Subject
Artificial intelligence (AI) is increasingly applied across all sectors utilizing information technology and is expected to be one of the main economic drivers. A consequence of this trend is that certain applications can give rise to societal challenges over the coming years.
This document intends to help organizations responsibly perform their role with respect to AI systems (e.g. to use, develop, monitor or provide products or services that utilize AI). AI potentially raises specific considerations such as:
- The use of AI for automatic decision-making, sometimes in a non-transparent and non-explainable way, can require specific management beyond the management of classical IT systems.
- The use of data analysis, insight and machine learning, rather than human-coded logic to design systems, both increases the application opportunities for AI systems and changes the way that such systems are developed, justified and deployed.
- AI systems that perform continuous learning change their behaviour during use. They require special consideration to ensure their responsible use continues with changing behaviour.
Applied standards
ISO/IEC 42001 provides requirements for establishing, implementing, maintaining and continually improving an AI management system within the context of an organization. Organizations are expected to focus their application of requirements on features that are unique to AI. Certain features of AI, such as the ability to continuously learn and improve or a lack of transparency or explainability, can warrant different safeguards if they raise additional concerns compared to how the task would traditionally be performed. The adoption of an AI management system to extend the existing management structures is a strategic decision for an organization.
The organization’s needs and objectives, processes, size and structure as well as the expectations of various interested parties influence the establishment and implementation of the AI management system. Another set of factors that influence the establishment and implementation of the AI management system are the many use cases for AI and the need to strike the appropriate balance between governance mechanisms and innovation. Organizations can elect to apply these requirements using a risk-based approach to ensure that the appropriate level of control is applied for the particular AI use cases, services or products within the organization’s scope. All these influencing factors are expected to change and be reviewed from time to time.
The AI management system should be integrated with the organization’s processes and overall management structure. Specific issues related to AI should be considered in the design of processes, information systems and controls. Crucial examples of such management processes are:
- determination of organizational objectives, involvement of interested parties and organizational policy;
- management of risks and opportunities;
- processes for the management of concerns related to the trustworthiness of AI systems such as security, safety, fairness, transparency, data quality and quality of AI systems throughout their life cycle;
- processes for the management of suppliers, partners and third parties that provide or develop AI systems for the organization.
This document provides guidelines for the deployment of applicable controls to support such processes.
This document avoids specific guidance on management processes. The organization can combine generally accepted frameworks, other International Standards and its own experience to implement crucial processes such as risk management, life cycle management and data quality management which are appropriate for the specific AI use cases, products or services within the scope.
An organization conforming with the requirements in this document can generate evidence of its responsibility and accountability regarding its role with respect to AI systems.
The order in which requirements are presented in this document does not reflect their importance or imply the order in which they are implemented. The list items are enumerated for reference purposes only.
ISO/IEC 42001 applies the harmonized structure (identical clause numbers, clause titles, text and common terms and core definitions) developed to enhance alignment among management system standards (MSS). The AI management system provides requirements specific to managing the issues and risks arising from using AI in an organization. This common approach facilitates implementation and consistency with other management system standards, e.g. related to quality, safety, security and privacy.
Our services
The SSA is planning to provides high quality services of Certification of managements systems of organisation towards Artificial Intelligence based on ISO/IEC 42001. The service will include a complex of onsite and off-site assessment of management system of use of Artificial Intelligence by an organisation.
Links
- ISO/IEC 42001:2023 - Information technology — Artificial intelligence — Management system
- ISO/IEC 22989:2022 - Information technology — Artificial intelligence — Artificial intelligence concepts and terminology
- ISO/IEC TR 24368:2022 - Information technology. Artificial intelligence. Overview of ethical and societal concerns
- ISO/IEC 23894:2023 - Information technology — Artificial intelligence — Guidance on risk management
- ISO/IEC TS 8200:2024 - Information technology — Artificial intelligence — Controllability of automated artificial intelligence systems
- ISO/IEC 5338:2023 - Information technology — Artificial intelligence — AI system life cycle processes
- ISO/IEC 5339:2024 - Information technology — Artificial intelligence — Guidance for AI applications
- ISO/IEC 5392:2024 - Information technology — Artificial intelligence — Reference architecture of knowledge engineering
- ISO/IEC 8183:2023 - Information technology. Artificial intelligence. Data life cycle framework
- ISO/IEC 24668:2022 - Information technology. Artificial intelligence. Process management framework for big data analytics
- ISO/IEC 38507:2022 - Information technology. Governance of IT. Governance implications of the use of artificial intelligence by organizations
- ISO/IEC 23053:2022 - Framework for Artificial Intelligence (AI) Systems Using Machine Learning (ML)
- ISO/IEC 5259-1:2024 - Artificial intelligence — Data quality for analytics and machine learning (ML) — Part 1: Overview, terminology, and examples