SS-ISO/IEC 42001:2023 — Artificial intelligence management systems, requirements
The requirements for governing AI systems: accountability, impact assessment, data, life cycle, logging and monitoring. It serves as a method when an organisation must show AI governance to customers and supervisors.
Register
- Designation
- SS-ISO/IEC 42001:2023
- Edition
- 2023
- Publisher
- Svenska institutet för standarder (SIS)
- Group
- Information security and privacy
- Area
- Data protection and cybersecurity
- Read date
- 2026-09-09
Standards are not statute. They are purchased documents from SIS that parties agree to, or that regulations refer to. We carry the designation, edition and scope, never the text.
Official text
Buy the standard from SISSS-ISO/IEC 42001:2023
Used together with
- Dataskyddslagen · SFS 2018:218
- NIS-lagen · SFS 2018:1174
Information security and privacy
- Information security management systems, requirements
SS-EN ISO/IEC 27001:2022Svenska institutet för standarder (SIS)
The requirements for an information security management system: scope, risk assessment, risk treatment, statement of applicability and management review. It is the most common basis when a business must show appropriate technical and organisational measures.
- Guidance on information security controls
SS-EN ISO/IEC 27002:2022Svenska institutet för standarder (SIS)
The catalogue of security controls that belongs with the management system: organisational, people, physical and technological controls, with the purpose and application of each.
- Guidance on managing information security risks
SS-ISO/IEC 27005:2022Svenska institutet för standarder (SIS)
The method for identifying, analysing, evaluating and treating information security risks, and how that work connects to the management system and to decisions on acceptable risk.
- Extension to the management system for privacy information management
SS-EN ISO/IEC 27701:2021Svenska institutet för standarder (SIS)
The extension that turns the information security management system into a privacy information management system, with roles for controller and processor and controls tied to data subject rights.
Swedish law
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.