ISO-42001-Visual-Library

September 8, 2026 Β· View on GitHub

License: MIT Cards Status Last commit

ISO 42001 Visual Library Banner

A collection of professional and humorous infographic cards to help you understand, remember, and explain ISO/IEC 42001.

Tip

nelsambrose.github.io/ISO-42001-Visual-Library β€” browse all cards in a clean, searchable page optimised for sharing.

Note

πŸ”“ Project Access

Free to use, share, or remix these cards in presentations, training, or anything else you wish to use them for. All cards in this repository were created by me and are released under the MIT Licence β€” free for any purpose, personal or commercial. Attribution is always appreciated but not required.

If you find them useful, consider leaving a ⭐ β€” it helps others find the library too.

87 cards and 32 written reference notes, covering Clauses 4–10 in full, all four Annex A domains, controls A.2 to A.10, the Audit Readiness mini-deck, and the six AI Principles. Actively maintained and still growing β€” see planned additions.


Click to expand Table of Contents

What this repository is

This repository is a practical visual library for learning and explaining ISO/IEC 42001:2023, the international standard for AI Management Systems (AIMS).

It is designed to make ISO 42001 easier to understand, remember, and explain through visual learning. The library combines professional and humorous infographic cards to support study, awareness, training, presentations, and audit preparation.

Why this exists

Most ISO 42001 material is dense or assumes prior knowledge. This library turns the standard into short visual cards designed for learning, communication, and memory.

How the library works

Each topic includes a professional card for clear explanation and sharing, and a funny card for memory and engagement. Some topics also include minimal memory cards focused on clause number and keyword recall.

These assets are learning aids and are not a replacement for the full ISO/IEC 42001:2023 standard.

Project structure and naming conventions are documented in CONTEXT.md.

Current coverage

The library currently covers the ISO 42001 overview, Domain cards, Control cards, Clauses 4 to 10, Annex A, the Audit Readiness, and AI Principles.

For Audit Readiness reference material, see the Audit Readiness reference index.

Planned additions

  • Expanded Annex A guidance and supporting visuals
  • Certification preparation
  • People impact and human oversight
  • ISO 42001 and ISO 27001 comparison
  • EU AI Act alignment
  • AI policy templates

New to ISO 42001? Work through the library in this order β€” each step assumes the one before it.

Click to expand

🧭 Start here

  1. ISO 42001 Overview β€” the whole standard on one card: the Plan–Do–Check–Act structure, the clause map, and where Annex A fits.
  2. Clause memory cards β€” lock in the clause numbers and their keywords before going deeper. Five minutes here saves a lot of confusion later.

πŸ“‹ The mandatory clauses (4–10)

  1. Clause 4 β€” Context of the Organisation β€” who is affected by your AI, what pressures shape it, and where the AIMS boundary sits.
  2. Clause 5 β€” Leadership β€” the AI policy, assigned accountability, and top management commitment.
  3. Clause 6 β€” Planning β€” AI risk assessment, AI system impact assessment, and measurable objectives.
  4. Clause 7 β€” Support β€” competence, awareness, communication, and documented information.
  5. Clause 8 β€” Operation β€” running the processes and retaining the evidence that they ran.
  6. Clause 9 β€” Performance Evaluation β€” monitoring, internal audit, and management review.
  7. Clause 10 β€” Improvement β€” nonconformities, corrective action, and continual improvement.

πŸ—‚οΈ Annex A controls

  1. Annex A domain overview β€” how Governance, Organisation, Operation, and Relationships divide the control set.
  2. A.2 Policies Related to AI β€” the anchor document auditors ask for first.
  3. A.5 Assessing Impacts of AI Systems β€” impact assessment, and why it is not the same as risk assessment.
  4. A.6 AI System Life Cycle β€” governance built into how systems are made.
  5. A.7 Data for AI Systems β€” quality and provenance, a frequent focus of audit attention.
  6. All nine controls, A.2 to A.10 β€” the full control set with cards and reference notes.

πŸŽ“ Getting audit-ready

  1. What an auditor actually looks for β€” what gets verified, and how.
  2. Evidence vs good intentions β€” the single largest source of audit findings.
  3. Common audit failure modes across Annex A β€” the patterns that repeat across organisations.

🧠 The underlying principles

  1. AI principles cards β€” fairness, transparency, accountability, human oversight, privacy, and safety and reliability.

Browse by category

Click to expand
CategoryCards
ISO 42001 overview2View β†—
Clause memory cards (quick recall)14View β†—
Clause cards, Clauses 4–1014View β†—
Annex A domain cards10View β†—
Annex A control cards, A.2–A.1018View β†—
Audit readiness cards10View β†—
AI principles cards12View β†—
Archive variants13View β†—

Tip

Click any card to open a full-size view. This is the easiest way to read the detail.

ISO 42001 Overview

ISO 42001 Overview - Professional Infographic


ISO 42001 Overview - Humorous Infographic

These overview cards show the complete ISO/IEC 42001:2023 AI Management System structure, covering mandatory clauses 4 to 10 and the optional Annex A controls.

ISO 42001 Clause Memory Cards

The simple memory cards are designed for quick recall. Each card reduces one clause to its core keyword. The professional simple cards use a clean minimal style. The funny simple cards use a strong visual hook.

These cards are intentionally simple. The goal is not to explain every sub-clause, but to make the main association easy to remember.

ISO 42001 Professional Simple Memory Cards

Clause 4Clause 5Clause 6
ISO 42001 Clause 4 Context of the Organisation - Professional Simple Memory Card
Context. Know your organisation, your interested parties, and the scope of your AIMS.
ISO 42001 Clause 5 Leadership - Professional Simple Memory Card
Leadership. Top management sets the AI policy and owns accountability for it.
ISO 42001 Clause 6 Planning - Professional Simple Memory Card
Planning. Assess AI risk and impact, then set measurable objectives.
Clause 7Clause 8Clause 9
ISO 42001 Clause 7 Support - Professional Simple Memory Card
Support. Competence, awareness, communication, and documented information.
ISO 42001 Clause 8 Operation - Professional Simple Memory Card
Operation. Run the processes, and keep the evidence that they ran.
ISO 42001 Clause 9 Performance Evaluation - Professional Simple Memory Card
Performance Evaluation. Monitor, audit internally, and review at management level.
Clause 10
ISO 42001 Clause 10 Improvement - Professional Simple Memory Card
Improvement. Fix nonconformities at the root and keep improving the system.

ISO 42001 Funny Simple Memory Cards

Clause 4Clause 5Clause 6
ISO 42001 Clause 4 Context of the Organisation - Humorous Simple Memory Card
Clause 4 as a visual hook β€” work out where you actually are before deciding where to go.
ISO 42001 Clause 5 Leadership - Humorous Simple Memory Card
Clause 5 as leadership imagery β€” somebody senior has to genuinely own AI governance.
ISO 42001 Clause 6 Planning - Humorous Simple Memory Card
Clause 6 as forward planning β€” what could go wrong, and what needs to go right.
Clause 7Clause 8Clause 9
ISO 42001 Clause 7 Support - Humorous Simple Memory Card
Clause 7 as the support layer β€” the skills, tools, and records that keep an AIMS running.
ISO 42001 Clause 8 Operation - Humorous Simple Memory Card
Clause 8 as day-to-day operation β€” governance applied to real systems, data, and users.
ISO 42001 Clause 9 Performance Evaluation - Humorous Simple Memory Card
Clause 9 as the check step β€” finding out whether any of it is actually working.
Clause 10
ISO 42001 Clause 10 Improvement - Humorous Simple Memory Card
Clause 10 as the improvement loop β€” learning from what went wrong and closing the gap.

Simple memory cards for ISO 42001 Clauses 4 to 10, designed for quick keyword recall in study, training, and awareness sessions.

ISO 42001 Clause Cards

Clauses 4–10 are the mandatory requirements of ISO 42001 - the standards that every organisation must implement. Unlike Annex A (which provides controls to select from), these clauses are non-negotiable. Each clause builds on the previous one, forming a management system cycle.

Topic Professional Funny
Clause 4
Context of the Organisation
Reference β†—

Establishes the foundation of the AI Management System. Before an organisation can govern AI it must understand itself: its purpose, its operating environment, the interested parties who can affect or be affected by its AI activities, and the boundaries within which the AIMS will operate. Clause 4 asks who is affected by your AI, what internal and external pressures shape it, and where the scope of the management system begins and ends. Nothing in Clauses 5 to 10 can be properly designed without this groundwork.
ISO 42001 Clause 4 Context of the Organisation - Professional Infographic ISO 42001 Clause 4 Context of the Organisation - Humorous Memory Card
Clause 5
Leadership
Reference β†—

Turns the AIMS from an idea into an organisational commitment. Clause 5 requires top management to actively lead AI governance, set direction through a documented AI policy, and ensure responsibilities and authorities are clearly assigned. ISO 42001 does not treat AI governance as something that can be delegated entirely to technical teams, compliance functions, or individual model owners. This is the clause where AI governance either gains real organisational authority and budget, or quietly stalls as a side project that nobody genuinely owns.
ISO 42001 Clause 5 Leadership - Professional Infographic ISO 42001 Clause 5 Leadership - Humorous Memory Card
Clause 6
Planning
Reference β†—

Where the organisation plans how the AIMS will address AI-related risk, opportunity, objectives and change. Clause 6 connects the context established in Clause 4 and the leadership direction set in Clause 5 to practical, risk-based governance. It asks the organisation to decide what could go wrong, what needs to go right, which measurable AI objectives it will pursue, and how changes to the management system will be controlled. Both AI risk assessment and AI system impact assessment originate here.
ISO 42001 Clause 6 Planning - Professional Infographic ISO 42001 Clause 6 Planning - Humorous Memory Card
Clause 7
Support
Reference β†—

Makes sure the AIMS has what it needs to work in practice. Clause 7 covers resources, competence, awareness, communication and documented information. This is the operational enablement layer: an AI policy and a risk process will not succeed unless people have the right skills, the right tools, clear communication channels and reliable records. The documented information requirements here are also where most audit evidence is eventually drawn from, so weak implementation of Clause 7 tends to surface later as missing evidence.
ISO 42001 Clause 7 Support - Professional Infographic ISO 42001 Clause 7 Support - Humorous Memory Card
Clause 8
Operation
Reference β†—

Where the AIMS moves from planning into controlled operation. Clause 8 requires the organisation to operate the processes needed to meet AIMS requirements, manage AI risk, carry out AI system impact assessments, and control operational change. This is the practical delivery layer of ISO 42001, where governance is applied to real AI systems, real users, real data and real organisational decisions. It also requires retaining documented evidence that those processes actually ran as planned, not merely that they exist on paper.
ISO 42001 Clause 8 Operation - Professional Infographic ISO 42001 Clause 8 Operation - Humorous Memory Card
Clause 9
Performance Evaluation
Reference β†—

Checks whether the AIMS is actually working. Clause 9 requires the organisation to monitor, measure, analyse and evaluate AIMS performance, conduct internal audits, and hold management reviews at planned intervals. This is the evidence loop: it establishes what gets measured, who checks it independently of the people doing the work, and how top management formally reviews whether the system remains suitable, adequate and effective. Internal audit findings raised under this clause feed directly into the corrective action required by Clause 10.
ISO 42001 Clause 9 Performance Evaluation - Professional Infographic ISO 42001 Clause 9 Performance Evaluation - Humorous Memory Card
Clause 10
Improvement
Reference β†—

Makes continual improvement a permanent part of the AIMS. Clause 10 requires the organisation to respond to nonconformities, take corrective action that addresses root causes rather than symptoms, and improve the suitability, adequacy and effectiveness of the management system over time. This clause is about learning. AI systems, risks, regulations, stakeholders and use cases all change quickly, so an AIMS that cannot adapt will steadily drift out of alignment with the organisation it is meant to govern.
ISO 42001 Clause 10 Improvement - Professional Infographic ISO 42001 Clause 10 Improvement - Humorous Memory Card

Full infographic cards for ISO 42001 Clauses 4 to 10 β€” the mandatory requirements every organisation must implement to achieve ISO/IEC 42001:2023 certification.

Annex A is the operational core of ISO 42001. It contains controls across nine areas (A.2–A.10) that define what responsible AI management looks like in practice.

ISO 42001 Annex A Domain Cards

These controls are grouped into four non-compulsory domains, and can be selected based on the organisation's AI risks, context, and objectives:

  • Governance - Establishing AI policies, leadership accountability, and the overall direction for responsible AI within the organisation.
  • Organisation - Defining internal roles and responsibilities, ensuring the right people, skills, and resources are in place to manage AI effectively.
  • Operation - Managing the full AI system lifecycle: from design and data management through deployment, monitoring, and decommissioning.
  • Relationships - Governing how the organisation works with third parties, customers, and other stakeholders who develop, supply, or are affected by AI systems.
Professional Funny
ISO 42001 Annex A Overview - Professional Domain Infographic ISO 42001 Annex A Overview - Humorous Domain Infographic

ISO 42001 Annex A groups controls across four domains: Governance, Organisation, Operation, and Relationships.

Domain Professional Funny
Governance
Reference β†—

Establishes the policies, leadership accountability and organisational direction needed for responsible AI management. The Governance domain sets the tone from the top and ensures that AI-related commitments are documented, communicated and owned by named people. Without these controls an organisation may develop or deploy AI with no clear principles, no defined accountability, and no shared understanding of what responsible AI actually means in its particular context. This is typically the first domain an auditor examines, because everything else depends on it.
ISO 42001 Annex A Governance - Professional Domain Infographic ISO 42001 Annex A Governance - Humorous Domain Infographic
Organisation
Reference β†—

Ensures the right people, skills and resources are in place to manage AI responsibly. The Organisation domain translates Governance-level policy into operational capability: who does what, with what competence, and supported by what resources. It is the bridge between stated intent and the ability to act on it. Organisations frequently write a strong AI policy and then fall down here, leaving controls formally assigned but unresourced β€” a pattern that shows up quickly once an auditor asks who actually performs them.
ISO 42001 Annex A Organisation - Professional Domain Infographic ISO 42001 Annex A Organisation - Humorous Domain Infographic
Operation
Reference β†—

Covers the full lifecycle of AI systems, from design and data management through development, deployment, monitoring and eventual decommissioning. This is the largest domain in Annex A and where most of an organisation's AI risk is either actively managed or quietly left unaddressed. The majority of day-to-day AI governance work sits here, and it is where the gap between documented process and actual practice tends to be widest, which makes it a consistently rich source of audit findings.
ISO 42001 Annex A Operation - Professional Domain Infographic ISO 42001 Annex A Operation - Humorous Domain Infographic
Relationships
Reference β†—

Governs how the organisation manages AI-related obligations with third parties, customers, and others who develop, supply, deploy or are affected by AI systems. AI systems rarely exist in isolation: they depend on data from suppliers, infrastructure from cloud providers, and models from third-party vendors. This domain ensures those dependencies are governed rather than assumed, and that responsibility for AI outcomes is explicitly allocated wherever a system crosses an organisational boundary and ownership could otherwise fall between two parties.
ISO 42001 Annex A Relationships - Professional Domain Infographic ISO 42001 Annex A Relationships - Humorous Domain Infographic

Domain-level cards for ISO 42001 Annex A, covering governance, organisation, operation, and relationship controls for responsible AI management.

ISO 42001 Annex A Control Cards

Annex A controls are recommended governance measures that help organisations manage AI systems responsibly across the areas mentioned below.

Control Professional Funny
A.2 Policies Related to AI
Reference β†—

Requires the organisation to establish and maintain policies defining its approach to responsible AI. Policies are the written foundation for everything else: they define what the organisation stands for, what is permitted and what is not, and they must align with business strategy and other organisational policies. A.2 also requires review at planned intervals. This is the anchor document auditors ask for first, and a policy carrying no evidence of having been reviewed is a very common early finding.
ISO 42001 Annex A.2 Policies Related to AI - Professional Control Card ISO 42001 Annex A.2 Policies Related to AI - Humorous Control Card
A.3 Internal Organisation
Reference β†—

Requires the organisation to define and assign AI governance roles, responsibilities and authorities, and to establish how concerns are reported and escalated. A.3 ensures somebody is accountable for every significant AI decision, and that AI governance is not treated as a shared but ultimately unowned responsibility. In practice this means naming individuals rather than teams, because an auditor asking who owns a given control needs an answer that resolves to a person who can be interviewed.
ISO 42001 Annex A.3 Internal Organisation - Professional Control Card ISO 42001 Annex A.3 Internal Organisation - Humorous Control Card
A.4 Resources for AI Systems
Reference β†—

Requires the organisation to ensure sufficient and appropriate resources support the development, deployment, operation and governance of AI systems β€” data, tooling, computing resources, human resources and system components. Responsible AI management cannot happen without the people, tools and investment to make it real. Documenting these dependencies serves a second purpose too: understanding what an AI system actually relies on is the necessary basis for assessing what can go wrong with it and where.
ISO 42001 Annex A.4 Resources for AI Systems - Professional Control Card ISO 42001 Annex A.4 Resources for AI Systems - Humorous Control Card
A.5 Assessing Impacts of AI Systems
Reference β†—

Requires the organisation to assess the potential impacts of AI systems, including intended benefits and unintended harms, before deployment and throughout the system's lifecycle. Impact assessment is the mechanism by which AI risk is made visible and manageable. It is deliberately distinct from risk assessment: risk assessment looks inward at what threatens the organisation, while impact assessment looks outward at consequences for individuals, groups and society. Conflating the two is a frequent source of audit findings.
ISO 42001 Annex A.5 Assessing Impacts of AI Systems - Professional Control Card ISO 42001 Annex A.5 Assessing Impacts of AI Systems - Humorous Control Card
A.6 AI System Life Cycle
Reference β†—

Requires the organisation to manage AI systems across their full lifecycle β€” from initial concept and design through development, testing, deployment, operation, monitoring and eventual decommissioning. Each stage carries distinct risks needing specific controls, so governance has to be built into how systems are made rather than bolted on shortly before launch. Decommissioning is the stage most often overlooked, yet retired models and their training data frequently remain accessible long after anyone is actively maintaining them.
ISO 42001 Annex A.6 AI System Life Cycle - Professional Control Card ISO 42001 Annex A.6 AI System Life Cycle - Humorous Control Card
A.7 Data for AI Systems
Reference β†—

Requires the organisation to manage the data used in AI systems responsibly, covering quality, provenance, preparation and acquisition. Data is the foundation of AI performance: poor quality, biased or inappropriately sourced data leads directly to unreliable or harmful outputs, and no amount of downstream governance fully compensates for it. Because AI behaviour is largely inherited from its training data, this control attracts sustained audit attention, particularly around whether provenance can actually be demonstrated rather than assumed.
ISO 42001 Annex A.7 Data for AI Systems - Professional Control Card ISO 42001 Annex A.7 Data for AI Systems - Humorous Control Card
A.8 Information for Interested Parties
Reference β†—

