ISO/IEC 42001 – Artificial Intelligence

A management system that promotes the ethical, trustable, and safe use of Artificial Intelligence in business processes

ISO/IEC 42001The ISO/IEC 42001 standard introduce a management system for Artificial Intelligence (AI). 

AI is a discipline that focuses on developing the ability of an IT system to imitate human characteristics such as reasoning, learning, planning, and creativity, through learning processes known as "machine learning". AI is increasingly being applied in contexts that use Information Technology to support business processes, including healthcare, finance, transport, human resources, and entertainment.

The integration of AI into processes that have traditionally relied on human thought raises a series of ethical concerns and risks associated with granting decision-making power to automated tools. These tools can change their behavior over time and may be influenced by not transparent factors beyond the control of process owners.

The AI management system aims to provide organizations - of any size and scope of activity - with the tools to govern the AI processes of their interest, whether as developers, suppliers or users of AI systems. This ensures that, the market is provided with guarantees of ethical, responsible, trustable, and safe use of AI.

Why choose RINA?

With our many years of experience in the ICT sector and ISO/IEC 27001 and ISO/IEC 20000 certifications, our auditors have specific skills in Computer Science and programming. Additionally, they actively participate in Artificial Intelligence Study Communities to further their knowledge and expertise. 

Certification process 

  • Completion of the information questionnaire. 
  • Receipt of the technical-economic offer which, once accepted, constitutes the service provision contract.
  • Conducting audit activities, both on-site and off-site, and issuing a final report.
  • If the previous phases are successful, the certification is evaluated by a Technical Committee.
  • If the previous steps are successful a certificate of conformity is issued.
  • Annual audit for certificate maintenance. 

The ISO/IEC 42001 certification is valid for years and can be renewed at the end of the three-year period.

Our experts answer to the most frequently questions

Our organization provides consulting services and we don’t develop systems based on Artificial Intelligence. Can we apply for ISO/IEC 42001 certification?

Yes, the Artificial Intelligence management system can be effectively used by developers, suppliers and users of AI-based products and services.  

Is ISO/IEC 42001 a technical standard for Artificial Intelligence programming techniques?

No. Like other standards (such as 9001, 14001 and 27001), ISO/IEC 42001 establishes the requirements for developing an Artificial Intelligence management system. This includes the organizational, operational and risk management aspects useful for achieving corporate objectives and ensuring ethical use, responsible and safe of Artificial Intelligence. 

Is it mandatory to have an ISO 9001 certification to be ISO/IEC 42001 certified?

No, ISO/IEC 42001 is a standalone certification. However, having an ISO 9001 management system related to processes that use AI techniques can facilitate the implementation of the standard. In fact, ISO/IEC 42001 is design to align perfectly with ISO 9001, making it easier to integrate with the Quality Management System (QMS). 

Regulatory Focus  

From a technical point of view, AI management systems refer to some several ISO framework standards, such as ISO/IEC TS 4213, 23053 and 5259 on "Machine Learning", ISO/IEC 5338 on the "System life cycle", as well as the methodological standards ISO/IEC 22989 (Concepts and terminology), 23894 (Risk Management), 24368 (Ethical aspects). 

NIST has also developed a "Risk Management Framework". 

In the legislative field, the "Artificial Intelligence Act" is being approved on the European territory, which will be the main regulation governing the use of Artificial Intelligence based on the level of risk assigned to its applications.  

Contact us
Embrace innovation
Find the nearest RINA office and speak with our experts
  • Country/Region
  • Albania
  • Argentina
  • Bangladesh
  • Brazil
  • Bulgaria
  • China
  • Denmark
  • Egypt
  • Germany
  • Greece
  • Hong Kong
  • India
  • Indonesia
  • Italy
  • Kazakhstan
  • Lebanon
  • Malaysia
  • Netherlands
  • Poland
  • Republic of Korea
  • Romania
  • Russia
  • Spain
  • Turkey
  • United Arab Emirates
  • United Kingdom
Resources

Certification rule

pdf

ISO 42001 rule appendix

pdf

General contract conditions

pdf

Rules governing the use of the RINA figurative mark in license agreements

pdf

Complaints, observations and appeals

General information questionnaire

docx

Specific information questionnaire

docx

Related services

You may also like