UNUS London  —  Compliance Architecture Division  |  UNCLASSIFIED // REGULATED INDUSTRIES
Home Solutions Legal & Professional Financial Services Manufacturing Healthcare Academy Blogs Ebooks About Book Discovery Call UNUS Govern
Standard Reference // ISO/IEC 42001:2023

Artificial Intelligence
Management Systems

ISO/IEC 42001:2023 is the world's first international standard specifying requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS). UNUS London delivers database-first AIMS infrastructure that maps every clause to controlled evidence — from AI risk assessments and impact registers to policy documentation and SRA-aligned governance records.

Standard Metadata
Standard Reference
ISO/IEC 42001:2023
Edition
First Edition — 2023
Governing Body
ISO/IEC JTC 1/SC 42
Annex A Controls
38 Controls — 9 Domains
Regulatory Scope
AI Governance · Risk · Ethics
UNUS Readiness Score
91/100
Deployment Tier
Enterprise — £32,347
Aligns With
ISO 27001 · EU AI Act · ITIL 4
🤖
Standard Purpose
Specifies requirements for an AIMS — a structured framework governing the responsible development, deployment, and use of AI systems. Organisations shall apply risk-based controls across AI lifecycle stages, from design through decommissioning.
📋
First Edition Scope
ISO/IEC 42001:2023 introduces 38 controls across nine Annex A domains, covering AI policy, human oversight, data governance, system transparency, and impact assessment. It follows the ISO High Level Structure (HLS) for integration with ISO 27001 and ISO 9001.
⚖️
UK Regulatory Relevance
Essential for organisations subject to SRA technology governance requirements, ICO AI guidance, FCA operational resilience obligations, and those preparing for EU AI Act compliance. UK law firms deploying AI in client-facing matters shall evidence AIMS controls.

The AIMS Standard
Clause Structure

ISO/IEC 42001:2023 follows the ISO High Level Structure (HLS), enabling integration with ISO/IEC 27001:2022 and ISO 9001:2015. Clauses 4–10 are normative — organisations shall comply with every requirement to claim conformance. All prescriptive language follows ISO/IEC Directives, Part 2.

Clause 4
Context of the Organisation
Organisations shall determine internal and external issues relevant to their AI purpose, identify interested parties and their requirements, and define the AIMS scope with respect to AI systems developed, provided, or used. AI-related objectives and obligations shall be documented.
AI Scope Register Stakeholder Map Shall Comply
Clause 5
Leadership & AI Policy
Top management shall demonstrate commitment to the AIMS, establish an AI policy governing responsible AI use, and assign roles for AI system ownership. The AI policy shall address human oversight principles and shall be communicated throughout the organisation.
AI Policy Document Role Assignment Shall Comply
Clause 6
Planning & AI Risk Assessment
Organisations shall establish an AI risk assessment process addressing the unique risks posed by AI — including algorithmic bias, opacity, and unintended outputs. AI objectives shall be established with measurable criteria. Risk treatment options shall be selected from Annex A controls.
AI Risk Register Impact Assessment Shall Comply
Clause 7
Support — Resources & Competence
Organisations shall determine and provide resources for the AIMS, ensure personnel are competent in AI governance, and raise AI awareness across the organisation. Documentation shall be controlled and retained as evidence. Competence records shall be maintained as AIMS evidence.
Competence Records Document Control Shall Comply
Clause 8
Operation — AI System Lifecycle
Organisations shall plan and control processes for the full AI system lifecycle — from design and data acquisition through deployment, monitoring, and decommissioning. AI impact assessments shall be conducted. Changes shall follow a controlled change management process.
Lifecycle Controls Change Management Shall Comply
Clause 9
Performance Evaluation
Organisations shall monitor, measure, analyse, and evaluate AIMS performance. Internal audits shall be conducted at planned intervals. Management reviews shall assess AIMS suitability, adequacy, and effectiveness. AI system performance metrics shall be defined and tracked.
Audit Programme Management Review Shall Comply
Clause 10
Improvement & Nonconformity
Organisations shall react to nonconformities in AI systems or governance processes, determine root causes, and implement corrective actions. Continual improvement of AIMS suitability and effectiveness shall be demonstrated through documented evidence of actions taken.
NCR Tracker Corrective Actions Shall Comply
Annex A / B
AI Controls & Implementation Guidance
Annex A provides 38 reference controls across nine domains that shall be selected in a Statement of Applicability (SoA). Annex B offers supplementary guidance on implementing AI-specific controls including transparency, human oversight, fairness, and data quality frameworks.
Statement of Applicability 38 Controls Select & Apply

38 AI Controls
Across Nine Domains

Annex A specifies 38 controls across nine domains. Organisations shall document their selection of applicable controls in a Statement of Applicability (SoA), providing justification for inclusions and exclusions. UNUS London maps each control to a database-driven evidence artefact.

🏛️
Policies for AI
Annex A.5 — AI Policy Domain
A.5.1
AI policy — top-level policy governing responsible AI use and objectives
A.5.2
AI system impact assessment — documented assessment before deployment
A.5.3
AI system lifecycle policy — controls across design, operation, and decommission
A.5.4
Resources for AI systems — capacity, infrastructure, and tooling policy
🗂️
Internal Organisation
Annex A.6 — Roles & Responsibilities
A.6.1
Roles and responsibilities for AI — documented ownership and accountability
A.6.2
Reporting obligations — defined escalation for AI incidents and concerns
A.6.3
Contact with authorities and interest groups — AI regulatory engagement
📦
Resources for AI Systems
Annex A.7 — Data & Infrastructure
A.7.1
Data — documented data sourcing, quality, and lineage controls
A.7.2
Tools and computing infrastructure — AI development environment controls
A.7.3
Human oversight — defined checkpoints for human review of AI outputs
A.7.4
Third-party AI suppliers — due diligence and contractual requirements
🔬
AI System Impact Assessment
Annex A.8 — Assessment & Evaluation
A.8.1
AI system impact assessment process — structured methodology and templates
A.8.2
Assessment of impacts on individuals and society — documented outcomes
A.8.3
AI system risk assessment — linked to the organisation's risk register
A.8.4
Bias assessment — documented evaluation and mitigation measures
🔄
AI System Lifecycle
Annex A.9 — Lifecycle Management
A.9.1
Intended purpose — documented specification before development begins
A.9.2
AI system design — controlled design documentation and review records
A.9.3
Data acquisition — provenance, consent, and quality controls
A.9.4
AI system testing and validation — test plans, results, and acceptance criteria
A.9.5
AI system documentation — user documentation and technical specifications
A.9.6
AI system decommissioning — controlled retirement and data disposition
🔒
Responsible AI
Annex A.10 — Transparency & Fairness
A.10.1
Transparency — disclosure of AI use in processes and client interactions
A.10.2
Accountability — documented responsibility for AI system outcomes
A.10.3
Explainability — records of AI decision rationale for regulated contexts
A.10.4
Fairness — documented measures to detect and mitigate discriminatory outputs

How UNUS Delivers
ISO/IEC 42001 Conformance

UNUS London's database-first approach maps every ISO/IEC 42001:2023 clause to a traceable, immutable evidence artefact. Each control in Annex A is addressed by a purpose-built database table — ensuring that every compliance assertion is backed by retrievable, timestamped documentation.

🗄️

AIMS Evidence Database

Clause 7.5 — Documented Information
  • AI Policy version-controlled document register with approval workflows
  • AI Risk Register with treatment status, owner, and review dates
  • Statement of Applicability (SoA) — database-driven with justification fields
  • AI Impact Assessment records retained with audit timestamp
  • Competence and training records linked to AI role assignments
  • Internal audit findings with corrective action tracking
🔍

AI Lifecycle Management

Clause 8 — Operational Controls
  • AI system register with status, purpose, owner, and risk classification
  • Design review records linked to intended purpose documentation
  • Data acquisition logs with provenance, consent basis, and quality scores
  • Validation and testing records with acceptance criteria and results
  • Deployment change management records aligned to ITIL 4 practices
  • Decommissioning checklists with data disposition evidence
⚖️

SRA Obligations Mapping

Legal Sector AI Governance
  • SRA Code of Conduct obligations cross-referenced to AIMS controls
  • Client disclosure records for AI-assisted legal work
  • Supervision register linking AI use to qualified supervisor oversight
  • Confidentiality impact assessments for AI data processing
  • Third-party AI supplier due diligence records and contractual controls
  • Incident register with SRA-reportable AI failure categorisation
📊

Performance & Monitoring

Clause 9 — Evaluation & Review
  • KPI dashboard for AIMS objectives with measurable targets
  • AI system performance monitoring logs with anomaly detection records
  • Internal audit programme with scheduled audits and findings register
  • Management review agenda templates with required AIMS inputs
  • Bias monitoring records with periodic re-assessment schedules
  • Nonconformity register with root cause analysis and closure evidence

The 9-Gap Guide Series
For UK Law Firms

UNUS London has produced the definitive implementation guide for ISO/IEC 42001:2023 in the UK legal sector — nine structured gap articles, each mapping a specific AIMS clause group to SRA obligations with a controlled document template that closes the identified gap.

Complete Implementation Resource

ISO/IEC 42001:2023
9-Gap Series for UK Law Firms

Nine gap articles. Nine controlled document templates. One complete AI Management System for UK law firms — aligned to ISO/IEC 42001:2023 and SRA Codes of Conduct. Each article identifies a specific compliance gap and delivers a production-ready document template to close it.

Access the Full Guide Series ↗ Discuss Implementation →
Series Stats
9
Gap Articles
9
Document Templates
Gap Article 1
Context & Stakeholder Register
ISO/IEC 42001:2023 — Clause 4
Gap Article 2
AI Policy & Leadership Commitment
ISO/IEC 42001:2023 — Clause 5
Gap Article 3
AI Risk Register & Treatment Plan
ISO/IEC 42001:2023 — Clause 6
Gap Article 4
Competence Framework & Training Log
ISO/IEC 42001:2023 — Clause 7
Gap Article 5
AI System Register & Lifecycle SOP
ISO/IEC 42001:2023 — Clause 8
Gap Article 6
AI Impact Assessment Template
ISO/IEC 42001:2023 — Annex A.8
Gap Article 7
Statement of Applicability (SoA)
ISO/IEC 42001:2023 — Annex A
Gap Article 8
Internal Audit Programme & Findings
ISO/IEC 42001:2023 — Clause 9.2
Gap Article 9
Nonconformity & Corrective Action Log
ISO/IEC 42001:2023 — Clause 10

ISO/IEC 42001:2023
Readiness Assessment

0 /100
AIMS Readiness Score
ISO/IEC 42001:2023
AI Policy & Leadership (Cl. 4–5) 95%
Risk Assessment & Planning (Cl. 6) 92%
Resources & Documentation (Cl. 7) 94%
AI Lifecycle Operations (Cl. 8) 89%
Performance Evaluation (Cl. 9) 91%
Annex A Control Coverage 88%
SRA Obligations Alignment 93%

Ready to Govern Your
AI Systems?

UNUS London deploys ISO/IEC 42001:2023-aligned AI Management Systems in under 90 days. Every clause is addressed by a database-driven evidence artefact — so when your regulator asks, the answer is already documented.