A practical, clause-by-clause guide for establishing, implementing, and maintaining an AI Management System (AIMS) in conformance with ISO/IEC 42001:2023.
ISO/IEC 42001:2023 is the first international standard specifically designed for AI Management Systems. It provides a certifiable framework for governing AI activities across an organization, covering governance, risk management, ethics, operations, and continuous improvement.
This playbook is organized by the standard's core clauses (4 through 10). For each clause:
- Read the overview to understand the intent and scope
- Work through each sub-clause using the actionable checklists and guidance
- Collect evidence using the suggested artifacts for audit readiness
- Use the templates to jumpstart your documentation
ISO-42001-Playbook/
├── 00-getting-started/ # Prerequisites and roadmap
├── 01-clause-4-context/ # Organization context
├── 02-clause-5-leadership/ # Leadership and commitment
├── 03-clause-6-planning/ # Planning and risk management
├── 04-clause-7-support/ # Resources, competence, communication
├── 05-clause-8-operations/ # AI lifecycle and controls
├── 06-clause-9-performance/ # Monitoring, audits, reviews
├── 07-clause-10-improvement/ # Corrective action and continual improvement
├── templates/ # Ready-to-use document templates
├── appendices/ # Evidence matrix, glossary, related standards
└── research/ # Source research paper
| Phase | Clauses | Focus |
|---|---|---|
| 1. Foundation | 4, 5 | Understand context, secure leadership, define scope |
| 2. Planning | 6 | Assess risks, set objectives, plan changes |
| 3. Enablement | 7 | Allocate resources, build competence, establish communication |
| 4. Execution | 8 | Implement AI lifecycle controls and operations |
| 5. Evaluation | 9 | Monitor performance, conduct audits and reviews |
| 6. Improvement | 10 | Address nonconformities, drive continual improvement |
- ISO 9001:2015 - Quality management systems
- ISO/IEC 27001:2022 - Information security management systems
- ISO 31000:2018 - Risk management guidelines
- ISO 37301:2021 - Compliance management systems
- NIST AI RMF 1.0 - AI Risk Management Framework
- EU AI Act - European AI regulation
This playbook is derived from the research paper "Operationalizing ISO/IEC 42001: Requirements and Conformance Evidence for AI Management Systems" by Kassem Saleh and Hanady Abdulsalam (Kuwait University). See research/operationalizing-iso-42001.md.