The OECD.AI Policy Navigator

Our policy navigator is a living repository from more than 80 jurisdictions and organisations. Use the filters to browse initiatives and find what you are looking for.

Information technology — Artificial intelligence — Management system (ISO/IEC 42001)


Added by:   OECD analyst
Added on:   02 Jul 2026
Updated by:   OECD analyst
Updated on:   28 Jul 2026

This standard specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an artificial intelligence management system within an organisation. It is intended for use by organisations providing or using products or services that utilise AI systems, helping them develop, provide or use such systems responsibly while meeting applicable requirements and stakeholder expectations. It applies to any organisation,

Initiative overview

This standard was prepared by Joint Technical Committee ISO/IEC JTC 1, Subcommittee SC 42, Artificial intelligence. It addresses the fact that AI is increasingly applied across sectors using information technology and expected to be a main economic driver, with certain applications giving rise to societal challenges. Specific considerations include AI used for automatic decision-making, sometimes in a non-transparent and non-explainable way, requiring specific management beyond classical IT systems; the use of data analysis and machine learning rather than human-coded logic; and AI systems performing continuous learning that change behaviour during use, requiring ongoing attention to ensure responsible use continues.

The initiative is intended to be integrated with an organisation's processes and overall management structure. Crucial management processes include determination of organisational objectives and involvement of interested parties; management of risks and opportunities; management of trustworthiness concerns such as security, safety, fairness, transparency and data quality throughout the AI system life cycle; and management of suppliers, partners and third parties providing or developing AI systems. Organisations can apply a risk-based approach to ensure the appropriate level of control for particular AI use cases, services or products within scope, with organisational needs, size and structure, and the expectations of interested parties all influencing implementation.

It applies the harmonised structure developed to enhance alignment among management system standards, facilitating consistency with other standards related to quality, safety, security and privacy. It avoids specific guidance on management processes, instead allowing organisations to combine generally accepted frameworks, other International Standards and their own experience for processes such as risk management and data quality management. An organisation conforming with the requirements can generate evidence of its responsibility and accountability regarding its role with respect to AI systems.

Stakeholders in development include national bodies that are members of ISO or IEC, participating through technical committees, along with other international organisations, governmental and non-governmental, in liaison with ISO and IEC.

About the policy initiative


Category:

  • AI Policy Frameworks and Initiatives (intergovernmental or supranational)

Initiative type:

  • Guidance/guidelines

Status:

  • Active

Start Year:

  • 2023

Target Sectors:


Other relevant urls: