> ## Documentation Index
> Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with ISO 42001

> A practical guide to building an AI management system aligned to ISO/IEC 42001 using Matproof.

# Getting Started with ISO 42001

ISO/IEC 42001:2023 is the international standard for **Artificial Intelligence Management Systems (AIMS)**. It provides a framework for organizations that develop, provide, or use AI systems to manage AI-related risks responsibly, establish governance, and demonstrate trustworthy AI practices.

Published in December 2023, ISO 42001 is the first management system standard specifically for AI. It follows the familiar ISO high-level structure (Harmonized Structure), making it straightforward to integrate with ISO 27001, ISO 9001, and other management system standards.

Matproof maps ISO 42001 requirements to controls, policies, and evidence workflows so you can build your AIMS and prepare for certification.

<Note>
  Activate ISO 42001 under **Settings - Frameworks - ISO 42001**. Controls are pre-populated based on the standard's clauses and Annex A/B controls.
</Note>

***

## Who Should Implement ISO 42001?

ISO 42001 is relevant to any organization involved in the AI lifecycle:

* Organizations that **develop** AI systems
* Organizations that **deploy or operate** AI systems
* Organizations that **provide data or components** for AI systems
* Organizations seeking to demonstrate responsible AI governance to customers, regulators, or partners

<Tip>
  ISO 42001 pairs well with the EU AI Act. While the AI Act sets legal requirements, ISO 42001 provides the management system framework to meet them systematically. Certification can support your conformity assessment evidence.
</Tip>

***

## Standard Structure

ISO 42001 follows the ISO Harmonized Structure:

| Clause | Topic                                                                                         | Matproof Module           |
| ------ | --------------------------------------------------------------------------------------------- | ------------------------- |
| 4      | Context of the organization                                                                   | Policies, Controls        |
| 5      | Leadership                                                                                    | Policies, People          |
| 6      | Planning (risk and opportunity assessment)                                                    | Risk Management           |
| 7      | Support (resources, competence, awareness, communication, documented information)             | People, Evidence          |
| 8      | Operation (AI risk assessment, AI risk treatment, AI system impact assessment)                | Risk Management, Controls |
| 9      | Performance evaluation (monitoring, measurement, analysis, internal audit, management review) | Audit Programs, Controls  |
| 10     | Improvement (nonconformity, corrective action, continual improvement)                         | Corrective Actions        |

### Annex A - AI Controls

Annex A provides a set of reference controls organized into key themes:

* AI policies and governance
* AI system lifecycle management
* Data management for AI
* AI system performance monitoring
* Third-party and supply chain considerations
* Responsible AI (fairness, transparency, accountability)

### Annex B - Implementation Guidance

Annex B provides detailed implementation guidance for each Annex A control.

***

## Recommended Implementation Plan

<Steps>
  ### Step 1 - Define the AIMS scope and context

  1. Identify the AI systems and activities covered by your AIMS
  2. Document interested parties and their requirements (customers, regulators, affected persons)
  3. Determine the boundaries and applicability of your AIMS
  4. Record the scope in **Settings - Organization**

  ### Step 2 - Establish AI governance and leadership

  1. Go to **Policies - Generate** and create your AI Management System Policy
  2. Ensure top management demonstrates commitment to the AIMS
  3. Assign roles and responsibilities for AI governance
  4. Define your AI risk appetite and ethical principles
  5. Document the governance structure in the People module

  ### Step 3 - AI risk assessment

  Clause 6.1 and Clause 8 require both organizational and AI system-level risk assessments:

  1. Go to **Risk Management - New Risk Assessment**
  2. Assess organizational risks to the AIMS (Clause 6.1)
  3. For each AI system, conduct an **AI risk assessment** covering: accuracy, reliability, security, bias, fairness, transparency, and safety
  4. Conduct **AI system impact assessments** for systems that may significantly affect individuals or groups
  5. Document risk treatment plans with clear ownership

  ### Step 4 - Implement Annex A controls

  Work through the Annex A control set in **Controls - ISO 42001**:

  * AI system lifecycle controls (design, development, deployment, monitoring, decommissioning)
  * Data management controls (data quality, provenance, bias assessment)
  * Performance and monitoring controls
  * Third-party and supply chain controls
  * Responsible AI controls (fairness, transparency, explainability, accountability)

  For each control, document its implementation, assign an owner, and link supporting evidence.

  <Tip>
    If you already have ISO 27001 implemented, many ISO 42001 controls around information security, access management, and risk methodology will overlap. Use the framework mapping in Matproof to identify shared controls and avoid duplicate effort.
  </Tip>

  ### Step 5 - Data governance for AI

  AI systems depend on data quality. ISO 42001 requires specific data management practices:

  1. Document data sources, quality criteria, and preprocessing steps for each AI system
  2. Assess training and testing data for bias and representativeness
  3. Establish data provenance tracking
  4. Define data retention and deletion policies aligned with your AI systems' lifecycles

  ### Step 6 - Monitoring and measurement

  1. Define performance metrics for each AI system (accuracy, fairness metrics, drift indicators)
  2. Establish monitoring processes to detect performance degradation
  3. Document how you measure the effectiveness of your AIMS
  4. Set up regular management reviews (at least annually)

  ### Step 7 - Internal audit

  1. Go to **Audit Programs - New Audit - ISO 42001**
  2. Audit against all clauses and applicable Annex A controls
  3. Document findings as Corrective Actions
  4. Verify that corrective actions address root causes
  5. Present audit results to management as input for the management review

  ### Step 8 - Management review and certification

  1. Conduct a formal management review covering: AIMS performance, risk assessment results, audit findings, and improvement opportunities
  2. Document management review outputs (decisions and actions)
  3. When ready, engage an accredited certification body for Stage 1 and Stage 2 audits
</Steps>

***

## Relationship to Other Standards

| Standard          | Relationship                                                                                                                           |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| **ISO 27001**     | Shared Harmonized Structure. ISO 42001 addresses AI-specific risks while ISO 27001 covers information security. Many controls overlap. |
| **ISO 9001**      | Quality management practices complement AI system lifecycle management.                                                                |
| **EU AI Act**     | ISO 42001 certification provides structured evidence for EU AI Act compliance, particularly for high-risk AI system governance.        |
| **ISO/IEC 23894** | AI risk management guidance that complements the risk assessment requirements in ISO 42001.                                            |

***

## Next Steps

* [Risk Management](/features/risk-management) - conducting AI risk assessments and impact assessments
* [Policy Management](/features/policy-management) - generating your AI Management System Policy
* [Controls](/features/controls) - working through Annex A controls
* [Audit Programs](/features/audit-programs) - planning your internal audit and certification
