Skip to main content
← All posts
RegulatorySentrify Team11 min read

ISO 42001 Explained: What Your AI Team Actually Needs to Do

ISO 42001 is the international standard for AI management systems. Most published commentary is written by standards bodies for other standards bodies. This one is for the people who actually have to implement it.

ISO 42001 is the international standard for AI management systems. It was published in December 2023 and is already shaping how boards, regulators, and procurement teams evaluate enterprise AI capability.

Most of the published commentary on ISO 42001 is written by standards bodies and consultants. It is accurate, thorough, and almost entirely unhelpful for the AI leaders, risk officers, and compliance teams who need to actually do something with it.

This post is different. It explains what ISO 42001 requires in plain language, what most enterprises are getting wrong about it, and what a practical path to genuine compliance actually looks like.


What ISO 42001 Is (And Is Not)

ISO 42001 specifies the requirements for an AI Management System (AIMS) — a structured organisational capability for governing AI across its full lifecycle.

It is important to understand what this means. ISO 42001 is not:

  • A technical standard for AI model performance or accuracy
  • A checklist you complete once and file away
  • A standard that audits individual AI decisions

It is a management system standard — in the same family as ISO 27001 (information security) and ISO 9001 (quality management). Like those standards, it requires you to demonstrate that your organisation has systematic, repeatable, and continuously improving processes for managing AI risk.

That distinction — between a one-time compliance exercise and an ongoing management system — is the source of most implementation failures.


The Five Things ISO 42001 Actually Requires

Strip away the clause numbering and the standards language, and ISO 42001 requires five things. Each one is more demanding than it sounds.

1. A defined scope and AI policy

You need to define which AI systems are in scope, who is responsible for governing them, and what your organisation's policy commitments are in relation to responsible AI.

What most enterprises do: Write a "Responsible AI Policy" document, publish it on the intranet, and consider the box ticked.

What ISO 42001 actually requires: A policy that is actively linked to AI systems, reviewed regularly, communicated to relevant staff, and demonstrably influencing operational decisions. A document nobody reads does not satisfy Clause 5.2.

2. A systematic AI risk assessment process

You must identify, assess, and treat risks associated with your AI systems — not generically, but specifically, for each AI system in scope.

What most enterprises do: Include AI risks in their existing enterprise risk register. Assign "High / Medium / Low" ratings. Move on.

What ISO 42001 actually requires: A structured risk assessment that considers the specific use case, the data the system operates on, the potential for bias or harm, the context of deployment, and the mitigations in place. This assessment must be documented, linked to the specific AI system, and updated when circumstances change.

This is where the evidence requirement becomes acute. It is not sufficient to have done a risk assessment. You need to be able to show what you assessed, when, who conducted it, and what the outcome was.

3. Objectives, targets, and measurement

ISO 42001 requires you to set measurable objectives for your AI management system and to track progress against them.

What most enterprises do: Nothing, because nobody told them this was required.

What ISO 42001 actually requires: Defined, measurable AI governance objectives — for example, "100% of high-risk AI systems assessed before deployment," or "average time to complete an AI evaluation reduced to under two weeks." These objectives must be monitored, reported on, and used to drive improvement.

This is the clause that transforms AI governance from a policy exercise into an operational discipline.

4. Operational controls and evidence

For each AI system in scope, you must implement controls that address the identified risks — and produce evidence that those controls are working.

What most enterprises do: Point to their existing security controls, data governance policies, and model documentation. Assume these are sufficient.

What ISO 42001 actually requires: Controls that are specific to the AI system's risk profile, documented, implemented, and — critically — evidenced. Evidence means artefacts: bias assessment reports, security test results, data governance approvals, human oversight documentation. Not references to where these things might exist. The actual documents, with provenance.

This is the point at which organisations without AI Trust Infrastructure hit a wall. The controls may exist in various systems, maintained by various teams, in various formats. Assembling them into a coherent, traceable evidence chain for a specific AI system — on demand — is not possible without systematic infrastructure.

5. Continuous improvement and management review

ISO 42001 is not a pass/fail certification. It is a continuous improvement framework. You must have processes for monitoring the performance of your AI management system, identifying gaps, and systematically addressing them.

What most enterprises do: Assume that getting certified is the end goal.

What ISO 42001 actually requires: Regular management reviews, internal audits, nonconformity tracking, and documented corrective actions. Certification is a snapshot. The standard expects you to keep improving after you get it.


The Evidence Problem at the Heart of ISO 42001

If there is one thing that separates organisations that achieve genuine ISO 42001 compliance from those that go through the motions, it is evidence management.

ISO 42001 uses the phrase "retain documented information as evidence" repeatedly. This is deliberate. The standard expects you to be able to demonstrate — with actual documents and records — that your management system is functioning as intended.

For a typical enterprise with ten or more AI systems in production, this evidence challenge is significant:

  • Each AI system may have a different risk profile, requiring different evidence
  • Evidence is typically distributed across teams: data science, legal, security, risk
  • Documents change as AI systems evolve; version control is rarely systematic
  • The link between a specific piece of evidence and a specific AI system is often implicit or informal

The consequence is that when an auditor — internal or external — asks for the evidence that a specific AI system has been properly assessed and governed, most organisations cannot produce it without a significant manual effort that takes weeks.

Most enterprises today sit at an ad-hoc or policy-only stage of AI governance maturity. ISO 42001 expects systematic, evidenced governance at certification — and continuous improvement towards a continuously-monitored trust infrastructure beyond it.


What the Assessment Process Should Actually Look Like

A practical ISO 42001-aligned assessment of an AI system should follow this sequence:

Step 1 — Register the system. Capture the AI system's purpose, the data it uses, the decisions it makes, who owns it, and its initial risk classification. This is not optional context — it is the foundation on which every subsequent step is built.

Step 2 — Identify applicable obligations. Map the system to the regulatory and policy obligations that apply: ISO 42001 clauses, sector-specific requirements (APRA, TEQSA, ASIC), internal policies, and contractual commitments.

Step 3 — Conduct the risk assessment. Assess the specific risks associated with this system in this context: bias risk, data quality risk, security risk, transparency risk, operational risk. Document the assessment with the assessor, date, methodology, and findings.

Step 4 — Gather and verify evidence. Collect the evidence that controls are in place: bias evaluation reports, security assessments, data governance approvals, human oversight procedures, incident response plans. Verify that evidence is current, complete, and linked to the specific system.

Step 5 — Evaluate against requirements. Run the system through a structured evaluation against applicable requirements. Identify gaps. Determine whether gaps are acceptable, require mitigation, or block deployment.

Step 6 — Generate an assurance output. Produce a structured output — a TrustScore™, an assurance report, or both — that summarises the assessment, links to the evidence, and provides a clear recommendation on deployment status.

Step 7 — Monitor continuously. Set up monitoring for the conditions that could change the system's risk profile: data drift, performance degradation, new regulatory requirements, changes in deployment context. Re-evaluate when material changes occur.

Steps 1 through 6 can be completed manually by a skilled team. Step 7 cannot — at least not reliably, at scale. This is where the infrastructure requirement becomes unavoidable.


The Common Mistakes That Fail ISO 42001 Audits

Based on the patterns we see across regulated industries, three mistakes account for the majority of ISO 42001 audit failures or findings:

Mistake 1: Treating ISO 42001 as a documentation exercise. Organisations spend months writing policies and procedures, then discover that auditors want to see evidence those policies are actually being followed — in the form of assessment records, meeting minutes, corrective action logs, and operational data. Documentation is necessary but nowhere near sufficient.

Mistake 2: Centralising governance away from AI system owners. ISO 42001 requires the people closest to each AI system — the developers, the business owners, the risk managers — to be actively involved in governance. Delegating "compliance" to a central team that has never seen the model card or the training data produces governance that looks good on paper and fails under scrutiny.

Mistake 3: Conflating AI governance with data governance. Your data governance framework is relevant but insufficient. ISO 42001 requires system-level assessment — looking at the AI system as a whole, including the model, the data it operates on, the decisions it makes, and the context in which it is deployed. Data governance addresses one input to that assessment.


What ISO 42001 Compliance Actually Costs Without Infrastructure

The organisations that attempt ISO 42001 compliance without systematic infrastructure typically find themselves in the same position: significant cost, fragile outcomes, and an ongoing maintenance burden that strains the teams carrying it.

A conservative estimate for a mid-sized financial services firm attempting ISO 42001 without dedicated infrastructure:

  • 3–6 months of consultant time to conduct initial gap assessment
  • 4–8 weeks of internal staff time per AI system for initial assessment and evidence gathering
  • 2–4 weeks per year per AI system for ongoing monitoring and re-assessment
  • 4–6 weeks of preparation time for each certification audit

For an organisation with fifteen AI systems in scope — which is not unusual — this represents a substantial and recurring operational cost, plus the ongoing risk that the evidence assembled manually is incomplete, outdated, or inconsistently structured.

AI Trust Infrastructure does not eliminate this work. It systematises it — so that the evidence is gathered continuously, the assessments are automated, and the audit preparation that previously took weeks takes hours.


The Practical Starting Point

If your organisation is beginning its ISO 42001 journey, the most valuable first step is not to write a policy or engage a consultant. It is to build an inventory.

You cannot govern what you cannot see. Most organisations do not know, with confidence, how many AI systems they have in production, who owns them, what decisions they make, or what data they operate on. Until you do, governance is theoretical.

A complete AI inventory — capturing system, owner, use case, data inputs, deployment context, and risk classification — is the foundation on which everything else is built. It is also the first thing an ISO 42001 auditor will ask for.

From there, the path to compliance follows naturally: risk assessment, evidence gathering, control implementation, evaluation, and continuous monitoring. The question is whether you build the infrastructure to support that path systematically, or attempt to walk it manually every time a new AI system is deployed.


The Standard Is Not Going Away

ISO 42001 is less than two years old. In the timescale of management system standards, it is new. But it is already being referenced by regulators, included in procurement requirements, and adopted as a benchmark by early-moving enterprises who understand that demonstrating AI trustworthiness is a competitive advantage, not just a compliance obligation.

The enterprises that build genuine AI management system capability now — not the documentation, but the infrastructure — will be the ones who can say, when the regulatory environment becomes more demanding: we have been doing this properly for years.

That is not just a compliance position. It is a market position.


Sentrify's evaluation engine maps directly to ISO 42001 requirements, generating TrustScores and evidence chains that are audit-ready by design. See how it works →

iso 42001ai managementregulatory complianceaudit
Sentrify

AI Trust Infrastructure for regulated industries. Deploy AI with confidence through machine-verifiable trust, continuous assurance, and audit-ready governance.

🇦🇺 Data hosted in Australia · AWS ap-southeast-2
Stay updated

Product updates and Australian AI-regulation insights. No spam.

© 2026 Sentrify Pty Ltd. All rights reserved.

AI Trust Infrastructure · sentrify.ai