ISO 42001 Glossary
Key terms used throughout ISO/IEC 42001:2023, this toolkit, and the surrounding regulatory landscape.
Core terms
- AIMS (AI Management System)
- A set of interrelated or interacting elements of an organisation intended to establish policies, objectives, and processes to achieve those objectives in relation to responsible development, provision, or use of AI systems. The AIMS is the subject of ISO/IEC 42001 certification.
- AI system
- A machine-based system that, for explicit or implicit objectives, infers from the inputs it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
- AI risk
- The effect of uncertainty on the objectives of an AI system, including effects on individuals, groups, and society, covering bias, fairness, safety, security, privacy, and transparency.
- AI impact assessment
- A documented process to identify, evaluate, and address the potential impacts of an AI system on individuals, groups, and broader society. Required by A.5 in ISO 42001 and by the Colorado AI Act, EU AI Act Article 27 (FRIA), and other regulations.
- Annex A
- The informative annex of ISO/IEC 42001:2023 containing 38 reference controls across 9 groups (A.2 through A.10). Applied selectively based on risk assessment and documented in the Statement of Applicability.
- Statement of Applicability (SoA)
- Document stating which Annex A controls apply to the AIMS, which are excluded, and justification for each decision. Required under ISO 42001 Clause 6.1.3.
- Conformity assessment
- The demonstration that specified requirements are fulfilled. Under ISO 42001 this is performed by accredited certification bodies. Under the EU AI Act, conformity assessment is required before placing high-risk AI systems on the market.
- Certification body
- An organisation accredited (by ANAB, UKAS, DAkkS, or equivalent) to issue certificates confirming conformance to ISO management-system standards. ISO/IEC 42006 governs certification-body operations for ISO 42001.
- Stage 1 audit
- The first on-site audit by the certification body, focused on documentation review and readiness for Stage 2.
- Stage 2 audit
- The second on-site audit, focused on the implementation and effectiveness of the AIMS. Longer than Stage 1; produces findings that must be closed for certification.
- Surveillance audit
- Annual check by the certification body to confirm continued conformance with the standard. Shorter than Stage 1/2.
Regulatory terms
- Colorado AI Act (SB 24-205)
- The Colorado Artificial Intelligence Act (SB 24-205, 2024) was repealed before taking effect and replaced by SB 189, signed 14 May 2026 and effective 1 January 2027, a transparency- and disclosure-based framework. The original ISO 42001 / NIST AI RMF affirmative defense was removed.
- EU AI Act (Regulation 2024/1689)
- European Union regulation on artificial intelligence, in force from August 2024. Risk-based obligations; Article 73 serious-incident reporting applies from 2 December 2027.
- Affirmative defense (Colorado)
- A legal defense that was available under Colorado's original AI Act (SB 24-205) to developers and deployers of high-risk AI systems who complied with an approved AI risk-management framework. SB 24-205 was repealed before it took effect and replaced by SB 189 (signed 14 May 2026, effective 1 January 2027), which contains no such defense. ISO 42001 is no longer a Colorado statutory defense, though it still supports SB 189's documentation duties. Full detail here.
- High-risk AI system
- AI systems in specific categories defined by the EU AI Act Annex III or the Colorado AI Act (employment, housing, healthcare, credit, education, law enforcement, and similar consequential decision domains).
- GPAI (General-Purpose AI) model
- Under the EU AI Act, an AI model that displays significant generality and is capable of competently performing a wide range of distinct tasks. Subject to specific transparency and documentation obligations.
- Microsoft SSPA
- Microsoft Supplier Security and Privacy Assurance program. Data Protection Requirements (DPR) v12 released March 2026 accepts ISO/IEC 42001 certification in lieu of independent assessment for AI-specific requirements.
- NIST AI RMF
- The NIST Artificial Intelligence Risk Management Framework, published January 2023. A voluntary US framework with four functions (Govern, Map, Measure, Manage). Recognised alongside ISO 42001 by the Colorado AI Act.
- ISO/IEC 42006
- Published standard for requirements for bodies providing audit and certification of AI management systems. Governs how certification bodies operate when issuing ISO 42001 certificates.