Glossary · AI governance and risk

ISO/IEC 42001

The international standard for an artificial intelligence management system, published in 2023. It specifies requirements for establishing, operating and continually improving the policies, processes and controls an organisation uses to develop, provide or use AI responsibly.

Why it matters

ISO/IEC 42001 gives AI governance a recognisable, auditable structure, in the same way ISO/IEC 27001 does for information security. It is certifiable, which makes it useful when customers or partners ask for evidence that AI is managed rather than improvised.

It is a management system standard, so it does not prescribe specific technical tests. Organisations still need to decide what evaluation, monitoring and oversight each AI use case requires.

In practice

For example, a UK software provider whose enterprise customers ask about its AI features might align its AI policy, risk assessment, supplier checks and incident process with ISO/IEC 42001, building on the controls it already operates for information security.

Where Rodan fits

Rodan produces the engineering evidence an AI management system relies on, including evaluation results, model documentation and monitoring, through Applied AI Engineering. See also what is AI governance and how do you implement it.

Related terms