{"id":20032,"date":"2026-02-23T08:00:04","date_gmt":"2026-02-23T08:00:04","guid":{"rendered":"https:\/\/letslaw.es\/?p=20032"},"modified":"2026-02-13T12:14:41","modified_gmt":"2026-02-13T12:14:41","slug":"iso-42001-artificial-intelligence","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/iso-42001-artificial-intelligence\/","title":{"rendered":"ISO 42001:2023 on artificial intelligence: what it is and what it is for"},"content":{"rendered":"<p>Artificial intelligence (AI) has become a key element in the digital transformation of companies, but it is also a source of legal, ethical and reputational risks.<\/p>\n<p>In this context, it is no longer enough for a model to work \u201cwell\u201d from a purely technical perspective. Authorities, clients and business partners want to know who controls these systems, what safeguards are in place and how risks are managed. To address these questions, the <strong>ISO\/IEC 42001:2023<\/strong> standard has been published, the first international standard specifically focused on artificial intelligence management systems. Its purpose is to provide a governance framework that enables organisations to design, deploy and use AI in a responsible way, aligned with applicable regulation and with market expectations regarding trust.<\/p>\n<h2>What does ISO 42001:2023 regulate?<\/h2>\n<p>ISO 42001 is not a technical manual on algorithms, but a management <strong>system standard<\/strong>. It regulates how the company organises itself around its AI systems: which policies it approves, which processes it follows, who takes decisions and which controls are applied.<\/p>\n<p>Like other standards such as ISO 9001 or ISO\/IEC 27001, it follows the high-level structure used for management systems. In practice, it requires the organisation to:<\/p>\n<ul>\n<li>Define the context and scope of the AI management system.<\/li>\n<li>Establish a responsible AI policy, approved by top management.<\/li>\n<li>Identify risks and opportunities and plan objectives and measures.<\/li>\n<li>Ensure resources, competences and documentation management.<\/li>\n<li>Manage the life cycle of AI systems: design, acquisition, testing, deployment and monitoring.<\/li>\n<li>Assess system performance using indicators and internal audits.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>What makes ISO 42001 distinctive is that it applies this logic to <strong>AI-specific risks<\/strong>: bias and potentially discriminatory decisions, lack of explainability, impact on fundamental rights, exposure of personal data and cyber security risks. In short, it regulates how AI is governed within the organisation, leaving room for technological freedom but requiring order, traceability and control.<\/p>\n<h2>Objectives of the AI management system<\/h2>\n<p>The AI management system (<strong>AIMS<\/strong>) is the set of policies, processes, roles and controls that the organisation implements to keep AI under control.<\/p>\n<h3>1. Good governance and accountability<\/h3>\n<p>The first objective is to ensure<strong> good governance<\/strong>. ISO 42001 seeks to prevent AI from being used in an improvised or fragmented way. The standard requires the organisation to define who does what: which body approves the AI policy and strategy, who is responsible for each system or use case, and how the areas involved coordinate with each other.<\/p>\n<p>This means that, in the event of an incident, there is<strong> traceability of decisions<\/strong> and the company can demonstrate that it has acted diligently, which is particularly relevant in dealings with supervisory authorities, clients and business partners.<\/p>\n<h3>2. Risk management and regulatory compliance<\/h3>\n<p>The second pillar is to establish <strong>AI-specific risk<\/strong> management and to facilitate regulatory compliance. For each system, the organisation must identify:<\/p>\n<ol>\n<li>Potential impacts on individuals and on the business.<\/li>\n<li>Legal risks (data protection, consumer law, equality and non-discrimination, liability, etc.).<\/li>\n<li>Appropriate controls: review of data and models, testing prior to deployment, limits on automation, human oversight and security measures.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>In addition, the AI management system must be integrated with compliance with the <strong>GDPR, Spanish data protection law (LOPDGDD), e-commerce and information society services law (LSSI), the AI Act and sector-specific regulation<\/strong>, generating documented evidence that can be presented to authorities, clients or partners (records, assessments, reports, minutes, etc.).<\/p>\n<h3>3. Trust and transparency<\/h3>\n<p>The third objective is to strengthen trust and transparency. A system aligned with ISO 42001 makes it easier to explain:<\/p>\n<ul>\n<li>When AI is used in products, services or internal processes.<\/li>\n<li>Which decisions are automated and which remain subject to human oversight.<\/li>\n<li>Which limits have been established and how incidents are handled.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>This improves how clients, users, investors and regulators perceive the organisation and strengthens its reputation compared to competitors that use AI without clear controls.<\/p>\n<h2>How to obtain certification for your company<\/h2>\n<p>ISO\/IEC 42001 is a <strong>certifiable standard<\/strong>. An independent certification body can audit the organisation\u2019s AI management system and, if it meets the requirements, issue a certificate with a defined scope.<\/p>\n<h3>1. Scope and initial diagnosis<\/h3>\n<p>The first phase consists of defining the scope and carrying out an initial diagnosis. Top management decides which areas and AI systems will be included in the management system and, where applicable, in the certificate. A gap analysis is then performed to:<\/p>\n<ol>\n<li>Identify the inventory of AI systems and use cases.<\/li>\n<li>Review existing policies and procedures.<\/li>\n<li>Assess the current degree of alignment with the standard.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>This provides a realistic roadmap towards compliance.<\/p>\n<h3>2. Design and implementation of the system<\/h3>\n<p>The second phase is to design and implement the AI management system. Based on the diagnosis, specific policies and procedures are drafted or adapted, objectives and indicators are defined, and roles and resources are assigned.<\/p>\n<p>In parallel,<strong> the system is rolled out in practice<\/strong>: training teams, putting processes into operation, generating evidence through records and reports, and monitoring AI systems.<\/p>\n<h3>3. Audits and certification<\/h3>\n<p>The third phase consists of <strong>conducting audits and obtaining certification<\/strong>. Once the system is up and running, the organisation carries out internal audits to verify its effectiveness and identify improvements.<\/p>\n<p>It can then request a certification audit from an accredited body, usually in two stages: a documentation review and an on-site verification. If the outcome is positive, the ISO\/IEC 42001 certificate is issued with the agreed scope and periodic <strong>surveillance audits<\/strong> are scheduled to ensure that the system is maintained and continues to improve over time.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/20032#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>ISO\/IEC 42001:2023 is the first international standard specifically for AI management systems, promoting its responsible use.<\/p>\n","protected":false},"author":2,"featured_media":20034,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-20032","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20032","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=20032"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20032\/revisions"}],"predecessor-version":[{"id":20039,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20032\/revisions\/20039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/20034"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=20032"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=20032"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=20032"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}