Requires the organisation to provide appropriate information about its AI systems to relevant stakeholders. Transparency about how a system works, what decisions it influences, what its limitations are, and what recourse exists is a core component of responsible AI governance. A.8 covers documentation, incident reporting, and communication of both capabilities and limitations. It is the control most directly connected to the transparency principle, and increasingly to external regulatory expectations such as the EU AI Act.
ISO 42001 Annex A.8 Information for Interested Parties - Professional Control Card ISO 42001 Annex A.8 Information for Interested Parties - Humorous Control Card
A.9 Use of AI Systems
Reference β†—

Requires the organisation to ensure AI systems are used within their intended purpose, with appropriate controls applied when they are. A.9 covers defining intended use, ensuring systems are used in line with policy, and monitoring for misuse or for use outside the intended context. Critically, organisations that use third-party AI rather than building their own cannot transfer accountability by pointing at the supplier: the obligation to govern how a system is used stays with the user.
ISO 42001 Annex A.9 Use of AI Systems - Professional Control Card ISO 42001 Annex A.9 Use of AI Systems - Humorous Control Card
A.10 Third-party and Customer Relationships
Reference β†—

Requires the organisation to manage AI-related obligations with third parties and customers, including supplier due diligence, contractual requirements, and ensuring that AI systems provided to customers are fit for purpose and responsibly governed. This control allocates responsibility across the AI supply chain so obligations, expectations and risks are understood and documented wherever a system crosses an organisational boundary. Gaps here usually surface as assumptions, with each party believing the other was handling a given control.
ISO 42001 Annex A.10 Third-Party and Customer Relationships - Professional Control Card ISO 42001 Annex A.10 Third-Party and Customer Relationships - Humorous Control Card

Control-level cards covering ISO 42001 Annex A controls A.2 through A.10, from AI policies and internal organisation to third-party and customer relationships.

ISO 42001 Audit Readiness Cards

These five cards help you prepare for ISO 42001 audits. They cover what auditors actually look for, the difference between strong and weak evidence, common failure patterns across Annex A, and how to talk about controls confidently.

Reference files available for all five cards. See the Audit Readiness reference index for an overview.

Card Professional Funny
Audit-01
What an Auditor Actually Looks For
Reference β†—

Explains the auditor mindset: what an auditor is assessing, how they think about evidence, and what they are trying to establish when examining an AI management system. Auditors verify that controls are defined, operating and maintained, and that you can demonstrate all three. Understanding this shifts preparation away from producing more documentation and towards being able to show that documented processes actually ran, were reviewed, and left records somebody independent can check.
ISO 42001 Audit Readiness - What an Auditor Actually Looks For Professional Infographic ISO 42001 Audit Readiness - What an Auditor Actually Looks For Humorous Infographic
Audit-02
Evidence vs Good Intentions
Reference β†—

Explains why good intentions, verbal assurances and planned actions carry very little weight in an audit. "We always check that before deployment" is an intention; an approved policy with a version number, date and named owner, or a completed checklist showing the check was carried out, is evidence. Evidence is tangible, can be pointed to, and does not require the auditor to take your word for it. The gap between intention and evidence is where audit findings are born.
ISO 42001 Audit Readiness - Evidence vs Good Intentions Professional Infographic ISO 42001 Audit Readiness - Evidence vs Good Intentions Humorous Infographic
Audit-03
Strong Versus Weak Evidence Examples
Reference β†—

Gives practical, grounded examples of what weak, better and strong evidence looks like across the key Annex A control areas, so practitioners can assess and improve the quality of their own evidence before an audit rather than during one. Seeing the same control evidenced three different ways makes the difference concrete: the progression usually runs from "we have a document", to "the document is current and owned", to "here is the record of it being applied".
ISO 42001 Audit Readiness - Strong vs Weak Evidence Examples Professional Infographic ISO 42001 Audit Readiness - Strong vs Weak Evidence Examples Humorous Infographic
Audit-04
Common Audit Failure Modes Across Annex A
Reference β†—

Identifies the recurring patterns that weaken audit confidence across Annex A: controls selected in the Statement of Applicability but never actually operated, documentation with no evidence of review, ownership assigned to a team rather than a named person, and gaps between what the SoA claims and what happens in practice. Recognising these before an audit is far cheaper than having an auditor find them, since each one typically generates a nonconformity requiring corrective action.
ISO 42001 Audit Readiness - Common Audit Failure Modes Professional Infographic ISO 42001 Audit Readiness - Common Audit Failure Modes Humorous Infographic
Audit-05
How to Talk About Controls Confidently
Reference β†—

Helps practitioners communicate clearly and honestly about controls during an audit conversation, covering what the control is, who owns it, how it operates, what evidence exists, and how it is reviewed and improved. The aim is neither over-claiming nor underselling genuine work. Auditors respond well to a structured, factual answer that acknowledges limitations, and poorly to vague reassurance, so knowing the shape of a good answer in advance materially changes how an interview goes.
ISO 42001 Audit Readiness - How to Talk About Controls Confidently Professional Infographic ISO 42001 Audit Readiness - How to Talk About Controls Confidently Humorous Infographic

ISO 42001 audit readiness cards covering auditor expectations, evidence standards, common Annex A failure patterns, and how to communicate controls confidently.

ISO 42001 AI Principles Cards

The AI Principles Cards explain core responsible AI concepts that support practical AI governance and AI Management System thinking. They cover fairness, transparency, accountability, human oversight, privacy, and safety and reliability. Each principle is shown as a professional card for clear explanation and a funny card for memory and engagement.

These cards are learning aids. They do not add new ISO/IEC 42001 requirements and should not be treated as a replacement for the official standard.

Principle Professional Funny
Principle-01
Fairness
Reference β†—

Fairness in AI means systems should treat people equitably and avoid producing biased or discriminatory outcomes. It requires organisations to consider how AI decisions may affect different groups, and to take active steps to identify and reduce unfair bias throughout the AI lifecycle. In practice this is harder than it sounds: competing mathematical definitions of fairness cannot all be satisfied at once, so organisations must decide which applies in their context and be able to justify that choice.
ISO 42001 AI Principles - Fairness - Professional Infographic ISO 42001 AI Principles - Fairness - Humorous Infographic
Principle-02
Transparency
Reference β†—

Transparency means being open about how AI systems work, what data they use, and how decisions are reached. Organisations should be able to explain AI behaviour in terms that are meaningful to the people affected by it, even when the underlying models are complex. It also covers whether someone knows they are interacting with an AI system at all. Transparency builds stakeholder trust and directly underpins the Annex A.8 obligations to inform interested parties.
ISO 42001 AI Principles - Transparency - Professional Infographic ISO 42001 AI Principles - Transparency - Humorous Infographic
Principle-03
Accountability
Reference β†—

Accountability means clear lines of responsibility exist for AI systems and their outcomes. Organisations should be able to identify who is responsible for each AI system at every lifecycle stage, from design and deployment through to decommissioning. Responsibility rests with identifiable people and organisations, never with the system itself. This principle underpins the governance structure of an AIMS, and it is what makes traceability from an outcome back to the decision that caused it possible at all.
ISO 42001 AI Principles - Accountability - Professional Infographic ISO 42001 AI Principles - Accountability - Humorous Infographic
Principle-04
Human Oversight
Reference β†—

Human oversight means people retain meaningful control over AI systems and the decisions they influence. Organisations should design systems so humans can intervene, correct or override outputs, particularly in high-stakes contexts. The word that carries the weight is "meaningful": oversight is not satisfied by a nominal reviewer who lacks the authority, information or time to actually intervene. This principle keeps AI systems as tools that support human judgement rather than quietly replacing it.
ISO 42001 AI Principles - Human Oversight - Professional Infographic ISO 42001 AI Principles - Human Oversight - Humorous Infographic
Principle-05
Privacy
Reference β†—

