ISO/IEC 42001:2023. AI GOVERNANCE THAT OPERATES.
ISO/IEC 42001 AI Management System Software
Control AI Use, Risk, Impact and Accountability Across the Organisation
Zebsoft ISO 42001 software helps organisations establish, operate, evaluate and continually improve an Artificial Intelligence Management System (AIMS). It connects AI systems, purposes, owners, risks, impacts, controls, suppliers, approvals, incidents and evidence through accountable workflows.
The platform controls how governance work moves. It does not decide whether an AI system is acceptable, invent evidence or replace competent human judgement.

CURRENT POSITION CHECKED: 26 AUGUST 2026
The AI Governance Position Has Moved On
A current AI governance programme must distinguish the management-system standard from impact-assessment guidance, certification rules and applicable law. These sources can reinforce one another, but they are not interchangeable.
ISO/IEC 42001 certification does not by itself demonstrate compliance with the EU AI Act. Legal applicability depends on the organisation’s role, AI system, use, market, geography and other facts.
A MANAGEMENT SYSTEM—NOT A PRODUCT CLAIM
What ISO/IEC 42001 Does and Does Not Mean
ISO/IEC 42001 uses a management-system approach. It asks the organisation to understand its context, lead and plan the AIMS, support and operate it, evaluate performance and improve. The standard is designed to be applicable to organisations that develop, provide or use AI systems.
THE OPERATING STRUCTURE
Run Clauses 4–10 as One Connected AIMS
ISO/IEC 42001 follows the familiar management-system structure. The clauses should work together around real AI systems and decisions rather than exist as isolated policy documents.
KNOW WHICH AI YOU GOVERN
Build a Usable AI System Inventory
An AIMS cannot govern an AI estate that nobody can describe. The inventory should cover internally developed systems, third-party services, embedded AI features, general-purpose models, automated decision support and approved employee uses.
Zebsoft relates the inventory to ownership, affected parties, suppliers, risks, assessments, obligations, controls, incidents, changes and evidence.

ASSESS EFFECTS BEFORE AND DURING USE
Connect ISO/IEC 42005 Impact Assessment to AI Risk Management
ISO/IEC 42005:2025 provides lifecycle guidance for assessing foreseeable impacts on individuals, groups and society. ISO/IEC 23894:2023 provides guidance on AI risk management. Zebsoft can connect both forms of analysis to the AIMS without pretending they are the same exercise.
The system preserves inputs, reasoning, evidence, consultation, assumptions and approvals. Competent people determine assessment conclusions and whether the remaining risk and impact are acceptable.
CONTROL THE COMPLETE AI LIFECYCLE
Govern the Decision Route From Proposal to Retirement
AI governance fails when approval is treated as the end of the process. Models, data, suppliers, usage and legal expectations change. The control route must continue while the system is in use.
GENERATIVE AI NEEDS OPERATING CONTROLS
Move Beyond a Generic AI Acceptable-Use Policy
A policy can state expectations, but it cannot prove how specific tools and uses are approved, monitored and changed. Generative AI requires controls around information, output, human review, disclosure and provider dependency.
EU AI ACT: CURRENT ENFORCEMENT TIMELINE
Do Not Use an Out-of-Date 2024 Implementation Timeline
The EU AI Act entered force on 1 August 2024 and applies progressively. As of 26 August 2026, enforcement powers and Article 50 transparency duties are active. The organisation must determine its own role and which provisions apply.
THIS IS HOW WE SOLVE THE PROBLEM
Put a Controlled Route Around Every Important AI Decision
Most organisations already have AI policies, risk templates, supplier questionnaires and project approvals. The weakness is that the controls are separated from the systems, people and changes they are meant to govern.
Humans remain responsible for the decisions, work, approvals and consequences. AI may assist analysis; it does not acquire organisational accountability.
CERTIFICATION READINESS
Operate the AIMS While Preserving Certification Independence
ISO/IEC 42006:2025 sets additional requirements for bodies that audit and certify AIMS. Zebsoft can help the organisation prepare and present controlled evidence, but certification remains an independent conformity-assessment decision.
Zebsoft does not certify organisations and cannot guarantee certification. It helps responsible people demonstrate how the AIMS is controlled, operated, evaluated and improved.
CONNECT GOVERNANCE WITHOUT COLLAPSING INTENT
Integrate AI Governance With Security, Privacy, Quality and Risk
An AIMS can share organisational processes with other management systems, but each standard and legal duty retains its own scope, criteria and evidence.
MOVE FROM POLICY PACKS TO OPERATING GOVERNANCE
Migrate Without Losing Ownership, Evidence or History
Zebsoft can replace or connect fragmented spreadsheets, SharePoint lists, policy folders, ticketing tools and supplier files. Migration should improve control, not merely copy old disorder into a new database.
The migration plan can be phased by AI risk, business unit or lifecycle state. Live high-impact systems and imminent regulatory duties should not wait behind low-value historical cleanup.
CONTROLLED EVIDENCE
Make AI Governance Verifiable From the Work Itself
A customer, auditor, regulator or governing body should be able to follow a reported position back to the system, assessment, control, evidence and authorised human decision.
| AI governance activity | Fragmented approach | Zebsoft controlled operation |
|---|---|---|
| AI system inventory | A spreadsheet with uncertain ownership and status | Each system has a purpose, owner, role, provider, lifecycle state, affected parties and linked obligations |
| Impact and risk assessment | A one-off document prepared before approval | Assessment conclusions, assumptions, controls, owners, evidence and review triggers remain connected |
| Deployment decision | Informal sign-off in email or a project meeting | Named competent people review defined criteria, record conditions and retain an authorised decision |
| Supplier or model change | Updates are discovered after behaviour or terms change | Change triggers reassessment, testing, approval, communication and monitoring |
| Assurance | Evidence is reconstructed for audit or customer review | Dashboards and reports trace to current records, exceptions, decisions and human accountability |
PRACTICAL QUESTIONS
ISO 42001 AI Management System Software FAQs
Use the licensed standards, current regulator information and competent professional advice when determining exact requirements.
What is ISO/IEC 42001:2023?
It is the current international requirements standard for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System.
Does Zebsoft certify an AIMS?
No. Zebsoft supports implementation, operation, evidence, audit and improvement. An independent competent certification body reaches the certification decision.
Is ISO/IEC 42005 part of ISO/IEC 42001?
It is a separate 2025 guidance standard for AI system impact assessment. It complements ISO/IEC 42001 and can strengthen the organisation’s impact-assessment method.
Does every AI system need the same controls?
No. The organisation determines proportionate controls from context, use, effects, risk, obligations and lifecycle stage. It must consider relevant Annex A control objectives and justify its approach.
Can we govern third-party and embedded AI?
Yes. The inventory and supplier processes can cover hosted tools, models, APIs and AI embedded in wider products, with controls reflecting the organisation’s actual role and influence.
Does ISO 42001 certification prove EU AI Act compliance?
No. Certification can support structured governance and evidence, but legal compliance depends on the applicable provisions and facts of each organisation and AI system.
Which EU AI Act dates matter now?
Article 50 transparency duties and enforcement powers began applying on 2 August 2026. Annex III high-risk rules apply from 2 December 2027 and regulated-product high-risk rules from 2 August 2028.
Can AI complete our governance records?
AI may help authorised users interrogate and analyse approved information. Humans remain responsible for assessments, controls, evidence, approvals, interpretations and decisions.
Can we integrate ISO 42001 with ISO 27001?
Yes. Common processes can be connected while the AIMS and ISMS retain their own scope, specialist requirements, risks, controls and audit conclusions.
Where can we verify the current position?
See the official ISO/IEC 42001 page, ISO/IEC 42005 page, ISO/IEC 42006 page, the European Commission AI Act enforcement timeline, the NIST AI RMF and current ICO AI guidance.
BRING ONE REAL AI USE CASE
See How Zebsoft Makes AI Governance Operable and Verifiable
Choose a real system—generative AI, decision support, automated inspection, customer interaction, workforce use or an embedded supplier feature. We will show how purpose, ownership, assessment, controls, approval, monitoring, change and evidence remain connected.

