AI Governance Frameworks

ISO/IEC 42001

ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system

The first certifiable international management-system standard for AI. Explained here through its risk and impact assessment requirements, and what they mean for data privacy when employees use AI tools at work.

International (voluntary, certifiable)Published December 2023; voluntary but certifiable by accredited auditorsVerified 2026-08-31

What it means for AI and data privacy

ISO/IEC 42001 is the AI equivalent of ISO 27001: a certifiable management system, called an AIMS, that proves to customers and regulators that your organization governs AI deliberately rather than by accident. Its core machinery is a pair of assessments you must run and keep running: an AI risk assessment (Clauses 6.1.2 and 8.2) covering risks to the organization, and an AI system impact assessment (Clauses 6.1.4 and 8.4) covering consequences for the individuals whose data the AI touches. Both assessments must reflect how AI is actually used, which means employee use of external AI tools with personal or confidential data is in scope whether or not it was ever approved. An organization that cannot say what data flows into which AI tools cannot complete either assessment honestly, and an auditor will ask for the evidence. Certification is voluntary, but it is fast becoming the artifact enterprise buyers request when AI shows up in a vendor questionnaire.

Who it applies to

  • Any organization that develops, provides, or uses AI systems and wants an auditable governance structure
  • Vendors asked for proof of responsible AI practices in procurement and security questionnaires
  • Organizations preparing for binding AI law (EU AI Act, provincial and state statutes) that want a recognized head start
  • Organizations already running ISO 27001 or ISO 9001 management systems, which ISO 42001 is designed to integrate with

Enforcement and penalties

ISO 42001 is a voluntary standard, so there are no statutory fines. The consequences are commercial and evidentiary: failing an audit means losing or never obtaining a certificate that customers increasingly require, and a certified organization that ignores its own documented AIMS gives regulators and litigants a ready-made record of what it knew and did not do. Conversely, a functioning AIMS is strong evidence of due diligence under laws such as the EU AI Act, which treat recognized standards as a path to demonstrating conformity.

Key provisions for AI and data privacy

Clause 6.1

Actions to address risks and opportunities

Clause 6.1 requires the organization to plan its AIMS around identified risks and opportunities. It contains the two signature planning requirements of the standard: Clause 6.1.2, an AI risk assessment with documented criteria that identifies and analyzes risks from the organization's use of AI, and Clause 6.1.4, an AI system impact assessment that evaluates consequences for individuals, groups, and society. Clause 6.1.3 then requires a treatment plan selecting controls, justified in a Statement of Applicability.

For an organization whose employees use external AI tools, the 6.1.2 risk assessment must cover the data those tools receive: prompts containing client records, health information, financials, or source code are a documented risk category, not an edge case. The 6.1.4 impact assessment forces a harder question: what happens to the actual people whose personal information an employee pastes into a chatbot? IBM found in 2025 that 63% of organizations have no AI governance policy at all, which means most organizations have not started what Clause 6.1 requires them to finish.

Clause 8.2

AI risk assessment in operation

Clause 8.2 moves the risk assessment from planning into operations: the organization must perform AI risk assessments at planned intervals and when significant changes occur, using the criteria defined under Clause 6.1.2, and retain documented results.

This clause is why a one-time workshop does not satisfy the standard. New AI tools appear in browsers monthly, and employees adopt them without asking: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage. A recurring risk assessment that never looks at actual, current AI usage across the workforce is assessing a fiction. Auditors will expect evidence that the inputs to each assessment reflect reality, which requires visibility into which tools are used and what data reaches them.

Clause 8.4

AI system impact assessment in operation

Clause 8.4 requires the organization to perform AI system impact assessments in accordance with Clause 6.1.4 at planned intervals and on significant change, and to keep documented information as evidence of the results.

Impact assessments look outward at the people affected. When personal or confidential data about clients, patients, students, or employees flows into external AI tools, the impact assessment must account for that exposure: who could be harmed, how severely, and what reduces the likelihood. An organization that redacts sensitive data before it enters AI tools can document a materially lower residual impact than one relying on a policy memo, and Clause 8.4 is where that difference gets written down.

Annex A, Control A.7

Data for AI systems

Annex A is the standard's control catalogue, selected and justified through the Statement of Applicability. The A.7 control family addresses data for AI systems: documenting data provenance, quality, preparation, and management across the AI lifecycle. Neighbouring families cover impact assessment processes (A.5), the AI system lifecycle (A.6), information for interested parties (A.8), and responsible use of AI (A.9, including acceptable-use direction).

A.7 obliges the organization to know and document what data its AI systems consume. Read together with the A.9 responsible-use controls, this covers the everyday case: employees feeding organizational data into AI tools. Evidence that sensitive data types are identified and controlled before entering AI tools, and that usage is monitored against a defined acceptable-use policy, is exactly the kind of documented operation of controls an ISO 42001 auditor samples.

Practical compliance steps

  1. 1Assign accountability for the AIMS and publish an AI acceptable-use policy that names permitted tools and prohibited data types
  2. 2Inventory actual AI usage across the organization, including unapproved browser-based tools, before writing the risk assessment
  3. 3Define AI risk criteria and run the Clause 6.1.2 risk assessment against real usage, not the approved-vendor list
  4. 4Run the Clause 6.1.4 impact assessment for systems touching personal or confidential data, documenting who could be affected and how
  5. 5Deploy a technical control that catches sensitive data in prompts at the point of entry, and reference it in the Statement of Applicability
  6. 6Schedule recurring Clause 8.2 and 8.4 reassessments, triggered also by new tools, new data types, and incidents
  7. 7Retain interception and usage reports as documented evidence for internal audit and certification audit sampling

How Sanitized AI maps to this

Clause 6.1.2 / 8.2 (AI risk assessment)

Administrator dashboards show which AI tools employees actually use and which categories of sensitive data appear in prompts, giving the recurring risk assessment real inputs instead of assumptions.

Clause 6.1.4 / 8.4 (AI system impact assessment)

Sensitive data in prompts is redacted before submission, which lowers the documented residual impact on the individuals whose personal information would otherwise reach external AI tools.

Annex A data and responsible-use controls

Interception reporting by data category provides ongoing documented evidence that the acceptable-use policy and data controls selected in the Statement of Applicability operate in practice, not just on paper.

Frequently asked questions

Is ISO 42001 certification mandatory?

No. It is a voluntary standard. But it is certifiable, and certification is increasingly requested in enterprise procurement and vendor security reviews wherever AI is part of the product or the workflow. It also serves as strong due-diligence evidence under binding AI laws, so many organizations pursue it before any regulator requires anything.

What is the difference between the AI risk assessment and the AI system impact assessment in ISO 42001?

The risk assessment (Clauses 6.1.2 and 8.2) looks at risks to the organization and its objectives from developing or using AI. The impact assessment (Clauses 6.1.4 and 8.4) looks outward at consequences for individuals, groups, and society affected by the AI system. Both are required, both must be documented, and both must be repeated at planned intervals and on significant change.

Does ISO 42001 cover employees using ChatGPT and other external AI tools?

Yes. The standard applies to organizations that use AI systems, not only those that build them, and its risk and impact assessments must reflect actual use. Employees pasting client data into external chatbots is an AI data flow the AIMS has to identify, assess, and control. Unapproved usage does not fall outside scope; it is precisely the unmanaged risk the assessments exist to surface.

How does ISO 42001 relate to ISO 27001?

They share the same management-system structure and are designed to be run together: ISO 27001 governs information security broadly, while ISO 42001 adds AI-specific machinery such as impact assessments and the Annex A controls on data for AI systems and responsible use. Organizations with an existing ISMS typically extend it rather than build a parallel system.

How does ISO 42001 help with EU AI Act compliance?

The EU AI Act expects providers of high-risk AI systems to run a risk management system and quality management system, and harmonized standards are the intended route to demonstrating conformity. ISO 42001 is not itself a harmonized standard under the Act, but it covers much of the same ground, and a working AIMS gives an organization most of the governance evidence the Act's obligations call for.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards