In recent years, new technologies in artificial intelligence (AI) have continuously made breakthroughs, new business forms have emerged, and new applications have been rapidly expanded, becoming an important driving force for a new round of technological revolution and industrial transformation. At the same time, the development of AI also faces a series of new challenges in the areas of law, security, employment, ethics, and other aspects. International organizations and many countries around the world have begun to explore feasible paths for AI governance in terms of concepts, legislation, and popular science, and have reached some consensus, striving to find a balance between development and security. China's AI industry has achieved rapid development in technological innovation, product creation, and industry applications, forming a huge market scale. With the accelerated iteration of new technologies represented by large models, the AI industry presents new characteristics such as breakthroughs in innovative technology clusters, integrated development of industry applications, and deep collaboration in international cooperation, urgently requiring the improvement of the AI industry standard system.
ISO/IEC 42001:2023 "Information Technology - Artificial Intelligence Management System" International Standard: In view of the significant impact of artificial intelligence on human society and economic activities, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) jointly issued the ISO/IEC 42001:2023 "Information Technology - Artificial Intelligence Management System" International Standard on December 18, 2023.
The ISO/IEC 42001:2023 international standard provides an international, standardized, and systematic management framework for organizations to establish, implement, maintain, and continuously improve their artificial intelligence management systems (AIMS). This framework enables organizations to adopt risk-based thinking, process methods, and the PDCA cycle, facilitating compatibility and integration with quality, information security, privacy protection, and other management systems. It also enables proactive and effective response and management of risks related to AI development and deployment. Additionally, the ISO/IEC 42001:2023 international standard offers a new management system certification program for third-party certification bodies, supporting their sustainable business development.
Benefits of ISO/IEC 42001:2023 certification
By conducting impact assessments, risk assessments, and risk management, enterprises can effectively address risks related to the unintended use, privacy and data security, AI system security, technological ethics, environment, and energy associated with AI systems, and continuously improve the impact of AI systems on individuals, groups, and society.
01 Integrate key frameworks with experience to implement critical processes such as risk management, lifecycle management, and data quality management;
02 Implement AI safely and provide evidence of responsibility and accountability;
03 Consider safety, fairness, transparency, and the quality of data and AI systems throughout their entire lifecycle;
04 indicates that the introduction of artificial intelligence is a strategic decision with a clear objective;
05 Demonstrate strong governance of artificial intelligence and strike a balance between governance and innovation;
06 Ensure the responsible use of artificial intelligence, especially in its continuous learning aspect, and ensure that all relevant safeguards are in place.
ISO/IEC 42001:2023 Application Requirements
01 Chinese enterprises hold the "Business License for Enterprise Legal Person", "Production License", or equivalent documents issued by the administrative department for industry and commerce; foreign enterprises hold registration certificates from relevant institutions;
02 The applicant's information technology service management system has been established in accordance with the requirements of ISO/IEC 42001:2023 standard and has been implemented and operated for 3 months;
03 Conducted at least one internal audit and management review;
04 The management system has not been subject to administrative penalties by the competent department during its operation and within one year prior to its establishment.