Quality Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Quality Magazine logo
  • NEWS
  • PRODUCTS
    • FEATURED PRODUCTS
    • SUBMIT YOUR PRODUCT
  • CHANNELS
    • AUTOMATION
    • MANAGEMENT
    • MEASUREMENT
    • NDT
    • QUALITY 101
    • SOFTWARE
    • TEST & INSPECTION
    • VISION & SENSORS
  • MARKETS
    • AEROSPACE
    • AUTOMOTIVE
    • ENERGY
    • GREEN MANUFACTURING
    • MEDICAL
  • MEDIA
    • A WORD ON QUALITY PUZZLE
    • EBOOK
    • PODCASTS
    • VIDEOS
    • WEBINARS
  • EVENTS
    • EVENT CALENDAR
    • IMTS
  • DIRECTORIES
    • BUYERS GUIDE >
      • Supplier Insights
    • NDT SOURCEBOOK
    • VISION & SENSORS
    • TAKE A TOUR
  • INFOCENTERS
    • Digital Quality Management Systems
    • NEXT GENERATION SPC & QUALITY ANALYTICS
  • AWARDS
    • ROOKIE OF THE YEAR
    • PLANT OF THE YEAR
    • PROFESSIONAL OF THE YEAR
  • MORE
    • Expert Columns
    • NEWSLETTERS
    • QUALITY STORE
    • INDUSTRY LINKS
    • SPONSOR INSIGHTS
  • EMAG
    • eMAGAZINE
    • ARCHIVES
    • CONTACT
    • ADVERTISE
  • SIGN UP!
Management

Management

The Rise of AI Governance: Unpacking ISO/IEC 42001

The need for AI governance has never been more pressing.

By Carol Dudley, Chief Commerical Office
Virtual hand pointing at Artificial Intelligence button.

Image provided by NSAI from Canva

July 5, 2024

In the digital age, artificial intelligence (AI) has become a pervasive force across all industries, revolutionizing the way we live and work. The integration of AI into various sectors has been nothing short of transformative bringing unprecedented efficiencies and insights. In healthcare, AI-powered diagnostic tools have revolutionized disease detection and treatment planning, while in finance, AI algorithms have streamlined risk assessment and investment strategies. However, this rapid proliferation has also highlighted the pressing need for robust governance frameworks to ensure AI’s responsible development and deployment. The need for AI governance has never been more pressing. The consequences of unregulated AI can lead to ethical dilemmas, data and privacy breaches, concerns with the quality or integrity of data and unintended biases. As AI systems become increasingly complex and autonomous, the need to govern not only the products but also the organizations producing them has become paramount.

Implementing effective AI governance is a multifaceted challenge that organizations face. Many companies grapple with a knowledge gap, lacking a comprehensive understanding of AI technologies, their capabilities, and potential risks. This knowledge deficit can impede the development of appropriate governance frameworks. AI systems, particularly deep learning models, are often referred to as “black boxes” due to their opaque decision-making processes, making it difficult to audit and govern them effectively. Furthermore, AI systems can exhibit emergent behaviors that were not explicitly programmed or anticipated by their developers, posing challenges for governance and risk management.

Ethical considerations also present significant hurdles. AI systems can perpetuate societal biases, raise privacy concerns, and have unintended consequences. Addressing these ethical issues through governance frameworks is a complex undertaking. The rapid pace of AI development makes it arduous for governance frameworks to keep up with the latest advancements and potential risks. Additionally, the absence of clear and consistent regulations around AI governance across different jurisdictions creates uncertainty for organizations operating globally.

Determining liability and accountability for the actions or decisions made by AI systems is a challenging aspect of AI governance. Organizations must strike a delicate balance between fostering innovation with AI and implementing robust governance measures, which can sometimes be perceived as hindering progress.

These challenges highlight the multifaceted nature of AI governance and the need for a comprehensive approach that addresses technical, ethical, legal, and organizational aspects of AI development and deployment.

Recognizing the urgency for AI governance, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) have taken proactive steps to establish a comprehensive set of standards. These standards aim to provide guidelines for the responsible development, deployment, and management of AI systems across various industries. One of the most significant developments in this domain is the introduction of ISO/IEC 42001:2023 – Artificial Intelligence Management System Standard (AIMS). This standard establishes a framework for organizations to implement, maintain, and continually improve an AI management system, ensuring ethical, secure, and transparent AI practices. ISO/IEC 42001 is a management system standard (MSS), which means it outlines the requirements for establishing policies, procedures, and processes to achieve specific objectives related to AI governance. Unlike technical standards that focus on specific AI applications, ISO/IEC 42001 provides a holistic approach to managing AI-related risks and opportunities across an organization.

While ISO/IEC 42001 serves as the overarching framework for AI management systems, it is complemented by several other ISO standards that address specific aspects of AI governance:

ISO/IEC 38507:2022 – Governance Implications of AI: This standard provides guidance on the governance implications of AI systems, including ethical considerations, risk management, and stakeholder engagement.

ISO/IEC 23894:2022 – AI Risk Management: This standard offers a structured approach to identifying, analyzing, and mitigating risks associated with AI systems, ensuring their safe and reliable operation.

ISO/IEC 25059:2023 – Software Life Cycle for AI: This standard focuses on the quality aspects of AI systems, providing guidelines for the entire software life cycle, from design to deployment and maintenance.

These complementary standards are referenced in Annex B of ISO/IEC 42001, underscoring the importance of a holistic and integrated approach to AI governance.

ISO/IEC 42001 is structured around several key principles, including ethical and trustworthy AI, risk management, data governance, and continuous improvement. The key elements of the standard are the AI policy; responsibility for the implementation, operation, and management of AI systems; resource allocations of data, tools, systems, and people; AI risk assessment; AI impact assessment; aligning goals for responsible development and use of AI; determining requirements for the AI life cycle; data sources, data quality and data preparation; communication with stakeholders and relationships with third parties.

ISO/IEC 42001 is broken down into 10 clauses, providing a comprehensive framework for establishing and maintaining an effective AIMS. Clauses 4 through 10 form the core of the standard, outlining the essential requirements for establishing and maintaining and effective AIMS. Clause 4 focuses on the context of the organization which requires organizations to understand internal and external factors influencing their AIMS, including stakeholder needs and expectations, as well as the scope of the organization’s certification. Clause 5 of the standard, Leadership, outlines the requirements for top management’s commitment, establishing an AI policy, and fostering a culture of responsible AI use. Clause 6, Planning, covers the planning process for addressing risks and opportunities, setting AI objectives, and managing changes related to the AIMS. Clause 7, Support, focuses on ensuring the necessary resources, competence, awareness, communication, and documentation to support the AIMS effectively. Operations, Clause 8, provides requirements for operational planning, implementation, and control processes, including AI system impact assessments and change management. Clause 9, Performance Evaluation, outlines the requirements for monitoring, measuring, analyzing, and evaluating the AIMS’s performance, as well as conducting internal audits and management reviews. And clause 10, Improvement, emphasizes the need for continual improvement of the AIMS by addressing nonconformities, implementing corrective actions, and maintaining documented information for accountability and tracking progress.

The standard also includes four annexes that provide additional guidance:

Annex A: Describes the 39 controls organizations must implement to ensure responsible AI practices, covering areas such as data management, transparency, and ethical considerations. One of the critical aspects of Annex A is the emphasis on stakeholder engagement and transparency. Organizations are encouraged to involve relevant stakeholders, such as employees, customers, and regulatory bodies, in the development and deployment of AI systems. This approach fosters trust and accountability, ensuring that AI solutions align with societal values and ethical norms.

Annex B: Offers practical advice and methodologies for implementing the controls outlined in Annex A, including guidance on data management, risk assessment, and impact evaluation. It offers guidance on effective data management, risk assessment, and impact evaluation, ensuring organizations have the necessary tools to navigate the complexities of AI governance.

Annex C: Discusses AI risk sources, potential organizational objectives for AI, and background information on AI risk management.

Annex D: Explores industry-specific considerations and scenarios related to using AI and operating an AIMS.

By following the clauses and guidance provided in ISO/IEC 42001, organizations can establish a robust AIMS that ensures the responsible development, deployment, and management of AI systems across various industries. To achieve ISO/IEC 42001 certification, organizations must undergo a rigorous assessment process conducted by accredited certification bodies. This process involves a thorough evaluation of the organization’s AI management system, including its policies, procedures, and practices.

As AI continues to reshape industries and societies, the need for robust governance frameworks becomes increasingly paramount. ISO/IEC 42001 represents a significant step towards ensuring the responsible development and deployment of AI technologies, striking a balance between innovation and ethical considerations. By achieving certification, organizations can position themselves as leaders in the AI revolution, fostering trust, mitigating risks, and contributing to a more sustainable and equitable future for all. Successful certification not only validates an organization’s commitment to responsible AI governance but also provides a competitive advantage in an increasingly AI-driven marketplace. Consumers and stakeholders are becoming more discerning about the ethical and responsible use of AI, and ISO/IEC 42001 certification can serve as a powerful signal of an organization’s dedication to these principles.

Related Articles

  • Integrating SHE Requirements into ISO 9001:2015 and AS9100D Systems
  • Integrating Climate Change into ISO Standards
  • ISO Climate Change: The Ongoing Story
KEYWORDS: Artificial Intelligence (AI) IEC 42001 ISO 42001 ISO certification ISO standards manufacturing metrology

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Carol Dudley, chief commercial officer, National Standards Authority of Ireland. For more information, call (603) 882-4412, email [email protected] or visit www.nsaiinc.com. www.linkedin.com/company/national-standards-authority-of-ireland-inc/

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • 2024 Quality Rookie of the Year Justin Wise 1440x750px banner with "Quality Rookie of the Year" logo inset

    Meet the 2024 Quality Rookie of the Year: Justin Wise

    Justin Wise is an exceptional individual who has been...
    Aerospace
    By: Michelle Bangert
  • Man with umbrella and coat stands outside while it rains at night looking at a building.

    Nondestructive Testing: Is there an ethics problem?

    I was a whistleblower who exposed fraudulent activities...
    NDT
    By: Dale Norwood
  • Unraveling Deflategate: Football stadium with closeup of football on field

    Unraveling the Tom Brady Deflategate

    The Deflategate scandal erupted following the 2014 AFC...
    Measurement
    By: Greg Cenker and Henry Zumbrun
Manage My Account
  • eMagazine Subscriptions
  • Newsletters
  • Online Registration
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Quality audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Quality or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • This image shows a person seated next to a Bobcat T66 compact track loader.
    Sponsored byPolyWorks by InnovMetric

    Supercharging Digital Gauging at Bobcat North America

  • Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios
    Sponsored byDorsey Metrology International

    Ensuring Product Quality in a Competitive Manufacturing Landscape

  • This image displays a Eddyfi Technologies Cypher portable inspection instrument alongside a scanner for non-destructive testing (NDT).
    Sponsored byEddyfi Technologies

    A Safer, Smarter Approach to Weld Inspection: Why Advanced Ultrasonic Testing Is Redefining Industry Standards

Popular Stories

MicroRidge MobileCollect wireless measurement system

Before AI Can Help, the Data Has to Be Ready

a titanium diaphragm speaker driver

The One Thing Elon Gets Right Is Designed to Scare You

This image shows a person seated next to a Bobcat T66 compact track loader.

Supercharging Digital Gauging at Bobcat North America

2026 Quality Professional of the Year!

Events

June 9, 2026

Future-Proof your Quality Processes with Advanced 3D Optical CMM Technology

Discover how to effortlessly capture complex data, leverage true multi-sensor automation, and ensure continuous operation without creating inspection delays.

June 22, 2026

Automate 2026

Automate is North America's largest robotics and automation event — and the best place to take your ideas from insight to impact.
 
Our show floor features the world’s leading automation solutions, from AI and robotics to motion control, vision systems, and more. Plus, our educational conference is second to none, led by the brightest minds in automation today.
 
Ready to transform the way you work? Take the next step at Automate.
View All Submit An Event

Products

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

See More Products
Quality Podcast Channel Custom Content

Related Articles

  • Big data Network Abstract concept using a network of blue, green, and red lines connected to small glowing white dots.

    Are You Blazing a New Path to ISO/IEC 42001 AI Standard?

    See More
  • two industrial workers shaking hands

    Putting the Customer Front and Center: The Rise of Customer-Centric Quality

    See More
  • 3d schematic of a factory using Metrology solutions in the production line - illustration Industry 4.0.

    The Rise of Industry 4.0 and its Impact on Metrology

    See More

Related Products

See More Products
  • louis hannigan.jpg

    The Non-Idiot's Guide to ISO 9001:2015: Understanding and Using the Quality Management System Standard to your benefit

  • iso.jpg

    The ISO 45001:2018 Implementation Handbook

  • ZEuCDwAAQBAJ.jpg

    Lean Six Sigma In The Age Of Artificial Intelligence: Harnessing The Power Of The Fourth Industrial Revolution

See More Products

Events

View AllSubmit An Event
  • December 16, 2025

    Focus On CAPA: Enhancing Failure Investigation & Root Cause Analysis & Benefits of AI Powered QMS

    On Demand Gain valuable insights into how to apply failure investigation techniques to identify true root causes and develop effective corrective actions.
View AllSubmit An Event

Related Directories

  • isoTracker Solutions Ltd.

    Popular cloud-based QMS software with a global customer base. Ideal for small to medium-sized businesses, with no set-up cost and proactive support. Designed for easy compliance with ISO 9001, ISO 14001, ISO 17025, ISO 13485, ISO 45001, ISO 22000 and other QM standards. Pay only for the features you need and add to them as your business grows.
×

Stay in the know with Quality’s comprehensive coverage of
the manufacturing and metrology industries.

Newsletters | Website | eMagazine

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Manufacturing Division
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletters
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Market Research
    • Reprints
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing