ISO/IEC 42001

A risk-based intake and oversight method for bought models, AI-enabled software, and outsourced AI services.

Start with the use, not the vendor questionnaire

Define the intended workflow and what the AI system will influence. A general-purpose model API, an AI-enabled SaaS feature, a training data supplier, and a finished decision-support product create different dependencies. Record the data supplied to the service, the people affected by outputs, the decisions a human may override, and whether the service can be interrupted safely.

ISO/IEC 42001 applies to organisations using AI as well as those providing it. The NIST AI RMF identifies third-party software, data, and supply-chain risk as a governance concern. Supplier assurance should therefore be proportional to the use case rather than a single checklist applied without context.

What should you ask the supplier?

Request a description of intended uses and limits, relevant model or service versions, data handling and retention, subprocessors, security practices, testing methods and results, known failure modes, human oversight options, incident contact, and change-notification process. For higher-impact uses, ask what evidence supports performance in conditions comparable to your deployment and what information the supplier can provide after an incident.

Record which answers are confirmed, qualified, unavailable, or contractually restricted. A supplier’s certificate or general security report may be useful, but check its scope and whether it addresses the AI function being purchased. Gaps can lead to narrower use, additional testing, contractual safeguards, or a decision not to deploy.

Test the integrated service in its own setting

Vendor tests may not cover your prompts, data, language, user population, retrieval sources, or downstream actions. Define acceptance criteria based on intended use and risk; evaluate the full application before launch; retain results and limitations; and specify who approves residual risk. Monitor quality, incidents, and user feedback after release.

Set review triggers for model changes, new features, changes to training or data use, outages, new subcontractors, and material contract changes. For critical uses, plan how to pause, switch, or fall back if the supplier fails. NIST’s AI RMF specifically addresses contingency processes for high-risk third-party AI failures.

What changes across markets?

For an EU-facing service, record the organisation’s role in the AI value chain and obtain the information needed from upstream providers; the European Commission explains that downstream providers may need documentation on general-purpose models’ capabilities and limitations. An ISO/IEC 42001 program can organise these requests, but EU AI Act obligations need their own system-specific assessment.

Australia’s National AI Centre guidance includes AI supply-chain accountability and risk treatment. In Singapore, AI Verify and local governance guidance may help plan suitable testing and process records. Keep these regional considerations linked to the same vendor and use-case record while preserving their distinct requirements and assessment outcomes.

Put it into practice

  • Describe the intended use, affected people, data, and fallback before selecting a supplier.
  • Request supplier evidence on limits, testing, data handling, changes, and incidents.
  • Test the integrated application against your own acceptance criteria.
  • Assign owners for monitoring, supplier changes, incidents, and suspension.
  • Map EU, Australian, Singaporean, and contractual duties separately where relevant.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources