AIセキュリティ

ISO/IEC 42001 (AIMS) Beginner’s Guide — The Next Move After 27001, Reading Annex A’s 38 Controls

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

“We have ISO/IEC 27001. AI use is ramping—what do we get next?” Leadership asks that far more often since late 2025.

ISO/IEC 42001 (AIMS) Beginner’s Guide — The Next Move After 27001, Reading Annex A’s 38 Controls
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

“We have ISO/IEC 27001. AI use is ramping—what do we get next?” Leadership asks that far more often since late 2025. My answer is fixed: it is time to decide whether to pursue ISO/IEC 42001 (AIMS).

ISO/IEC 42001, published December 2023, is the world’s first international AI management system standard (see Microsoft Learn). In January 2026, ISMS-AC granted Japan’s first AIMS accreditations to SGS Japan and TÜV Rheinland Japan (see JIPDEC). Domestic certification is now practical.

Why 42001 exists — AI-specific risks 27001 does not reach

ISO/IEC 27001 is the established information security baseline, but AI exposed clear coverage gaps:

  • Fairness: Does hiring AI underrate applicants with protected attributes?
  • Explainability: Can you explain a credit decision AI’s rationale to a customer?
  • Human oversight: Does a clinician still make the final call on medical diagnostic AI?
  • Impact assessment: Did you evaluate effects on people, society, and the organization before deployment?

None of 27001’s 93 controls treat these directly. 42001 was built as the international frame for AI-specific risk.

My blunt forecast: late 2026–2027, a 27001 + 42001 pair becomes a de facto requirement for global trade and government procurement. With EU AI Act obligations for Annex III high-risk AI (Art. 6(2)) applying from December 2, 2027, and Annex I product-embedded high-risk AI (Art. 6(1)) from August 2, 2028 (see EU AI Act Digital Omnibus), Japanese firms trading with Europe will use 42001 as a negotiation card.

The 42001 body — 10 clauses, similar to 27001 but not the same

Like ISMS, 42001 follows the Annex SL 10-clause template—familiar to teams that already hold 27001.

Clause Content Difference from 27001
4 Context of the organization Adds AI-affected parties and society
5 Leadership Separate AI policy required
6 Planning AI system impact assessment at planning stage
7 Support AI skills, data management
8 Operation AI system life-cycle management
9 Performance evaluation AI system monitoring, internal audit
10 Improvement Nonconformity and AI incident response

Distinctive: Clause 6 AI system impact assessment—absent from 27001. AI Impact Assessment systematically evaluates effects on individuals, society, and the organization before design/deployment—conceptually close to the EU AI Act’s FRIA.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Annex A 38 controls — ten domains at a glance

Annex A holds 38 controls in 10 domains (see Sprinto).

A.2 AI policy (2 controls)
A.2.2 AI policy; A.2.3 alignment of AI policy—with other policies such as 27001 information security policy.

A.3 Internal organization (3)
A.3.2 roles and responsibilities; A.3.3 reporting of concerns; A.3.4 AI risk—implicitly favors structures like an AI ethics committee.

A.4 Resources (6)
A.4.2–A.4.6 cover data, tools, compute, people, systems—planned acquisition and management for AI development.

A.5 AI system impact assessment (4)
A.5.2–A.5.5. Process to assess effects on individuals, groups, society. The core of 42001.

A.6 AI system life cycle (9)
A.6.1.2–A.6.2.8. Design through decommission. Connects to MLOps.

A.7 Data for AI systems (4)
A.7.2–A.7.5. Training data quality, provenance, preparation, data governance.

A.8 Information for interested parties (3)
A.8.2–A.8.4. Transparency and explainability for users and affected parties.

A.9 Use of AI systems (2)
A.9.2–A.9.3. Documented intended use and fit with organizational policy.

A.10 Third-party and customer relationships (3)
A.10.2–A.10.4. External AI services (OpenAI, Anthropic, etc.) and responsibility split when providing your AI to third parties.

Thirty-eight is fewer than half of 27001’s 93—but implementation difficulty is high. A.5 (impact) and A.6 (life cycle) force real process change. Honestly, teams that treat 42001 as “another document set after 27001” usually stall here.

Three themes Japanese teams always stall on

Theme 1: “When do we run impact assessment?”
Not every Excel macro can be in scope. Borrow EU AI Act risk tiers and invent your own triage. In programs I support, impact assessment targets only AI that is externally exposed, automated decision-making, or processes personal data.

Theme 2: Data provenance records fall through
A.7.3 data provenance demands tracking where training data came from and how it was processed—painful for fine-tuning and RAG. Internal docs embedded for RAG need rights, update history, and deletion-request handling. MLflow, Weights & Biases, and similar MLOps tools become practical answers.

Theme 3: Fuzzy third-party AI responsibility
A.10.2 third-party responsibility requires written boundaries when using external AI. If a ChatGPT-API chatbot misinforms a user, where do your firm, OpenAI, and data providers sit? Terms and privacy policies need AI-generated content disclaimers.

The standard does not hand you these answers. You need partners or firms that already accumulated implementation patterns.

WARP SECURITY — hands-on bridge from standard to implementation

Since late 2025, TIMEWELL has seen a surge of 27001-certified firms exploring 42001. WARP SECURITY’s 42001 track aims to leave participants able to run an impact assessment on their own AI the same day—not stop at clause lecture:

  • AI system inventory workshop — map use cases into risk tiers
  • Impact assessment template implementation — customize A.5 sheets to your domain
  • Third-party AI contract negotiation points — SLA, data handling, liability caps for OpenAI/Anthropic-class APIs
  • MLOps ↔ provenance — patterns to embed A.7 into existing CI/CD

My strongest point: 42001 is not a “document your way through it” standard like 27001 often is. You must change how AI systems are built and run. Clause-only training never reaches that.

Details: WARP SECURITY.

Latest as of August 2026

As of August 2026, domestic and international frames for 42001 programs keep updating. Domestically, MIC/METI published AI Business Guidelines v1.2 on March 31, 2026 (METI). Mapping 42001 impact and transparency work to domestic guideline language eases internal explanation.

Abroad, the Digital Omnibus amending the AI Act — Regulation (EU) 2026/1744 — was adopted on July 8, 2026, published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026. The general date of application stays August 2, 2026 after the amendment. What starts on that date, however, is not full application to high-risk AI. From August 2, 2026 the applicable pieces are the Art. 50 transparency obligations (Chapter IV), the provisions on harmonised standards, conformity assessment, CE marking and registration (Chapter III Section 5 = Art. 40–49), and the Commission’s power to fine general-purpose AI (GPAI) providers (Art. 101), among others. Fines run up to €35M or 7% of worldwide turnover (whichever is higher) for prohibited practices under Art. 5, and up to €15M or 3% (whichever is higher) for GPAI-related breaches.

The substantive high-risk obligations (Chapter III Sections 1, 2 and 3) apply from December 2, 2027 for Annex III systems (Art. 6(2)) and from August 2, 2028 for Annex I product-embedded systems (Art. 6(1)). Deployer duties (Art. 26) and the fundamental rights impact assessment (Art. 27) start at the same points. Transitional treatment of systems already on the market (Art. 111(2)) was also re-anchored to the Chapter III application dates rather than a fixed date, catching systems whose designs change significantly after those dates. Firms with European trade have more reason to start 42001 earlier. Pair with agent governance: Governed enterprise AI agents.

Key takeaways — “27001 + 42001 dual wield” as the new normal

  • ISO/IEC 42001 is the world’s first AI MS standard (Dec 2023); Japan’s first AIMS accreditations came January 2026
  • Annex A 38 controls / 10 domains; core = A.5 impact assessment and A.6 life cycle
  • 27001’s CIA axis gains fairness, transparency, explainability, and human oversight under 42001
  • Japanese stalls cluster on impact triage, data provenance, and third-party AI responsibility
  • August 2, 2026 is the EU AI Act’s general date of application, covering Art. 50 transparency duties and the Commission’s Art. 101 GPAI fining power; high-risk obligations follow on December 2, 2027 (Annex III) and August 2, 2028 (Annex I)
  • With Annex III applying from December 2, 2027, starting 42001 in 2026 is realistic for Europe-facing firms

As AI socializes further, “do you have 42001?” will differentiate supplier selection more than “do you have 27001?” 27001 is the minimum ticket; 42001 is competitive advantage. If I had to start one workstream this quarter for a Europe-facing firm, it would be the AI inventory that feeds impact assessment—not a binder of blank templates.

Related: ISMS beginner’s guide, ISO/IEC 27001 certification complete guide, EU AI Act Digital Omnibus 2026.

References

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles