Back to Learning Center

ISO 42001: A Complete Guide to the International AI Risk Management Standard

When generative and agentic AI systems first appeared, organizations struggled to secure them, due in part to a lack of guidance and standards for modern AI security.

ISO/IEC 42001 helps close that gap. As the first international standard designed to structure AI security strategies and operations, ISO/IEC 42001 can provide valuable guidance in areas like how to conduct risk assessment and what to prioritize when protecting AI infrastructure and services.

Read on for the details on how ISO/IEC 42001 works, which organizations should use it, the standard’s limitations, and best practices for getting the most from this AI risk management framework.

A quick note on naming: this article refers to the standard as both ISO/IEC 42001 and, for brevity, ISO 42001. Both names describe the same standard.

What is ISO/IEC 42001?

ISO 42001/IEC, which appeared in late 2023, is a comprehensive AI risk management framework. Its goal is to help organizations formalize their approach to identifying, assessing, mitigating, and preventing risks in AI systems.

ISO 42001 is also a certifiable standard (and it happens to be the first AI risk management framework within this category). Being a certifiable standard means that independent auditors can use the framework to assess organizations’ AI security practices.

ISO/IEC 42001 vs. NIST AI RMF

ISO/IEC 42001 is not the first major AI risk management framework to come into existence. It was preceded by the NIST AI Risk Management Framework (NIST AI RMF).

ISO 42001 and NIST AI RMF are broadly similar in that they both provide guidance on securing AI systems. However, NIST AI RMF is outcome-focused and non-prescriptive, whereas ISO 42001 offers more specific guidance in the form of 38 controls covering data, lifecycle, third-party risk assessment and management, impact assessment, and more.

Another important difference is that, unlike ISO/IEC 42001, NIST AI RMF is not a certifiable standard. This means that businesses can’t use the NIST AI RMF to undergo independent audits that demonstrate their compliance with an AI security framework.

ISO 42001 vs. ISO 27001

ISO/IEC 42001 is also distinct from ISO 27001. The latter is a general-purpose information security framework. It’s useful for structuring overall IT security strategies, but it includes no measures that are specific to AI security.

The EU AI Act and ISO 42001

ISO/IEC 42001 is related to, but distinct from, the EU AI Act. The latter is a regulation that addresses AI safety, fundamental rights, and risk tiering for organizations that operate within the European Union. In contrast, ISO 42001 is a voluntary standard that no organization is required to adopt.

Adopting ISO 42001-based practices can help businesses comply with the EU AI Act. However, on its own, ISO 42001 compliance doesn’t guarantee EU AI Act compliance.

White Paper

Operationalizing CTEM Through External Exposure Management

CTEM breaks when it turns into vulnerability chasing. Too many issues, weak proof, and constant escalation…

This whitepaper offers a practical starting point for operationalizing CTEM, covering what to measure, where to start, and what “good” looks like across the core steps.

Get the White Paper

Essential components of ISO 42001

ISO 42001’s major components include organizational context, AI risk assessment, responsible and ethical AI principles, AI security controls, and documentation.

Here’s a detailed look at how the framework approaches each of those requirements.

Organizational context and management

ISO/IEC 42001 requires organizations to establish a formal understanding of the context in which AI systems are developed, deployed, or used.

Specifically, Clause 4.1 requires organizations to identify internal and external issues that can affect the effectiveness of their Artificial Intelligence Management System (AIMS), while Clause 4.2 requires consideration of the needs and expectations of relevant interested parties. Clause 4.3 further requires organizations to define and document the scope of the AIMS, including which AI systems, business functions, and operational activities fall under governance. These requirements ensure that AI governance aligns with organizational objectives, stakeholder expectations, legal obligations, and business risks.

In a similar vein, Clause 5 addresses management oversight, requiring organizations to establish an AI policy, as well as clearly defined roles, responsibilities, and authorities for enforcing it. Organizations must also assign accountability for AI governance and ensure that management actively supports the implementation and continual improvement of the AIMS.

Together, Clauses 4 and 5 establish the governance framework necessary to oversee AI systems throughout their lifecycle and ensure that AI-related decisions are aligned with organizational priorities and risk tolerance.

AI risk assessment

AI risk assessment is a core requirement of ISO 42001. It’s addressed primarily through Clause 6.1, which states that organizations must establish processes to identify, analyze, evaluate, and treat AI-related risks and opportunities. Clause 6.1.2 specifically requires an AI risk assessment methodology that considers risks arising from the development, deployment, operation, and use of AI systems. The standard also requires organizations to assess potential impacts associated with AI systems and incorporate those findings into planning and decision-making activities.

Importantly, risk assessment under ISO 42001 extends beyond traditional cybersecurity concerns to include issues such as bias, fairness, transparency, safety, regulatory compliance, and societal impacts. Organizations must use the results of risk assessments to determine appropriate risk treatment measures under Clause 6.1.3 and integrate those measures into operational controls. Because AI risks and threats evolve over time, risk assessment is not a one-time exercise; it must be continuously reviewed as AI systems change, new use cases emerge, or the external environment shifts.

Responsible and ethical AI

ISO 42001 embeds responsible and ethical AI principles throughout the management system rather than treating them as standalone requirements. Clause 4.1 requires organizations to consider ethical factors when determining the context of the organization, while Clause 6.1.4 requires AI system impact assessments that evaluate potential consequences for individuals, groups, and society. These provisions ensure that organizations systematically identify and address concerns related to fairness, accountability, transparency, explainability, and human oversight.

The standard further reinforces responsible AI through Annex A controls, particularly those related to impact assessment (A.5), information for interested parties (A.8), use of AI management systems (A.9), and responsible use of AI. Organizations are expected to establish governance processes that mitigate harmful outcomes, provide appropriate transparency, and ensure that AI systems are used in ways consistent with organizational values and stakeholder expectations.

As a result, ethical considerations become part of ongoing governance, risk management, and operational activities rather than isolated compliance exercises.

AI security measures and controls

The framework requires organizations to implement controls that protect AI management systems, their data, and supporting infrastructure from cyber threats. More specifically, Clause 8 requires controls to manage identified risks and support secure AI operations throughout the AI lifecycle. These operational controls must align with the outcomes of risk assessments and be integrated into activities such as model development, validation, deployment, monitoring, and change management.

Additional security requirements are reflected in Annex A, which includes controls addressing AI system lifecycle management (A.6), data governance (A.7), organizational responsibilities (A.3), and third-party relationships (A.10). Together, these controls help organizations manage risks such as unauthorized access, data manipulation, model compromise, insecure development practices, and supply-chain vulnerabilities. Rather than prescribing specific technical safeguards, ISO/IEC 42001 requires organizations to select and implement security controls appropriate to their risk environment and document those decisions through a Statement of Applicability.

Documentation

Documentation is a foundational requirement of ISO/IEC 42001. It’s addressed primarily in Clause 7.5, which requires organizations to create, maintain, and control documented information necessary for the effectiveness of the AIMS. Required documentation typically includes recording the scope of the AIMS, AI policies, risk assessment methodologies, impact assessments, objectives, operational procedures, monitoring records, audit results, and management review outputs. The purpose is to ensure traceability, consistency, accountability, and auditability across AI governance processes.

Documentation also plays a critical role in demonstrating AI compliance and supporting continual improvement. Organizations must maintain evidence showing that AI risks have been assessed, controls have been implemented, and governance processes are operating as intended.

Records generated through monitoring, internal audits, corrective actions, and management reviews provide the evidence needed to demonstrate conformity with ISO/IEC 42001 requirements and support ongoing improvements to AI governance practices.

How ISO/IEC 42001 strengthens AI compliance

From the perspective of AI compliance, ISO/IEC 42001 stands out because it’s the first certifiable standard for the secure and responsible use of AI. This means that organizations can use the framework to undergo third-party audits that demonstrate their commitment to AI security. In addition to helping to reveal internal shortcomings that businesses should address to improve their own operations, ISO 42001 audits can help prove to customers, partners, regulators, and other stakeholders that the business takes AI security seriously and that it has the proper controls in place to detect and mitigate AI risks.

This is not to say that adopting ISO/IEC 42001 or passing an ISO audit guarantees an organization has completely addressed all AI-related risks. It doesn’t, because ISO 42001 doesn’t address every potential type of AI risk. It’s limited to the components and risk categories described above.

Still, ISO 42001 AI compliance is a good starting point for organizations seeking a formal means of implementing AI security.

Tips from the Expert

Rob Gurzeev CEO and Co-Founder

Rob Gurzeev, CEO and Co-Founder of CyCognito, has led the development of offensive security solutions for both the private sector and intelligence agencies.

Here are our tips for conquering AI security risks with help from ISO 42001:

  • Prioritize AI risks based on context and validation: Not all AI security threats pose the same level of risk. To decide what to prioritize, assess vulnerability exploitability, as well as the role that vulnerable systems play in the business and which types of data they process. Be sure, too, to validate that mitigations actually resolve cyber threats.
  • Continuously monitor for new AI assets and exposures: ISO 42001 provides guidance on how to secure AI assets – but new AI applications and services come online all the time, and you can’t protect what you don’t know about. That’s why CTEM is critical for staying ahead of AI risks.
  • Maintain documented policies, procedures, and evidence of compliance: Frameworks like ISO 42001 deliver the greatest benefit when organizations apply them consistently. To that end, documenting AI security policies, procedures, and outcomes is an essential best practice.
  • Continuously improve AI governance through measurement, auditing, and review: Achieving a baseline of ISO 42001 compliance doesn’t mean your AI security journey is complete. Businesses should strive to improve their AI security posture continuously by scanning for new assets and risks on an ongoing basis.

Who needs to comply with ISO/IEC 42001?

ISO 42001 is a voluntary standard. This means that no organization is formally required to adopt it or undergo relevant audits. In this sense, ISO 42001 is different from regulations like the GDPR or HIPAA, which are legal requirements that businesses operating in certain jurisdictions or industries are obliged to follow.

Nonetheless, deciding to comply with ISO 42001 can be a smart choice for organizations aiming to systematize their approach to AI security. It’s especially valuable given that modern AI systems (specifically, those powered by LLMs) remain quite novel, and many businesses are still struggling to secure them. ISO 42001 provides a structured framework for AI security that can help prevent oversights or gaps, allowing businesses to derive the most value from AI without letting it become the weakest link in their cybersecurity strategies.

Limitations of ISO/IEC 42001

While ISO 42001 is a powerful framework for helping establish foundational AI security practices, it’s not without its limitations and potential drawbacks, such as:

  • Generic guidance that lacks specificity: The framework requires high-level practices, such as establishing an AI policy, but it doesn’t offer highly specific guidelines about how to secure AI management systems. This is deliberate; the broadness of the framework helps ensure that it can remain relevant as AI technology evolves. Still, it can leave some organizations with uncertainty about exactly how to approach the technical specifics of AI security.
  • Lack of regulatory teeth: As a voluntary standard, ISO 42001 can’t obligate organizations to follow AI security best practices. There’s no guarantee that the AI security hygiene of the typical organization will improve as a result of the standard.
  • Immature auditing landscape: While ISO 42001 is a certifiable framework, it can be tough to find independent auditing firms that will conduct 42001 assessments. This may change over time as the standard gains wider adoption, but for now, it is a limitation for businesses aiming to use the standard as a way of demonstrating AI security best practices.

How ISO/IEC 42001 reinforces the need for AI exposure management

ISO 42001 doesn’t refer explicitly to AI exposure management – meaning the practice of continuously monitoring for and remediating security risks within AI management systems. However, the framework strongly implies that organizations should be doing these things. Continuous exposure management should be part of the AI policy that businesses develop under ISO 42001, as it’s only through exposure management that organizations can meet the risk assessment and security control requirements of the framework.

In this sense, ISO 42001 is another impetus for adopting Continuous Threat Exposure Management (CTEM) and ensuring that it extends to AI management systems.

Best practices for achieving ISO/IEC 42001 compliance

To leverage ISO 42001 to the fullest effect, consider the following best practices:

Map and document AI systems and security risks

ISO 42001 requires organizations to establish, maintain, and continually improve an AI management system. The ability to do so depends on understanding the AI management systems, data, processes, and risks within scope. Maintaining accurate inventories and risk documentation supports requirements related to organizational context, risk identification, AI governance, and documented information.

Prepare a customized AI risk profile

The framework emphasizes risk-based management of AI systems, requiring organizations to assess risks in light of their specific business objectives, regulatory obligations, stakeholders, and AI use cases. A tailored AI risk profile helps ensure that risk treatment activities align with the organization’s unique operational and compliance requirements.

Implement relevant AI security controls

The standard requires organizations to select and apply controls that address identified AI-related risks, including risks affecting security, safety, transparency, reliability, and responsible AI use. Implementing appropriate technical and administrative safeguards demonstrates that risks are being managed through effective treatment measures rather than merely documented.

Deploy checks and validations

ISO 42001 calls for ongoing monitoring, measurement, evaluation, and improvement of AI systems and the AI management system itself. Validation processes, testing procedures, audits, and continuous oversight help verify that AI systems operate as intended, controls remain effective, and emerging risks are identified before they create compliance gaps.

Streamlining AI governance with CyCognito

ISO 42001 requires you to define which AI management systems are in scope, assess their risk, and prove your controls work. The standard sets those requirements; it does not produce the evidence.

