An AI management system (AIMS) is the set of policies, procedures, roles, risk assessments and records an organization keeps so that it knows what artificial intelligence it is using, who is responsible for it, what could go wrong, and what it checks before it trusts the output. It is a management system in the same sense that your quality management system is one. ISO/IEC 42001:2023 is the international standard that defines what an AI management system must contain, and it is written on the same clause structure as ISO 9001, ISO 13485 and ISO 27001. If you already run one of those, or a GMP quality system under 21 CFR 210/211 or Part 820, you will recognize most of an AIMS on sight, and you will probably not need a second system to hold it.
This article is written for the quality or operations manager who already owns a QMS and is being asked what the company is doing about AI.
What an AI management system is
ISO uses the phrase "management system" in a specific way. It means the organized set of things a company does to reach an objective and to prove it did: a policy that says what leadership wants, defined responsibilities, a way of identifying risks, procedures for the work, records showing the procedures were followed, and audits and reviews that catch drift and correct it. Your QMS does that for product quality. An AIMS does it for the way the organization develops, buys, deploys and uses AI.
The word "uses" matters. Most companies that need an AIMS are not building models. They are using a chatbot to draft procedures, a vendor feature that flags deviations, or a machine-vision system on a line. ISO 42001 covers organizations that provide AI systems, that develop them, and that simply use them, and the controls scale with the role you play. A 40-person supplement manufacturer whose only AI is a general-purpose assistant still has an AI system in scope, and its AIMS will be small.
An AIMS answers a short list of questions that an auditor, an FDA investigator or a customer's procurement team will eventually ask:
- What AI systems are in use here, including the ones embedded in vendor tools?
- Who owns each one, and who has the authority to stop it?
- What could each one do to product quality, to a patient, to an employee or a customer, and how likely is that?
- What controls are in place before an AI output is relied on, especially for regulated records?
- What evidence shows those controls actually operate?
If you can answer those five questions with documents and records instead of from memory, you have most of an AIMS already, whatever you call it.
What an AI management system is not
The market has attached the phrase to several things it does not mean, and the confusion costs real money.
It is not a software product. Several vendors now sell "AI governance platforms" that inventory models, log prompts and track approvals. Those can help you run an AIMS, in the same way an eQMS helps you run a QMS. But buying one gives you a tool, and the system is the policy, the responsibilities, the assessments and the records the tool holds. A certification auditor will not accept a licence key as evidence of clause 6.
It is not an ethics statement. A "responsible AI principles" page on the website is, at most, a policy under clause 5.2. An AIMS has to show what you did: which systems were assessed, who reviewed the assessment, what was decided, and what was checked afterward. In my experience the companies that feel most exposed are the ones with a polished principles page and no record behind it.
It is not a one-time validation of a model. Validating one model against acceptance criteria is one control at one stage of one system's life cycle. It does not tell you what other AI is in use, what happens when the vendor updates the model, or whether the people relying on the output know its limits.
It is not a legal compliance certificate. ISO 42001 is voluntary. Certification does not satisfy the EU AI Act (more on that below) and no US law requires it. It is the recognized way to show that AI use is under control, which is a more useful thing than a shield.
What an AI management system contains
ISO/IEC 42001:2023 follows the Annex SL structure, so clauses 4 through 10 carry the same headings you know from ISO 9001. The AI-specific content lives in clause 6 (the AI risk and impact assessments) and in Annex A, which lists the AI controls in nine control areas. The table shows what each clause asks for and how much of it a mature QMS already covers.
| Clause | What ISO 42001 asks for | What a working QMS already has | What is new for AI |
|---|---|---|---|
| 4 Context | Scope; interested parties; your role (provider, developer, user) | Context analysis, scope statement | An inventory of AI systems, including AI features inside vendor tools |
| 5 Leadership | AI policy; roles; management commitment | Quality policy, org chart | An AI policy; a named owner per AI system with authority to suspend it |
| 6 Planning | AI risk assessment; AI system impact assessment; objectives; Statement of Applicability | Risk register, quality objectives | Impact assessment on people; SoA selecting Annex A controls |
| 7 Support | Competence, awareness, documented information | Training records, document control | AI competence for owners and reviewers; awareness for everyone using AI output |
| 8 Operation | AI risk treatment; life cycle controls; third-party AI | Procedures, change control, supplier controls | Life cycle stages per AI system; data management; supplier questions about AI; change control on model updates |
| 9 Performance evaluation | Monitoring, internal audit, management review | Internal audit program, management review | AI metrics and incidents as audit scope and review inputs |
| 10 Improvement | Nonconformity, corrective action, improvement | CAPA | AI incidents routed through the same CAPA process |
Annex A's nine areas are policies related to AI, internal organization, resources for AI systems, assessing the impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. You select the controls that apply in a Statement of Applicability and justify the ones you exclude, as ISO 27001 does with its own Annex A. We walk through that selection in which Annex A controls apply, and the full detail is in the clause-by-clause breakdown.
Two items in that table are new to most quality managers. The AI system impact assessment is different from the risk assessment: the risk assessment asks what could go wrong for the organization, and the impact assessment asks what the AI system could do to people, meaning the operator who relies on it, the patient or consumer downstream, and the applicant it screens. For a manufacturer using AI to draft a specification it is short; for a company using AI to make decisions about people it is the document a regulator asks for first. The AI inventory sounds trivial and rarely is. The first list a client gives us is short; the complete one, after asking IT, HR, marketing and the lab, is usually several times longer.
How an AI management system relates to ISO 42001
The AIMS is the thing you build and run. ISO/IEC 42001:2023, published in December 2023, is the standard that says what it must contain and the one a certification body audits against. The relationship is the same as between your QMS and ISO 9001: you can have the system without the certificate.
Certification is still rare. Fewer than 100 organizations held a 42001 certificate in January 2026, and roughly 350 did by spring 2026; there is no official register, so those figures come from announcements. Certification bodies are reporting auditor backlogs, and some Stage 2 audits have waited six months or more. If a customer contract will require the certificate, that lead time belongs in your plan now.
It helps to know where 42001 sits among the other names you will hear. The NIST AI Risk Management Framework is voluntary guidance, and nobody certifies against it. AIUC-1 is a newer assurance standard for AI agents with published crosswalks to 42001, a complement that applies when you deploy agents. On the legal side, EN ISO/IEC 42001:2026 was adopted as a European standard on 18 March 2026, but no harmonised standard for the EU AI Act has been cited in the Official Journal, so a 42001 certificate does not give a presumption of conformity with the Act; the standard being written for that job is prEN 18286, targeted for late 2026, and under the 2026 revisions the Act's high-risk obligations now land in December 2027 and August 2028. In the US, Texas's TRAIGA took effect on 1 January 2026 and Colorado's narrower replacement law (SB 26-189) takes effect 1 January 2027, so state law is moving and far from settled. The longer comparison is in ISO 42001 vs NIST AI RMF vs the EU AI Act.
How it fits into a quality system you already run
Here is the choice that decides most of the cost. You can stand up the AIMS as a second management system, with its own manual, risk register, audit schedule and management review, or you can extend the QMS you already run so that AI becomes one more thing it controls. Annex SL exists so that the second option works, and in our experience it is the only one that survives past the first certification cycle, because two systems means two sets of records for the same people to maintain, and the AI one gets neglected.
Extending the existing system looks like this in practice:
- One quality manual with an AI section, and one scope statement that names the AI systems alongside the products and processes.
- AI risks in the existing risk register, with the impact assessment as a separate record where people are affected.
- AI vendors on the approved supplier list, with a few AI questions added to the questionnaire: what model, what data, how updates are communicated, what happens to our data.
- Model updates and new AI tools through existing change control, so a new model version gets assessed like any other change.
- AI-generated documents through existing document control, with the review step requiring a qualified person to check the content and not just the format.
The details differ by system. For an ISO 9001 company the additions are mostly clause 6 and Annex A, and the rest is a few paragraphs in existing procedures; we lay that out in what ISO 42001 adds to an ISO 9001 system. For an ISO 13485 device manufacturer, the impact assessment sits beside the ISO 14971 risk management file, and AI used inside the QMS runs into the software validation requirement in clause 4.1.6.
For a GMP manufacturer the fit is tighter than most people expect, because FDA has now said out loud what it will cite. In April 2026 FDA issued a warning letter to Purolea citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c): specifications, procedures and master production records written by AI and released without qualified review. That was the first time AI-generated quality records drew an FDA citation. A chatbot drafting a procedure does not change who is accountable for its content. An AIMS folded into a GMP system gives the quality unit the inventory, the review step and the record to show an investigator which documents AI touched and who checked them. We cover that in ISO 42001 for GMP manufacturers, and for firms that want the records checked before an inspection does it, our AI-in-the-quality-system review is a fixed $5,000 review of the AI-generated records already in the system.
An ISO auditor or an FDA investigator will assume you are using AI. What they will ask is whether you can show who is responsible for it and what they checked.
What it takes to build one
The order matters, because each step feeds the next.
- Inventory the AI in use, including vendor features and the personal subscriptions people use for work.
- Decide the scope. A small scope you can support is worth more than a broad one you cannot.
- Run a gap assessment against ISO 42001, with the existing QMS documents open beside the standard, so every gap is marked "new" or "extend existing".
- Write the AI policy and name the owners. One page for the policy, one named person per AI system.
- Do the risk and impact assessments, reusing the QMS risk method.
- Prepare the Statement of Applicability, selecting Annex A controls and justifying exclusions.
- Fold the controls into existing procedures: supplier, change control, document control, training, CAPA.
- Train the people who use AI output, and the smaller group who own systems and review records.
- Run it long enough to generate records. Two or three months is usually the minimum before an audit has anything to see.
- Internal audit and management review, then Stage 1 and Stage 2 with a certification body if you are certifying.
The timeline from gap assessment to certificate is typically four to twelve months, and organizations with a working ISO 9001 or ISO 27001 system are usually at the short end because steps 4 through 8 are mostly extensions of what exists.
On cost, the 2026 market looks roughly like this: a two-day gap assessment for a small organization using one or two AI tools runs about $1,500 to $2,500; a scoped readiness review for a larger organization $5,000 to $20,000; and total first-year cost for a 50-to-200-person company, including internal time, tooling and the certification body, is commonly quoted at $85,000 to $150,000. Treat those as ranges. Our own ISO 42001 gap assessment is a fixed fee of $9,750 and produces the marked-up clause map from step 3. The full budget breakdown is in the implementation cost guide.
Do you need one?
An honest answer depends on what the AI is touching. If AI is drafting or reviewing regulated records, inspecting product, informing decisions about employees, patients or customers, or sitting inside a product you sell, then yes, you need an AIMS, and you need it in the QMS rather than beside it. If your entire AI use is a few people drafting emails with a general assistant, you still need a policy, an inventory entry and a rule about what may not be pasted into it, but the whole system can be a few pages. Nothing in US or EU law today requires ISO 42001 certification, and we will not tell you otherwise. What the standard gives a quality manager is a way to bring AI under the same discipline everything else in the plant already runs under, so that the next time someone asks what the company is doing about AI, the answer is a document you can hand over.
If you are not sure which side of that line you are on, the ISO 42001 consulting page explains how we scope the work, and who needs ISO 42001 goes through the question sector by sector.
Frequently Asked Questions
Is an AI management system a software product?
No. An AI management system is a documented set of policies, procedures, roles, risk assessments and records, in the same sense that a quality management system is. Software can help you keep the inventory and the records, but buying a tool does not give you the system.
Do I need a separate AI management system if I already have ISO 9001 or ISO 13485?
Usually not. ISO 42001 uses the same clause structure as ISO 9001 and ISO 13485, so most organizations extend the system they already run by adding an AI policy, AI risk and impact assessments, and the Annex A controls that apply, then folding the rest into existing document control, internal audit and management review.
Is an AI management system the same thing as ISO 42001?
Not quite. The AI management system is the thing you build and operate. ISO/IEC 42001:2023 is the standard that says what it must contain and the one a certification body audits against. You can run an AI management system without ever certifying it.
How long does it take to build an AI management system?
Typically four to twelve months from gap assessment to certificate. Organizations with a working ISO 9001 or ISO 27001 system are usually at the short end, because most of the clauses already exist and only the AI-specific parts are new.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.