Techné AI · Free reference · Edition 3.0.0
International Standards (ISO/IEC)
The different roles of ISO/IEC 42001, 23894, 22989, 42005 and 42006 in AI management, risk, impact assessment and certification.
On this page
ISO/IEC standards serve different purposes: management-system requirements, risk and impact guidance, terminology, and requirements for certification bodies. These roles are complementary, not interchangeable. Two additions in 2025 were ISO/IEC 42005, published in May, and ISO/IEC 42006, published in July.12
This overview uses ISO’s public descriptions and publication records. It does not reproduce or claim clause-by-clause verification of the licensed standards. Obtain the applicable edition for implementation, and separately determine legal and contractual requirements.
ISO/IEC 42001:2023 — AI management systems
Published in December 2023, ISO/IEC 42001 specifies requirements for establishing, operating and improving an AI management system (AIMS). It is relevant to organisations developing, providing or using AI across sectors and sizes.3
The management system brings policies, responsibilities, processes and improvement activity into a defined organisational scope. A third party can assess conformity to the standard, but the certificate concerns that management-system scope. It should not be presented as proof that every model output is accurate, every AI product is safe, or every regulatory duty has been met.
For procurement, examine the certificate’s legal entity, activities, systems, sites, validity and issuing body. A certificate covering one team or service does not establish coverage of a supplier’s entire portfolio. Ask for supporting evidence relevant to the actual service you are buying.
ISO/IEC 23894:2023 — AI risk management
ISO/IEC 23894, published in February 2023, provides guidance on AI-related risk management and its integration into organisational activities. It is a guidance standard, distinct from the certifiable management-system requirements of 42001.4
An implementation can use 23894 to structure risk identification, analysis, treatment and review inside an AIMS. The practical task is to record context, affected people, uncertainty, controls and decision owners—not merely to list the standard in a policy.
ISO/IEC 22989:2022 — AI concepts and terminology
ISO/IEC 22989, published in July 2022, establishes AI terminology and concepts to support communication among different stakeholders.5 Use a controlled glossary in contracts, inventories and incident records, while recognising that a statute may define the same term differently.
The handbook’s Glossary is explanatory material, not a reproduction of this standard or a claim that every definition has been checked against it.
ISO/IEC 42005:2025 — AI system impact assessment
ISO/IEC 42005, published in May 2025, guides assessment of an AI system’s foreseeable effects on individuals, groups and society throughout its lifecycle. It complements management-system and risk-management work.1
An organisation may use this guidance to organise an impact-assessment method. It is not a mandatory implementation recipe for every 42001-conforming organisation. Nor does using it automatically satisfy an EU AI Act Article 27 fundamental-rights assessment or a privacy impact assessment: scope, responsible party, required content, consultation and submission obligations need their own legal mapping. See EU AI Act.
ISO/IEC 42006:2025 — AIMS certification bodies
ISO/IEC 42006, published in July 2025, adds AI-specific requirements for bodies auditing and certifying an AIMS against 42001. It supplements ISO/IEC 17021-1; it is not the organisation’s AIMS certification standard.2
The standard supports consistent, competent assessment. Certificates from different providers still need to be evaluated for their particular scope, validity and issuing body’s status; publication of a standard does not establish those facts for an individual certificate.
Certification and accreditation are different. An external certification body issues a certificate; an accreditation body recognises a certification body’s competence for a defined scope. ISO itself neither certifies organisations nor issues their certificates. Check the certification body’s relevant accreditation and the certificate’s current status rather than describing an organisation as “42006-accredited.”6
Other relevant ISO/IEC references
| Reference | Role |
|---|---|
| ISO/IEC 38507:2022 | Guidance for governing bodies on the organisational implications of AI use |
| ISO/IEC 5338:2023 | AI system lifecycle processes |
| ISO/IEC TR 24028:2020 | Overview of AI trustworthiness; not a specification of required trustworthiness levels |
| ISO/IEC TR 24368:2022 | Overview of ethical and societal concerns |
A practical implementation sequence
The following is a suggested workflow, not a requirement to adopt every standard:
- Define the organisational scope, AI uses, applicable laws and contractual promises.
- Establish shared terminology, retaining any distinct legal definitions.
- Build governance responsibilities and management processes; use 42001 where an AIMS is appropriate.
- Select risk and impact methods suited to the context, drawing on 23894 and 42005 as useful.
- Test whether controls operate in practice and retain evidence of decisions, monitoring and corrective action.
- If certification serves a real customer or organisational need, agree the assessment scope and verify the external body’s competence and accreditation.
Existing quality or information-security processes may be reusable, but an ISO 9001 or ISO/IEC 27001 certificate does not establish AI management-system conformity. Likewise, a management-system certificate is not a substitute for legal analysis, product testing or ongoing oversight.
Footnotes
This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.