ISO/IEC 42001 and ISO/IEC 42005 are the two international standards organizations use to govern AI: one covers how an organization runs its overall AI program, the other covers assessing the impact of each individual AI system.
An AI policy can establish what an organization allows. It cannot show whether every AI system follows that policy, whether a system's risk profile has changed, or whether an agent has gained access to a new tool or data source.
Effective AI governance needs both an organization-wide management structure and a way to evaluate the individual systems operating within it. ISO/IEC 42001 and ISO/IEC 42005 address those two layers. Used together, they connect AI policy with the systems, decisions, and activities that policy is supposed to govern.
ISO/IEC 42001 Sets the Structure for AI Governance
ISO/IEC 42001 establishes the management system for governing AI across an organization: defining responsibilities, setting policies and objectives, managing risk, and continually improving how AI is overseen. Its focus is the organization's decision-making process, not the technical details of any single model or application.
This has to hold up as AI adoption spreads across employee tools, code assistants, customer-facing applications, and agentic workflows. Governance cannot depend on a separate process for every new AI product. Applying that structure to individual systems is where ISO/IEC 42005 comes in.
ISO/IEC 42005 Brings Governance to the System Level
ISO/IEC 42005 provides guidance for conducting AI system impact assessments. These assessments identify, evaluate, and document how an AI system and its foreseeable uses affect individuals, groups, and society across its lifecycle, from design through decommissioning. The assessment covers the system's purpose, its operating context, who it affects, and what it depends on to function.
The scope is broader than security alone. Relevant impacts can involve fairness, safety, privacy, transparency, human oversight, or other effects created by how a system is designed and used. Security still plays a central role within that scope: weak access controls, exposed data, manipulated inputs, or misuse can drive the wider impacts an assessment is meant to catch.
ISO/IEC 42005 treats assessment as a lifecycle activity rather than a one-time gate. An assessment should be revisited whenever a system, its purpose, its users, or its operating environment changes.
How the Two Standards Fit Together
ISO/IEC 42001 asks how the organization should manage AI responsibly and consistently. ISO/IEC 42005 asks what impacts a particular AI system could create and how to evaluate them.
In practice, that looks like:
- Establish governance and ownership. Define who is accountable for AI systems, policies, risk decisions, and monitoring.
- Identify the AI systems in scope. Track systems built internally, purchased from vendors, embedded in existing software, or adopted directly by employees.
- Assess each system in context. Look at what it is for, who it affects, what it depends on, and what impacts it may create.
- Apply proportionate controls. Use the findings to set access restrictions, data protections, testing requirements, and monitoring.
- Retain evidence. Document assessments, decisions, exceptions, and changes to the system.
- Reassess when conditions change. Treat a new model, data source, user base, or environment as a trigger to look again, since the original sign-off doesn't cover the change.
This keeps impact assessments from becoming static documents completed before launch and never revisited.
What Changes for AI Agents
ISO/IEC 42005's core principles hold for agentic AI: context, foreseeable use, and lifecycle reassessment matter just as much when a system can act on a user's behalf. But applying them to an agent means deliberately widening what gets assessed, not simply carrying over the same scope.
For an AI agent, the assessment boundary extends past the prompt and response. Organizations also need to consider:
- Which tools, applications, and services the agent can access
- What data and credentials are available to it
- Which actions it can perform and under whose authority
- Whether it retains memory or external context
- How it delegates work to other agents or services
- Where human approval is required
- How actions can be stopped, reversed, or investigated
- What happens when tools, permissions, or objectives change
Two of these, approval and the ability to stop, reverse, or investigate an action, are governance questions as much as assessment ones. Both belong within the management structure established under ISO/IEC 42001: who owns the decision to grant an agent new permissions, and who is accountable when something goes wrong. What that access could do, and whom it could affect, is what the impact assessment helps examine.
An agent initially approved to summarize internal documents may later gain permission to update records, send messages, or interact with external systems. The agent's name stays the same while its potential impact changes substantially, which is exactly the kind of shift ISO/IEC 42005's lifecycle-based assessment is built to catch.
From Policy to Evidence
Policies and assessments set direction, but they need evidence showing whether a system’s actual use still matches its approved purpose and impact assessment. Useful records can include system inventories, completed assessments, approval histories, access and activity logs, policy exceptions, and documentation of significant changes.
With those records in place, an audit or investigation becomes a lookup instead of a scramble.
A policy can stay stable for years. The systems operating under it rarely do. ISO/IEC 42001 and ISO/IEC 42005 give organizations a structure and a method to keep pace.