Digital Information GovernanceDIG® · The Standard Reference
HomeRegulations › ISO/IEC 42001
Regulatory context

ISO/IEC 42001

ISO/IEC 42001:2023 is the international management-system standard for artificial intelligence, defining auditable controls for governing AI across its lifecycle.

As a management-system standard, ISO 42001 is built around audit and continual improvement, which aligns with DIG's Audit Readiness pillar. Its controls for data, accountability, and transparency map to Information Provenance, Decision Traceability, and Representation Integrity. An organization pursuing ISO 42001 certification can use DIG as the decision-level discipline underneath the management system.

References

  1. NIST AI Risk Management Framework (AI RMF 1.0): Govern, Map, Measure, Manage. National Institute of Standards and Technology, 2023. View source ↗
  2. Information governance: the records and data lifecycle discipline (storage, retention, disposition), distinct from AI decision governance. ARMA International, Generally Accepted Recordkeeping Principles; AIIM. View source ↗
  3. EU AI Act, Regulation (EU) 2024/1689 (Official Journal of the European Union); ISO/IEC 42001:2023; Texas Responsible AI Governance Act (TRAIGA). View source ↗
  4. USPTO Trademark Reg. No. 99559923, Digital Information Governance / DIG, owner Matthew Bertram. View source ↗