Artificial intelligence is moving from pilots to everyday operations — in banks, telecoms, tax administrations and public services. With it come new questions: who is accountable for an AI system’s decisions, how is data protected, how are risks such as bias or errors managed? ISO/IEC 42001, published in December 2023, gives organisations a structured answer.
What ISO/IEC 42001 is
ISO/IEC 42001 specifies requirements for an AI management system (AIMS): the policies, roles, processes and controls an organisation uses to develop, provide or use AI responsibly. Like ISO/IEC 27001 for information security, it follows the common ISO management-system structure, so it can be integrated with existing systems.
Who should care
- Organisations that develop AI solutions for clients.
- Organisations that buy and deploy AI tools — chatbots, scoring models, document automation.
- Public institutions that use AI in services to citizens.
- Organisations already certified to ISO/IEC 27001 that want to extend their governance to AI.
Five steps to get started
- Inventory the AI systems you develop or use, including tools bought from vendors.
- Assign accountability: who owns each system and its risks?
- Assess risks and impacts — on people, data, operations and reputation.
- Define policies and controls proportionate to those risks.
- Train the people who build, buy and run AI systems.
Projects and AI governance go together
Many AI failures are project failures: unclear objectives, poor data, no plan for adoption. Combining ISO/IEC 42001 with an AI-specific delivery method such as PMI-CPMAI™ helps teams deliver AI that is both useful and well governed.
HOPE FOR AFRIKA offers ISO/IEC 42001 Lead Implementer and Lead Auditor programmes with PECB, and PMI-CPMAI™ training. See the Academy.


Leave a Reply