Skip to main content
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Skip to main Content
Back to Blog
AI Regulations

How ISO/IEC 42001 and 42005 Work Together for AI Governance

Written by: 
Prompt Security Team
June 18, 2025

ISO/IEC 42001 and ISO/IEC 42005 are the two international standards organizations use to govern AI: one covers how an organization runs its overall AI program, the other covers assessing the impact of each individual AI system.

An AI policy can establish what an organization allows. It cannot show whether every AI system follows that policy, whether a system's risk profile has changed, or whether an agent has gained access to a new tool or data source.

Effective AI governance needs both an organization-wide management structure and a way to evaluate the individual systems operating within it. ISO/IEC 42001 and ISO/IEC 42005 address those two layers. Used together, they connect AI policy with the systems, decisions, and activities that policy is supposed to govern.

ISO/IEC 42001 Sets the Structure for AI Governance

ISO/IEC 42001 establishes the management system for governing AI across an organization: defining responsibilities, setting policies and objectives, managing risk, and continually improving how AI is overseen. Its focus is the organization's decision-making process, not the technical details of any single model or application.

This has to hold up as AI adoption spreads across employee tools, code assistants, customer-facing applications, and agentic workflows. Governance cannot depend on a separate process for every new AI product. Applying that structure to individual systems is where ISO/IEC 42005 comes in.

ISO/IEC 42005 Brings Governance to the System Level

ISO/IEC 42005 provides guidance for conducting AI system impact assessments. These assessments identify, evaluate, and document how an AI system and its foreseeable uses affect individuals, groups, and society across its lifecycle, from design through decommissioning. The assessment covers the system's purpose, its operating context, who it affects, and what it depends on to function.

The scope is broader than security alone. Relevant impacts can involve fairness, safety, privacy, transparency, human oversight, or other effects created by how a system is designed and used. Security still plays a central role within that scope: weak access controls, exposed data, manipulated inputs, or misuse can drive the wider impacts an assessment is meant to catch.

ISO/IEC 42005 treats assessment as a lifecycle activity rather than a one-time gate. An assessment should be revisited whenever a system, its purpose, its users, or its operating environment changes.

How the Two Standards Fit Together

ISO/IEC 42001 asks how the organization should manage AI responsibly and consistently. ISO/IEC 42005 asks what impacts a particular AI system could create and how to evaluate them.

In practice, that looks like:

‍

  1. Establish governance and ownership. Define who is accountable for AI systems, policies, risk decisions, and monitoring.
  2. Identify the AI systems in scope. Track systems built internally, purchased from vendors, embedded in existing software, or adopted directly by employees.
  3. Assess each system in context. Look at what it is for, who it affects, what it depends on, and what impacts it may create.
  4. Apply proportionate controls. Use the findings to set access restrictions, data protections, testing requirements, and monitoring.
  5. Retain evidence. Document assessments, decisions, exceptions, and changes to the system.
  6. Reassess when conditions change. Treat a new model, data source, user base, or environment as a trigger to look again, since the original sign-off doesn't cover the change.

This keeps impact assessments from becoming static documents completed before launch and never revisited.

What Changes for AI Agents

ISO/IEC 42005's core principles hold for agentic AI: context, foreseeable use, and lifecycle reassessment matter just as much when a system can act on a user's behalf. But applying them to an agent means deliberately widening what gets assessed, not simply carrying over the same scope.

For an AI agent, the assessment boundary extends past the prompt and response. Organizations also need to consider:

  • Which tools, applications, and services the agent can access
  • What data and credentials are available to it
  • Which actions it can perform and under whose authority
  • Whether it retains memory or external context
  • How it delegates work to other agents or services
  • Where human approval is required
  • How actions can be stopped, reversed, or investigated
  • What happens when tools, permissions, or objectives change

Two of these, approval and the ability to stop, reverse, or investigate an action, are governance questions as much as assessment ones. Both belong within the management structure established under ISO/IEC 42001: who owns the decision to grant an agent new permissions, and who is accountable when something goes wrong. What that access could do, and whom it could affect, is what the impact assessment helps examine.

An agent initially approved to summarize internal documents may later gain permission to update records, send messages, or interact with external systems. The agent's name stays the same while its potential impact changes substantially, which is exactly the kind of shift ISO/IEC 42005's lifecycle-based assessment is built to catch.

From Policy to Evidence

Policies and assessments set direction, but they need evidence showing whether a system’s actual use still matches its approved purpose and impact assessment. Useful records can include system inventories, completed assessments, approval histories, access and activity logs, policy exceptions, and documentation of significant changes.

With those records in place, an audit or investigation becomes a lookup instead of a scramble.

A policy can stay stable for years. The systems operating under it rarely do. ISO/IEC 42001 and ISO/IEC 42005 give organizations a structure and a method to keep pace.

‍

Last Updated:
August 9, 2026

Share this post
Summarize this Post
On This Page

TOC Element

Related Posts

View All Posts
No items found.
Log In
Learn More
Book a Demo

Resources

Blog
AI Security Glossary
What is AI Security?
PromptCast: The Voice of AI & Security
ClawSec
OneClaw
Prompt Fuzzer
AI Security Startup Map
© {{year}} Prompt Security. All Rights Reserved.
Privacy Policy
Terms of Service

Follow Us