AI changes the evidence pattern, not the need for control.
ISO/IEC 42001Management-system scope
Define which AI activities, teams, products, and suppliers are inside the AIMS.
Risk and impact
AI risks and impacts need owners, controls, and review cycles.
Supplier AI
External models and platforms need due diligence and monitoring.
Continual improvement
Incidents, findings, and changes feed management review and action closure.
AI governance must connect to existing regulated systems.
not isolatedAI management-system scope
Connect this evidence to QMS, clinical, software, supplier, data, or lifecycle governance where applicable.
AI policy
Connect this evidence to QMS, clinical, software, supplier, data, or lifecycle governance where applicable.
AI objectives
Connect this evidence to QMS, clinical, software, supplier, data, or lifecycle governance where applicable.
Role and responsibility matrix
Connect this evidence to QMS, clinical, software, supplier, data, or lifecycle governance where applicable.
AI risk register
Connect this evidence to QMS, clinical, software, supplier, data, or lifecycle governance where applicable.
AI system inventory
Connect this evidence to QMS, clinical, software, supplier, data, or lifecycle governance where applicable.
Current public sources for ISO/IEC 42001.
official firstThese links are the public source anchors for this workspace. Interpretation, checklists, and future assets should point back here before being reused outside iFeed.
ISO/IEC 42001 standard page
2023 · Source-owner page for ISO/IEC 42001. Public pages must not reproduce protected standard text.
ISO explainer: ISO/IEC 42001
Current · Public ISO explanation of AI management system purpose and scope.
IEC ISO/IEC 42001 webstore page
2023 · IEC source-owner page for the same international standard.