Management system standards and the Harmonized Structure

Lesson 3 of 5 in The AI Standards Landscape and Core Terminology (ISO/IEC 22989).

Most standards tell you how to do a thing — measure classification accuracy, format a date, test a helmet. A management system standard (MSS) is a different animal: it tells you how to run an organisation so that a whole category of outcomes — quality, security, now AI responsibility — is produced systematically rather than heroically. ISO 9001 did it for quality (over a million certificates worldwide), ISO/IEC 27001 for information security, and in December 2023 ISO/IEC 42001 joined the family as the first certifiable management system standard for AI.

The family resemblance is engineered, not accidental. Since 2012, every ISO management system standard has been built on the same skeleton — originally called Annex SL, today the Harmonized Structure — ten clauses with identical numbering, largely identical core text, and identical logic:

Clauses 1–3 are scaffolding (scope, normative references, terms). The engine is clauses 4–10: Context, Leadership, Planning, Support, Operation, Performance evaluation, Improvement. Each discipline-specific standard takes that skeleton and adds its own flesh — 27001 inserts information-security risk assessment, 42001 inserts AI-specific planning like impact assessment. Learn the skeleton once and every MSS you ever open will feel familiar.

The Harmonized Structure skeleton — and the AI-specific flesh 42001 adds
ClauseWhat the shared skeleton demands (every MSS)What ISO/IEC 42001 adds for AI

4 — Context

Understand internal/external issues, interested parties and their requirements; define the management system’s scope

Determine the organisation’s role(s) with respect to AI — provider, developer, user, or several at once — because obligations differ by role

5 — Leadership

Top management commitment; a topic policy; roles, responsibilities and authorities assigned

An AI policy covering responsible development and use, aligned with organisational objectives

6 — Planning

Address risks and opportunities; set measurable objectives; plan changes

A formal AI risk assessment and risk treatment process with a Statement of Applicability — plus an AI system impact assessment (6.1.4) that no other MSS requires

7 — Support

Resources, competence, awareness, communication, and controlled documented information

AI-specific competence: data science, ML lifecycle, and AI-risk literacy, not just process skills

8 — Operation

Plan and control the processes that deliver the system’s intent

Execute risk assessments, treatments, and impact assessments operationally — at planned intervals and on significant change

9 — Performance evaluation

Monitor and measure; run internal audits; hold management reviews

Metrics that track AI system behaviour (drift, incidents, fairness indicators), not just process health

10 — Improvement

Continual improvement; nonconformity and corrective action

The corrective-action loop must reach into models and data, not just procedures

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.