TwinEthosRequest access

Standard or framework

ISO/IEC 42001:2023 (AIMS)

ISO / IEC (JTC 1/SC 42) · International (INTL) · 2 provisions encoded · verified against the official source as of 2026-09-06.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.iso.org.

Standard / soft law

AI systems should undergo a documented AI system impact assessment (ISO/IEC 42001)

ISO/IEC 42001:2023, Clause 6 + Annex A (AI system impact assessment) · official text · Certifiable standard (not binding law)

In our own words: ISO/IEC 42001:2023 distinctively requires an AI system impact assessment — assessing potential consequences of an AI system for individuals, groups of individuals, and society — carried out and maintained within the AI management system (Clause 6 planning + the Annex A impact-assessment control area), rather than only an organizational risk assessment. Detect an AI deployment with no documented impact assessment covering individual, group, and societal effects. [TIER C: own-words summary of PUBLIC scope; licensed normative text not stored.]

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: automated decision, high risk
  • Organizations operating an AIMS under ISO/IEC 42001. The AI system impact assessment is a distinguishing requirement vs. generic management-system standards. Voluntary but certifiable.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.

A per-system impact assessment, distinct from the organizational risk register, that looks outward: intended use and context, who is affected (individuals, groups including vulnerable ones, society), foreseeable benefits and harms (rights, safety, fairness, access, wider societal effects), reasonably foreseeable misuse, mitigations, residual impact, and sign-off. The AI system owner maintains it within the AI management system and revisits it before release and on any material change of model, data, or use. Keep it next to the model card and have a release check confirm a current assessment exists for each deployed system.

Where it goes: 12 repository artifacts, 11 CI/CD pipeline.

Example (Impact assessment record (docs/impact/)), before:

# Resume screener
Risk: low. Approved.

After:

# AI system impact assessment: resume screener (v3, 2026-09-01)
- Intended use: rank applications for recruiter review; no automatic rejection
- Affected: applicants; groups at risk: career-gap, non-native-language applicants
- Harms: unfair exclusion, opaque ranking; societal: narrowing of hiring pools
- Mitigations: subgroup ranking audit each release; recruiter sees all applicants
- Residual impact: medium, accepted by Head of Talent (signed 2026-09-03)
- Revisit: on model, feature, or use change

Control: AI system deployed without an AI system impact assessment. The same guard addresses 1 item. Engineering guidance, not legal advice.

Rule id iso-42001.ai-system-impact-assessment · review status: tier c citation only

Standard / soft law

Organizations developing, providing, or using AI should operate a certifiable AI management system (ISO/IEC 42001)

ISO/IEC 42001:2023, Clauses 4-10 (AIMS requirements) · official text · Certifiable standard (not binding law)

ISO/IEC 42001:2023 is the first certifiable international AI management system (AIMS) standard. In our own words: its auditable requirements (Clauses 4-10, Annex-SL harmonized structure) call for establishing context and AIMS scope, top-management commitment via an AI policy with assigned roles and authorities, AI-specific risk assessment and objectives, resources/competence/documented information, lifecycle operation controls, performance evaluation via internal audit and management review, and continual improvement. Annex A supplies a reference control set (38 controls across nine areas incl. AI policy, impact assessment, lifecycle, data governance). Applies across the AI value chain — developers, providers, and users. Detect an organization developing/providing/using AI with no documented AI management system artifacts. [TIER C: own-words summary of the standard's PUBLIC scope; licensed normative text not stored — purchase from ISO to read it.]

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: automated decision
  • Any organization of any size that develops, provides, or uses products/services using AI systems. Voluntary but CERTIFIABLE by accredited bodies (3-yr cycle + annual surveillance). Referenced as an assurance/conformity route by AI laws and EU AI Act conformity discussion; integrates with ISO/IEC 27001.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Maintain a documented AI management system: an approved AI policy, named roles, an AI risk process, lifecycle controls, and internal audit and review records.

An organizational artifact set owned by an accountable executive: an AI policy approved by top management; the scope of the management system and an inventory of AI systems; roles and authorities (who approves releases, who owns each system's risk); an AI risk assessment and treatment process with a register; lifecycle controls for data, development, validation, deployment, monitoring, and retirement; internal audit and management-review records; and tracked improvement actions. It is reviewed on a planned cycle and when AI systems are added or materially changed. In the repository, keep the AI-system inventory with links to those records and a CI check that every listed system has an owner and a risk-register entry.

Where it goes: 12 repository artifacts, 11 CI/CD pipeline.

Example (AI system inventory (repo record)), before:

# ai-systems.yaml
- name: support-chatbot
  model: gpt-4o

After:

# ai-systems.yaml, reviewed at each management review
policy: docs/aims/ai-policy.md            # approved by CEO, 2026-03-01
statement_of_applicability: docs/aims/soa.md
systems:
  - name: support-chatbot
    model: gpt-4o
    owner: head-of-support
    risk_register: docs/aims/risk-register.md#support-chatbot
    lifecycle_stage: production
    last_internal_audit: 2026-06-12

Control: Organization using AI without a documented AI management system. The same guard addresses 1 item. Engineering guidance, not legal advice.

Rule id iso-42001.aims-management-system · review status: tier c citation only