International

ISO/IEC 42001:2023

79 controls. 132 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

79 controls 132 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ISO/IEC 42001:2023 AI Management System Evidence & Implementation Kit

79 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
10.1Continual improvement40
10.2Nonconformity and corrective action44
4.1Understanding the organization and its context29
4.2Understanding the needs and expectations of interested parties27
4.3Determining the scope of the management system19
4.4Management system20
5.1Leadership and commitment40
5.2Policy17
5.3Roles, responsibilities and authorities37
6.1Actions to address risks and opportunities32
6.1.2Risk assessment45
6.1.3Risk treatment23
6.1.4AI system impact assessment6
6.2Objectives and planning to achieve them19
6.3Planning of changes3
7.1Resources15
7.2Competence24
7.3Awareness24
7.4Communication48
7.5Documented information35
7.5.2Creating and updating21
7.5.3Control of documented information21
8.1Operational planning and control29
8.2AI risk assessment22
8.3AI risk treatment23
8.4AI system impact assessment15
9.1Monitoring, measurement, analysis and evaluation40
9.2Internal audit44
9.2.2Internal audit programme13
9.3Management review39
9.3.2Management review inputs4
9.3.3Management review results2
A.10Third-party and customer relationships8
A.10.2Allocating responsibilities14
A.10.3Suppliers21
A.10.4Customers3
A.2Policies related to AI5
A.2.2AI policy10
A.2.3Alignment with other organizational policies7
A.2.4Review of the AI policy9
A.3Internal organization10
A.3.2AI roles and responsibilities30
A.3.3Reporting of concerns10
A.4Resources for AI systems27
A.4.2Resource documentation9
A.4.3Data resources9
A.4.4Tooling resources6
A.4.5System and computing resources15
A.4.6Human resources19
A.5Assessing impacts of AI systems3
A.5.2AI system impact assessment process10
A.5.3Documentation of AI system impact assessments7
A.5.4Assessing AI system impact on individuals or groups9
A.5.5Assessing societal impacts of AI systems4
A.6AI system life cycle10
A.6.1.2Objectives for responsible development of AI systems6
A.6.1.3Processes for responsible design and development of AI systems14
A.6.2.2AI system requirements and specification8
A.6.2.3Documentation of AI system design and development12
A.6.2.4AI system verification and validation15
A.6.2.5AI system deployment8
A.6.2.6AI system operation and monitoring16
A.6.2.7AI system technical documentation10
A.6.2.8AI system event logging15
A.7Data for AI systems6
A.7.2Data for development and enhancement of AI systems6
A.7.3Acquisition of data8
A.7.4Quality of data for AI systems8
A.7.5Data provenance11
A.7.6Data preparation7
A.8Information for interested parties of AI systems4
A.8.2System documentation and information for users13
A.8.3External reporting10
A.8.4Communication of incidents45
A.8.5Information for interested parties9
A.9Use of AI systems6
A.9.2Processes for responsible use of AI systems7
A.9.3Objectives for responsible use of AI system8
A.9.4Intended use of the AI system5

Tell me when ISO/IEC 42001:2023 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Risk-based audit programme with frequency, methods and responsibilities
  • Audit plans with criteria and scope per audit
  • Auditor independence records
  • Audit reports to management and tracking of findings to closure
  • documented audit programme with frequency and methods
  • auditor independence declarations

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 42001:2023, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition