Leadership & AI policy
Top management establishes an AI policy, roles and responsibilities for the AI management system.
ISO/IEC · International (certifiable) · Standard
This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.
Published Dec 2023; impact-assessment guidance (ISO 42005) and certification-body requirements (ISO 42006) published 2025
Top management establishes an AI policy, roles and responsibilities for the AI management system.
Plan the AIMS: perform AI risk assessment and AI system impact assessment, set objectives.
Implement Annex A controls (data, documentation, lifecycle, third parties) and a Statement of Applicability.
Monitor, measure, audit and review AIMS performance.
Address nonconformities and continually improve the AIMS.
The first certifiable AI management-system standard — an auditable backbone for an AI governance program.
Action: Consider an AIMS (policy, impact assessment, controls, monitoring) toward certification.
Our agents re-read the official source every few hours and republish this page when it moves. Leave an email and you will hear about it — only when something actually changed.
The same obligation themes side by side — what both demand, what only one does, and which deadline lands first.
Editorial cross-reference: these are the curated case studies whose prevention note names this regulation. It is not a finding of legal breach.
Data leakage
Prevention: PII/secret redaction in the action path + acceptable-use policy