What ISO 42001 Requires of Boards and CEOs (Plain English Guide)

The moon against a deep blue sky — AI governance requires boards to look further ahead

ISO 42001 is the international standard for artificial intelligence management systems. Published in late 2023, it is the first standard of its kind — a structured framework that tells organisations how to govern AI responsibly across their operations.

Most coverage of ISO 42001 focuses on IT teams, risk functions, and compliance officers. That makes sense — they will do most of the implementation work. But the standard itself has a great deal to say about what it expects at the top of the house. Boards and CEOs are not spectators in this process. They are specifically called out.

This piece sets out what ISO 42001 actually requires at the governance and executive level — without the standards jargon.

First, a bit of context

ISO 42001 follows the same structure as other ISO management system standards you may have encountered — ISO 9001 for quality, ISO 27001 for information security. If your organisation has implemented either of those, some of this will feel familiar.

The standard uses the term "AIMS" — AI Management System. The AIMS is not a technology system. It is the collection of policies, processes, roles, and controls through which your organisation governs its AI activity. The standard provides a framework for establishing, implementing, maintaining, and continually improving that system.

What makes ISO 42001 different from previous AI guidance documents is that it is certifiable. An organisation can be independently audited against it and receive a certificate of conformance. Whether or not you pursue certification, the standard represents the emerging global benchmark for what good AI governance looks like.

What it specifically asks of leadership

Section 5 of ISO 42001 is titled "Leadership". This is not a soft chapter about vision and culture. It contains specific requirements.

Demonstrated commitment. The standard requires that top management — which it defines as the person or group that directs and controls the organisation at the highest level — demonstrate leadership and commitment to the AI management system. This is not a delegatable item. The standard is explicit that top management cannot simply assign this to a team and consider it done.

What does demonstrated commitment look like? The standard points to things like ensuring the AIMS objectives are compatible with the organisation's strategic direction, ensuring that the necessary resources are available, and promoting continual improvement. These are governance-level responsibilities.

Establishing policy. Top management is required to establish an AI policy. This is a formal document that sets out the organisation's commitments in relation to AI — its principles, its risk appetite, its obligations. The policy must be appropriate to the purpose and context of the organisation, provide a framework for setting AI objectives, and include a commitment to satisfying applicable requirements.

The policy must also be communicated within the organisation and available to relevant interested parties. This means it cannot sit in a drawer. It is a public-facing statement of how your organisation approaches AI.

Assigning roles and authorities. The standard requires top management to ensure that responsibilities and authorities for relevant roles are assigned and communicated. Someone — or a group — needs to be accountable for the AIMS and for reporting on its performance to top management.

This is significant. It means the board or CEO needs to designate someone responsible for AI governance and ensure that person has the authority and access to do the job. In larger organisations this might be a Chief AI Officer or equivalent. In smaller ones it might sit with the CTO, CRO, or a senior leader with a defined mandate.

What about the board specifically?

ISO 42001 uses the term "governing body" to refer to the board or equivalent oversight function. In several places the standard distinguishes between top management (the executive) and the governing body, acknowledging that in many organisations these are separate groups with different roles.

The standard expects the governing body to provide oversight of the AI management system — not to run it, but to understand it, ask questions about it, and hold the executive accountable for its performance. This is the same relationship a board has with financial management or enterprise risk: you do not need to know how to do the work, but you do need to know whether the work is being done well.

For boards, this translates to a few practical things. First, AI governance needs to be a standing agenda item, not something that surfaces only when a problem occurs. Second, the board needs enough understanding of AI risk to ask meaningful questions of management. Third, the board needs to see regular reporting on AI-related risks, incidents, and the health of the AI management system.

The governing body does not run the AI management system. But it is responsible for ensuring that someone does, and for understanding whether it is working.

Risk and impact assessment

One of the most substantive parts of ISO 42001 relates to risk and impact assessment for AI systems. The standard requires organisations to assess both the risks arising from their AI use and the potential impacts on people and society.

This is not just a technical exercise. Many of the most significant AI risks are not technical at all — they are strategic, reputational, ethical, and legal. Decisions about which AI systems to deploy, in which contexts, with what level of human oversight, are decisions that have implications well beyond the IT team.

Senior leaders and boards need to be part of conversations about AI risk appetite. What level of algorithmic risk is the organisation willing to accept? In which decisions should AI be making recommendations versus making decisions? What happens when an AI system causes harm? Who is accountable?

These are governance questions, and the standard asks that they be answered at a governance level.

What about Australia?

Australia does not yet have mandatory AI regulation equivalent to the EU AI Act, but the landscape is shifting. The Australian Government's voluntary AI Safety Standard, released in 2024, aligns closely with ISO 42001 and references it explicitly. The standard's ten guardrails map directly onto ISO 42001's risk management requirements.

For Australian boards and executives, ISO 42001 represents the most credible and internationally recognised benchmark available right now. Organisations that implement it — even without pursuing formal certification — will be well positioned as the regulatory environment in Australia continues to develop. And those that wait for mandatory requirements to force the issue will find themselves starting from behind.

Where most boards are right now

In my experience working with boards and executive teams, most are somewhere on a spectrum between "we haven't really discussed AI governance formally" and "we've had one or two conversations but don't have a framework or policy yet." Very few have a well-functioning AI management system in place.

That's not unusual given the speed at which AI has moved onto the corporate agenda. Two years ago, most boards were not being asked about this at all. Now it's showing up in conversations about strategy, risk, and stakeholder expectations — and boards are playing catch-up.

The good news is that ISO 42001 is not as daunting as it might appear from the outside. It is structured, practical, and scalable. An organisation does not need to implement everything at once. What it does need is leadership commitment and a clear starting point.

For most boards, the most useful starting point is a gap analysis: where are we now relative to what ISO 42001 requires, and what are the highest-priority areas to address? That exercise alone tends to surface issues that were previously invisible — because nobody had asked the right questions in the right structured way.

← What Does Disability Confidence Actually Mean for Managers? More Articles →

The AI Governance Confidence Framework

Built for boards and senior executives navigating AI governance. The AGCF covers ISO 42001, the EU AI Act, NIST AI RMF, and the Australian AI Safety Standard — with practical tools, gap analysers, and plain-English guidance for leaders at every level.

Explore the Framework Talk to Michael
Or explore: AI Governance Services Frameworks & Guides More Articles