A management system that promotes the ethical, trustable, and safe use of Artificial Intelligence in business processes
ISO/IEC 42001 introduced the Artificial Intelligence Management System (AIMS).
Artificial Intelligence (AI) is the discipline focused on developing the ability of an IT system to simulate typically human tasks such as reasoning, learning, planning, and creativity through structured learning processes, including machine learning.
AI is increasingly being applied in technology-enabled business processes across a wide range of sectors, including healthcare, finance, energy, transportation, human resources, entertainment, and cybersecurity.
The introduction of AI into processes that have traditionally relied on human reasoning raises ethical concerns and risks associated with delegating decision-making powers to automated tools. These systems can modify their behavior over time based on the inputs they receive and may be influenced by factors that are not fully transparent and that lie beyond the control of process owners.
The purpose of an AI management system is to provide organisations of any size and industry with the tools needed to govern AI-related processes, whether they act as developers, providers, or users of such systems. In this way, organisations can offer the market assurance that Artificial Intelligence is being used in an ethical, responsible, trustworthy, and secure manner.
RINA can issue accredited certifications through Accredia, leveraging teams of highly qualified auditors.
In addition, our extensive experience in the ICT sector, gained through certifications such as ISO/IEC 27001 and ISO/IEC 20000-1, ensures that our audit teams possess specific expertise in information technology and software development. Furthermore, our professionals actively participate in study communities dedicated to Artificial Intelligence.
The ISO/IEC 42001 certification is valid for years and can be renewed at the end of the three-year period.
Yes, the Artificial Intelligence management system can be effectively used by developers, suppliers and users of AI-based products and services.
No. Like other standards (such as 9001, 14001 and 27001), ISO/IEC 42001 establishes the requirements for developing an Artificial Intelligence management system. This includes the organizational, operational and risk management aspects useful for achieving corporate objectives and ensuring ethical use, responsible and safe of Artificial Intelligence.
No, ISO/IEC 42001 is a standalone certification. However, having an ISO 9001 management system related to processes that use AI techniques can facilitate the implementation of the standard. In fact, ISO/IEC 42001 is design to align perfectly with ISO 9001, making it easier to integrate with the Quality Management System (QMS).
From a technical perspective, AI management systems refer to several ISO standards that provide guidance and context, including ISO/IEC TS 4213, ISO/IEC 23053, and ISO/IEC 5259 on Machine Learning, ISO/IEC 5338 on the System Life Cycle, as well as methodological standards such as ISO/IEC 22989 (Concepts and Terminology), ISO/IEC 23894 (Risk Management), and ISO/IEC 24368 (Ethical Considerations).
The National Institute of Standards and Technology (NIST) has also developed an AI Risk Management Framework.
From a regulatory standpoint, the Artificial Intelligence Act (AI Act) is now in force across the European Union (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744). It is the primary regulation governing the use of Artificial Intelligence based on the level of risk associated with AI-enabled applications.
The European standard EN 18286:2026 is aligned with and references the requirements of the EU AI Act.