No – for conformance to ISO 42001, you will need to conduct both an artificial intelligence impact assessment (AIIA) and a risk assessment. When conducting your risk assessment, you will need to identify the AI systems covered, any activities prohibited by applicable and relevant regulations and legislation, and high-risk AI systems that have been produced or utilised by your organisation. In terms of approach, the AI risk assessment will be similar to risk assessments conducted for other management system standards, such as ISO 27001, however some different inputs, threats and risks will need to be considered.

Auditing ISO 42001: Its Unique Requirements and Key Differences From ISO 27001
URM's blog examines how the ISO 42001 management system requirements differ from ISO 27001, and the impact this has on what auditors will expect to see.
URM’s blog breaks down how to effectively implement ISO 42001, where it differs from other ISO standards, and the common certification pitfalls to avoid
URM’s blog explores 3 leading AI governance frameworks and regulations, how they complement and differ & what they mean for organisations working with AI.
URM’s blog explores ISO 42001, its intentions and structure, and the AI perspectives that will need to be considered by organisations implementing the Standard.

