An AI Management System (AIMS) is the running set of policies, roles, processes and records you use to govern AI, defined by the ISO 42001 standard. The key thing to understand: it is not a single document, it is a system you operate. At a minimum it contains an AI policy, an inventory of the AI you use, a way to classify each system’s risk, controls, clear accountability, human oversight, monitoring, and a standing evidence trail.
People often picture a policy PDF. An AIMS is the machinery that makes a policy true, and keeps it true as your AI use and the rules change. Here is what is actually inside one.
What is an AIMS, exactly?
ISO/IEC 42001, published in 2023, is the first international standard for an AI Management System. If you know ISO 27001 (information security) or ISO 9001 (quality), the shape is familiar: a management system you run on a plan, do, check, act cycle, with defined roles, documented processes, and evidence that it works. ISO 42001 applies that discipline specifically to AI.
So an AIMS is not a deliverable you finish. It is the structure that lets you answer, on any given day, three questions: what AI are we using, how is each piece controlled, and can we prove it.
The core components
A complete AIMS pulls together the following. Not every organisation needs all of it at full depth, but a credible system touches each area.
1. An AI policy
The top-level statement of how your organisation will use AI: principles, boundaries, who is accountable, and the standards you hold yourself to. Short, approved by leadership, and the anchor everything else hangs off. We cover how to write one, with a template, separately.
2. Roles and accountability
Named ownership. Who is accountable for AI governance overall, who owns each system, and how decisions escalate. Ungoverned AI usually means no one owns it, so this is where governance becomes real rather than theoretical.
3. An AI system inventory (the register)
A single, maintained register of every AI system, model and tool in use: what it does, who owns it, what data it touches, and its status. You cannot govern what you cannot see, so the register is the foundation the rest sits on. We cover what to actually track in it separately.
4. Risk and impact assessment
A consistent way to assess and classify each system: its risk tier, who it affects, and what could go wrong. ISO 42001 expects an AI impact assessment, and it is where the standard meets the EU AI Act’s risk tiers. We set out a method in how to classify your AI systems by risk, and cover the impact side in how to run an AI impact assessment.
5. Controls
The actual safeguards, drawn from ISO 42001’s Annex A reference set: controls across AI policy, internal organisation, resources, impact assessment, the system lifecycle, data, information for users, and use of AI. You apply the controls that fit your risk and justify the ones you leave out.
6. Data governance for AI
How data used to train, tune and run AI is sourced, handled, and kept lawful and fit for purpose. This is where AI governance overlaps with your existing data protection obligations.
7. Lifecycle management
Process for how AI systems are designed, validated, deployed, monitored and retired, including a gate that assesses new tools before they go live rather than after.
8. Human oversight
Where people stay in control: the checkpoints, approvals and intervention paths for systems whose decisions carry weight. Required outright for higher-risk uses.
9. Supplier and third-party management
Most AI risk now comes from tools you bought, not models you built. The AIMS covers how you assess and govern third-party AI and the vendors behind it, starting with how you evaluate an AI vendor.
10. Competence and AI literacy
Making sure the people using and overseeing AI understand it well enough to do so responsibly. This also maps to the EU AI Act’s AI literacy duty.
11. Monitoring, internal audit and management review
The check step: measuring whether controls are working, auditing the system, and a regular leadership review that re-prioritises as things change. This is what stops an AIMS becoming a binder on a shelf.
12. Incident response and corrective action
What happens when something goes wrong: how AI incidents are caught, handled, and fed back into the system so the same gap does not reappear.
13. Documented information (the evidence trail)
Running through all of the above: the records. The decisions logged, the assessments filed, the reviews minuted. When a regulator, auditor or customer asks you to demonstrate control, this is the answer, and it is the part that has to already exist, not be assembled in a panic.
What an AIMS is not
- It is not an AI policy. The policy is one page of it.
- It is not a one-off project. It is a system you run continuously.
- It is not the ISO 42001 certificate. You can run an AIMS without certifying; the certificate just has an accredited body confirm the system exists and works. We covered that in do you need ISO 42001?.
The minimum viable AIMS
If that list looks heavy, start where the leverage is. The smallest version that genuinely reduces risk is: a complete register, every system risk-classified, a short AI policy, clear ownership, and a standing evidence trail. That alone closes the three gaps most organisations have, visibility, classification and proof, and gives you something defensible to build on. The rest is depth you add as your AI use grows.
The short version
An AIMS is the working system that makes your AI governable: the policy, the register, the risk classification, the controls, the accountability, the oversight, the monitoring and the records, run as one thing and kept current. ISO 42001 tells you what it should contain. Building it is the job; the certificate is optional.
Want to see how much of this you already have? The free AI governance readiness assessment gives you a quick, no-email read on your AIMS maturity in about ten minutes. When you want to stand the system up properly, talk to us.
For the full picture, see the AI governance guide.
Frequently asked questions
What is an AI Management System (AIMS)?
An AIMS is the set of policies, roles, processes and records an organisation uses to govern its development and use of AI, in a structured, auditable way. ISO 42001 is the international standard that defines what one should contain. It is a system you run, not a document you file.
Is an AIMS the same as an AI policy?
No. An AI policy is one component of an AIMS: the high-level statement of intent. The AIMS is everything that makes that policy real: the inventory, risk process, controls, accountability, oversight, monitoring, records and the review cycle that keeps it current.
What controls does ISO 42001 include?
ISO 42001 sets out a reference set of controls in its Annex A, grouped into areas such as AI policies, internal organisation and roles, resources, impact assessment, the AI system lifecycle, data for AI, information for users, and use of AI systems. You apply the ones relevant to your risk, and justify any you leave out.
Do you need ISO 42001 certification to have an AIMS?
No. You can build and run an AIMS using ISO 42001 as the blueprint without ever certifying. Certification is a separate, optional step where an accredited body audits the system you are already running. Many organisations build the AIMS first and certify later, if a customer or regulator makes it worth it.
How long does it take to build an AIMS?
A proportionate AIMS for a small or mid-sized organisation typically takes a few weeks to stand up, then runs continuously. The build time depends on how much AI you use, how much governance already exists, and whether you reuse an existing management system such as ISO 27001.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert