ISO/IEC 42001:2023, the world’s first certifiable standard for AI management systems, arrives at a pivotal moment. I had the honor of helping draft it as a member of the U.S. ISO delegation, and I’ve watched the regulatory ground shift under organizations ever since: the EU AI Act now requires conformity assessment for high-risk AI systems, and U.S. regulators are already penalizing companies for reckless AI deployment. Below, I break down what ISO 42001 certification actually requires, why AI governance can no longer be an afterthought, and the four concrete steps to take before you’re anywhere near audit-ready.

Context first

ISO 42001 comes at a pivotal moment. In Europe, Article 6 of the EU AI Act requires providers of high-risk AI systems to undergo a conformity assessment that certifies whether the AI system meets the legal requirements outlined in Title III, Chapter 2 of the Act. In the U.S., many federal agencies, states, and local government entities have already issued directives to regulate certain aspects of AI systems. More recently, the Federal Trade Commission banned the U.S. drugstore chain Rite Aid from using facial recognition technology for five years. Rite Aid was fined for its “reckless use of facial surveillance systems” and for deploying “a technology without reasonable safeguards.” According to the FTC’s statement, Rite Aid’s failure to implement comprehensive procedures to protect consumer privacy “left its customers facing humiliation and other harms.”

What is ISO/IEC 42001, and how does it help?

The new standard helps organizations establish a comprehensive governance framework that defines the roles and responsibilities of those in charge of the AI system, as well as the rules, processes, and controls needed to deploy AI systems more responsibly. It is a critical standard because it helps you organize internally to build a comprehensive AI management system that drives value. More importantly, it facilitates setting up an AI governance system that complies with laws and regulations. While it is a voluntary standard, it is also an auditable one that can be certified by a third party.

How do I implement the new standard?

To begin implementing the standard, I suggest the following four steps:

1. Understand the context of your AI system. Knowing about your AI system and how it interacts with the external and internal environment is a crucial step. Conducting an organizational analysis allows you to comprehend the bigger picture of how AI trends affect your business strategy, and how you can organize internally to leverage your AI system. Context analysis is also vital for legal purposes, as it helps you learn how laws, regulations, and standards evolve across jurisdictions.

2. Conduct a risk analysis. A critical requirement of the standard is to conduct a risk analysis to understand the impact of AI systems on stakeholders. Because AI systems are built on machine learning technology, they can learn and evolve independently. This is a novel and serious risk, as the outcome of the system’s self-learned capabilities may deviate from the initial intention, creating new risks the organization is unprepared for. Risks relating to system performance, and to consumer safety and security, are real. Legal and reputational risks are also critical and must be identified before model production. For an AI system to be certifiable, the standard requires three critical actions:

  • Risk assessment analysis. Conduct a set of “if-then” scenarios of possible outcomes. Spell out the risks that may harm stakeholders.
  • Risk treatment options. Define how you intend to treat each risk category identified above, and how you plan to mitigate it.
  • Impact assessment. Define how different AI products and services may impact your stakeholders. Impact assessment procedures are distinct from risk assessment procedures.

3. Engage your senior leadership. Regardless of whether you are building your AI management system from scratch or developing an existing one, AIMS requires resources, engagement, guidance, and a vision that only leaders can deliver. Leadership commitment helps define priorities, strategic direction, and the tangible and intangible resources required. Creating coherence and alignment between different parts of the system is the essence of what leadership engagement means.

4. Lead with Responsible AI principles. As a transformative technology, AI requires a transformational leadership style, one that shapes how you define priorities and use the technology. A Responsible AI pact that aligns with organizational values and culture should be in place to help employees understand when and how to use it. ISO/IEC 42001 requires a set of controls, such as an AI policy, data framework, documentation, computing systems, and tooling resources, to ensure AI systems act responsibly. Finally, make sure you identify the ethical principles that guide the AI system.

Preparing your organization for ISO certification

The first step in preparing your organization for ISO/IEC 42001 certification is to start immediately. Purchase the standard, read it, and understand it. Then assemble a team diverse enough to comprehend the complexity of the technology and its intricacies across the organization. I suggest the following six steps:

  1. Mobilize the team and clarify the mission. This is not an IT or a compliance issue. AI is a business issue.
  2. Set the roadmap by defining timelines and milestones for the certification team.
  3. Conduct discovery sessions to gather information and get everyone on the same page.
  4. Conduct an internal analysis to identify gaps in your current capabilities. Pay special attention to the AI talent pipeline.
  5. Expand the conversation to include your main stakeholders, to learn about the potential risks and harms of your AI systems (impact assessment) as well as the opportunities AI technology offers.
  6. Understand the regulatory environment by reviewing applicable laws, regulations, and ethical frameworks that apply to your AI products and services, in your jurisdiction and others.

A final word

This is a new standard addressing a new and constantly changing technology. The risks are high, and the stakes are even higher. If you start working on implementation today, it will take roughly 3–6 months to get certified. This is new, complex, and constantly shifting, and very few companies can achieve certification at present. For context: the EU AI Act, approved in June 2023, set a two-year grace period for organizations to comply with its legal requirements. Don’t delay implementation. Begin now.