verified_user
Standardful
首頁chevron_right標準chevron_rightISO/IEC 42001:2023
現行有效國際標準update 最後更新:2023年12月

ISO/IEC 42001:2023

資訊技術 人工智慧 管理系統

apartment發布組織:國際標準化組織 (ISO)

標準簡介

ISO/IEC 42001:2023 是由 國際標準化組織 (ISO) 發布的現行有效標準,常用於科技、服務業、金融銀行、醫療健康、製造業、汽車、零售等產業,並適用於全球等市場。

本頁整理了 ISO/IEC 42001:2023 的官方文件、目前狀態以及常見相關認證或評估機構,便於快速理解要求與落地路徑。

smart_toy

AI-Specific Management System

The world's first international standard providing a certifiable framework for responsible AI development, deployment, and use — covering the entire AI system lifecycle.

assessment

AI Risk and Impact Assessment

Requires systematic identification of AI-specific risks and assessment of impacts on individuals, groups, and society — including ethical, fairness, transparency, and safety considerations.

database

Data Governance

Mandates robust data management practices covering data quality, bias detection, provenance tracking, and lifecycle management for AI training and operational data.

list_alt AIMS Framework

  • AI policy and organizational commitment
  • AI risk assessment and treatment process
  • AI impact assessment for affected stakeholders
  • Data management and data quality controls
  • AI system lifecycle management (design through retirement)
  • Transparency and explainability requirements
  • Third-party and supply chain AI governance
  • Monitoring, measurement, and continual improvement

Who Needs to Comply?

groups

Organizations that develop, provide, or use AI systems — including technology companies, financial institutions, healthcare organizations, government agencies, and any entity deploying AI in decision-making processes.

Key Requirements

1

AI Risk Assessment

Implement a systematic process to identify, analyze, and evaluate risks specific to AI systems — including risks of bias, unfairness, lack of transparency, safety failures, and privacy violations throughout the AI lifecycle.

2

AI Impact Assessment

Assess the potential consequences of AI systems on individuals, groups, and society. Consider ethical, social, environmental, and human rights impacts. Document assessment results and implement mitigation measures.

3

Data Management

Establish controls for data acquisition, quality, labeling, bias assessment, and lifecycle management. Ensure training data is representative, appropriately documented, and compliant with applicable privacy and intellectual property requirements.

4

AI System Lifecycle Controls

Implement controls across the AI system lifecycle — from requirements definition and design through development, testing, deployment, monitoring, and retirement. Maintain documentation and traceability throughout.

5

Transparency and Accountability

Ensure AI systems and their outputs are explainable to relevant stakeholders. Maintain clear accountability structures for AI-related decisions. Provide mechanisms for affected parties to seek recourse.

Penalties & Enforcement

warning

No direct legal penalties — ISO/IEC 42001 is voluntary. However, it provides a structured path to demonstrate compliance with the EU AI Act and other emerging AI regulations. Certification increasingly expected by enterprise customers and regulators.

官方文件

查看全部

實施時間線

edit_document
2020年
ISO/IEC JTC 1/SC 42 begins development of AI management system standard
rocket_launch
2023年12月
ISO/IEC 42001:2023 published — world's first AI management system standard
verified_user
2024年1月
ANAB launches ISO/IEC 42001 AIMS accreditation program
check_circle
2024年3月
BSI becomes first UKAS-accredited certification body for ISO 42001
gavel
2024年
EU AI Act enters into force, driving alignment with ISO 42001

相關分類