CyCognito is a leading external attack surface management platform that continuously discovers and validates every internet-facing AI asset you run, generating the audit-ready evidence ISO 42001 depends on, starting from nothing more than your organization’s name.

  • Discovers internet-facing AI assets, MCP servers, and shadow AI so your AIMS scope and asset inventory stay accurate as deployments change
  • Continuously validates whether discovered AI exposures are actually exploitable, so your risk assessments reflect real risk instead of theoretical severity
  • Assesses externally hosted and third-party AI exposure, supporting the supply-chain and third-party relationship controls in Annex A
  • Generates documented, repeatable evidence that controls work, the proof an ISO 42001 audit and Statement of Applicability require
  • Prioritizes findings by exploitability and business context, then tracks them through to verified closure

Continuous validation narrows a noisy backlog to the roughly 0.1% of findings confirmed exploitable, then documents that those exposures were closed, giving an ISO 42001 auditor evidence of control effectiveness rather than a policy on paper.

If you want to see CyCognito in action, click here to schedule a 1:1 demo.

Explore all guides

AI Security

AI Security

AI security covers prompt injection, model poisoning, insecure agents, MCP servers, shadow AI, and more. Learn the key risks and best practices for securing AI systems and infrastructure.

Learn More about AI Security
API Security

API Security

APIs, the unseen connections powering modern apps, can be vulnerable entry points for attackers. Weak API security exposes sensitive data and critical functions, potentially leading to breaches and disruptions.

Learn More about API Security
Application Security

Application Security

Application security (AppSec) involves safeguarding applications against threats throughout their lifecycle. This encompasses the entire process from design to deployment, ensuring that applications remain resilient against cyber threats.

Learn More about Application Security
Attack Surface Management

Attack Surface Management

Attack surface management is the continuous process of identifying and reducing an organization’s exposed assets and vulnerabilities before attackers can exploit them.

Learn More about Attack Surface Management
Cloud Security

Cloud Security

Cloud security refers to the discipline of protecting cloud-based infrastructure, applications, and data from internal and external threats.

Learn More about Cloud Security
Cyber Attack

Cyber Attack

A cyber attack is an attempt by hackers to damage or disrupt a computer network or system.

Learn More about Cyber Attack
DRPS

DRPS

A digital risk protection service (DRPS) offers visibility and defense against cybersecurity threats to an organization’s digital attack surfaces.

Learn More about DRPS
Exposure Management

Exposure Management

Exposure management is a set of processes which allow organizations to assess the visibility, accessibility, and risk factors of their digital assets.

Learn More about Exposure Management
Penetration Testing

Penetration Testing

Penetration testing, often called pentesting, is a simulated cyberattack on a computer system, network, or application to identify vulnerabilities.

Learn More about Penetration Testing
Red Teaming

Red Teaming

Red teaming is a security assessment method where a team simulates a real-world cyberattack on an organization to identify vulnerabilities and weaknesses in their defenses. This helps organizations improve their security posture by revealing potential attack vectors and response inefficiencies.

Learn More about Red Teaming
Threat Hunting

Threat Hunting

Threat hunting is a proactive cybersecurity practice where security teams search for and isolate advanced threats that have bypassed traditional security measures. It involves actively searching for malicious activity within a network, rather than just responding to alerts from security systems.

Learn More about Threat Hunting
Threat Intelligence

Threat Intelligence

Threat intelligence is the process of gathering, analyzing, and interpreting information about potential or actual cyber threats to an organization. It’s a proactive approach that helps organizations understand the threat landscape, identify risks, and implement effective security measures.

Learn More about Threat Intelligence
Vulnerability Assessment

Vulnerability Assessment

Vulnerability assessment is the process of identifying, quantifying, and prioritizing vulnerabilities in a system.

Learn More about Vulnerability Assessment
Vulnerability Management

Vulnerability Management

Vulnerability management is a comprehensive approach to identifying and reporting on security vulnerabilities in systems and the software they run.

Learn More about Vulnerability Management

By clicking submit, I acknowledge receipt of the CyCognito Privacy Policy.

Thank you! Here is the report you requested.

Click below to access your copy of the "Operationalizing CTEM With External Exposure Management" white paper.

Read the White Paper
Cycognito White Paper

Operationalizing CTEM With External Exposure Management

Operationalizing CTEM With External Exposure Management

CTEM breaks when it turns into vulnerability chasing. This whitepaper gives a practical starting point to operationalize CTEM through exposure management, with requirements, KPIs, and where to start.