01Introduction
Customers and regulators are starting to ask how companies govern the AI they build and buy. ISO 42001 is the first certifiable standard designed to answer that question.
02What is ISO 42001?
ISO/IEC 42001:2023 specifies requirements for an AI management system (AIMS): the policies, roles, risk assessments and controls an organization uses to develop, provide or use AI systems responsibly. It follows the same management system structure as ISO 27001, so the two are often certified together.
Its Annex A controls cover AI policy, impact assessment, data quality, system lifecycle, third-party relationships and transparency. Certification is increasingly used as evidence toward the EU AI Act.
03How ISO 42001 works
Implementation follows the familiar plan-do-check-act cycle.
- 1.
Context and scope
Identify AI systems in use or development and the organization's role for each.
- 2.
Risk and impact assessment
Assess risks to individuals, society and the business, including security risks such as prompt injection.
- 3.
Controls
Apply Annex A controls across data, models, lifecycle and suppliers.
- 4.
Audit and improve
Run internal audits and management reviews, then certify with an accredited body.
04Threats and risks
AI introduces risks that traditional frameworks don't fully cover.
Model and prompt attacks
Prompt injection, data poisoning and model extraction.
Shadow AI
Teams adopting AI tools outside governance, covered by AI-SPM.
Data leakage
Sensitive data exposed through training sets or model outputs.
Opaque suppliers
Third-party models with little transparency into how they behave.
05How Parameter helps
Parameter tests the security of AI features, which supports the technical side of an AIMS.
LLM app testing
The pentesting agents probe AI features for prompt injection, data leakage and excessive agency.
AI in the pipeline
Sentinel reviews AI-generated code before it merges.
AI infrastructure
Cloud Security maps AI services and the data they can reach.

