Management system standards and the Harmonized Structure
Lesson 3 of 5 in The AI Standards Landscape and Core Terminology (ISO/IEC 22989).
Most standards tell you how to do a thing — measure classification accuracy, format a date, test a helmet. A management system standard (MSS) is a different animal: it tells you how to run an organisation so that a whole category of outcomes — quality, security, now AI responsibility — is produced systematically rather than heroically. ISO 9001 did it for quality (over a million certificates worldwide), ISO/IEC 27001 for information security, and in December 2023 ISO/IEC 42001 joined the family as the first certifiable management system standard for AI.
The family resemblance is engineered, not accidental. Since 2012, every ISO management system standard has been built on the same skeleton — originally called Annex SL, today the Harmonized Structure — ten clauses with identical numbering, largely identical core text, and identical logic:
Clauses 1–3 are scaffolding (scope, normative references, terms). The engine is clauses 4–10: Context, Leadership, Planning, Support, Operation, Performance evaluation, Improvement. Each discipline-specific standard takes that skeleton and adds its own flesh — 27001 inserts information-security risk assessment, 42001 inserts AI-specific planning like impact assessment. Learn the skeleton once and every MSS you ever open will feel familiar.
| Clause | What the shared skeleton demands (every MSS) | What ISO/IEC 42001 adds for AI |
|---|---|---|
4 — Context | Understand internal/external issues, interested parties and their requirements; define the management system’s scope | Determine the organisation’s role(s) with respect to AI — provider, developer, user, or several at once — because obligations differ by role |
5 — Leadership | Top management commitment; a topic policy; roles, responsibilities and authorities assigned | An AI policy covering responsible development and use, aligned with organisational objectives |
6 — Planning | Address risks and opportunities; set measurable objectives; plan changes | A formal AI risk assessment and risk treatment process with a Statement of Applicability — plus an AI system impact assessment (6.1.4) that no other MSS requires |
7 — Support | Resources, competence, awareness, communication, and controlled documented information | AI-specific competence: data science, ML lifecycle, and AI-risk literacy, not just process skills |
8 — Operation | Plan and control the processes that deliver the system’s intent | Execute risk assessments, treatments, and impact assessments operationally — at planned intervals and on significant change |
9 — Performance evaluation | Monitor and measure; run internal audits; hold management reviews | Metrics that track AI system behaviour (drift, incidents, fairness indicators), not just process health |
10 — Improvement | Continual improvement; nonconformity and corrective action | The corrective-action loop must reach into models and data, not just procedures |
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.