatory compliance challenges, in France, Luxembourg and Scandinavia.

It is delivered as part of the 51 PECB certifying curricula for which Dominique Bourra is accredited to train and assess — in French and English, in person and remotely.

Artificial intelligence is not merely an opportunity to seize or a risk to contain. It is a new frontier for governance. The organisations that build a structured management system today — policy, risk assessment, controls, audit — are the ones that will extract lasting value from it, and that will meet tomorrow's regulatory requirements with evidence, not declarations.

Dominique Bourra  ·  PECB Platinum Trainer

Going further

ISO/IEC 42001 takes on its full meaning when combined with other frameworks — particularly ISO/IEC 27001, to build a coherent information and AI governance offer. Discover how to design this trajectory → Strategic Capability Architecture

Train your teams in AI governance, or prepare a Lead Implementer or Lead Auditor for ISO/IEC 42001?
On site or remote, in French or English.

Request a programme →