Privacy in AI means protecting personal data throughout the AI lifecycle, from collection and model training through to deployment and decommissioning. Organisations should apply data minimisation, purpose limitation and appropriate safeguards wherever personal data is used. AI introduces privacy risks beyond conventional data processing: models can re-identify individuals from supposedly anonymous data, infer sensitive attributes that were never collected, and memorise training examples that can later be extracted from their outputs.
ISO 42001 AI Principles - Privacy - Professional Infographic ISO 42001 AI Principles - Privacy - Humorous Infographic
Principle-06
Safety and Reliability
Reference β†—

Safety and reliability mean AI systems should perform as intended, remain stable under varied conditions, and not cause unintended harm. Organisations should test systems thoroughly, monitor their behaviour in production, and have processes ready for when systems fail or behave unexpectedly. Reliability includes degrading predictably rather than failing silently, and detecting drift as real-world conditions diverge from training conditions. A system that cannot be relied upon cannot be responsibly deployed.
ISO 42001 AI Principles - Safety and Reliability - Professional Infographic ISO 42001 AI Principles - Safety and Reliability - Humorous Infographic

AI principles cards covering the core responsible AI concepts that underpin ISO/IEC 42001:2023 governance: fairness, transparency, accountability, human oversight, privacy, and safety and reliability.


ISO 42001 Additional Variants

These are earlier infographic cards that have since been superseded by the current card designs, but the content remains accurate. Feel free to use any of these if you prefer the format.

ISO 42001 Archive - Manage AI Like a Boss Variant Card
An earlier all-in-one ISO 42001 overview card, framed as β€œmanage AI like a boss”.

ISO 42001 Archive - Clause 8 Operation Variant Card
Earlier Clause 8 Operation design, superseded by the current clause card.
ISO 42001 Archive - Clause 10 Improvement Variant Card
Earlier Clause 10 Improvement design, covering corrective action and continual improvement.
ISO 42001 Archive - Clause 8 Operation Mission Control Variant Card
Clause 8 Operation using a mission-control framing for the operational delivery layer.
ISO 42001 Archive - A.5 Assessing Impact of AI Systems Variant Card
Earlier Annex A.5 card on assessing the impacts of AI systems on people and society.
ISO 42001 Archive - Annex A Domain Operation Variant Card
Earlier overview of the Annex A Operation domain and the AI system lifecycle it covers.
ISO 42001 Archive - Clause 9 Performance Evaluation Variant 2 Card
Clause 9 Performance Evaluation, second design iteration.
ISO 42001 Archive - Clause 9 Performance Evaluation Variant 3 Card
Clause 9 Performance Evaluation, third design iteration.
ISO 42001 Archive - Clause 7 Support Variant Card
Earlier Clause 7 Support design, covering resources, competence, and documented information.
ISO 42001 Archive - Clause 9 Performance Evaluation Variant 1 Card
Clause 9 Performance Evaluation, first design iteration.
ISO 42001 Archive - Clause 5 Leadership Variant Card
Earlier Clause 5 Leadership design, covering the AI policy and management accountability.
ISO 42001 Archive - A.10 Third-Party and Customer Relationships Variant Card
Earlier Annex A.10 card on third-party, supplier, and customer relationships.
ISO 42001 Archive - Clause 9 Performance Evaluation Variant Card
Clause 9 Performance Evaluation, original design.

Earlier ISO 42001 infographic card variants covering Clause 8 Operation, Clause 9 Performance Evaluation, Clause 10 Improvement, Annex A.5, Annex A.10, and the Annex A domain overview.

Community Recognition

This repository has been included in the following curated AI governance and responsible AI resource lists:

Licence

This work is released under the MIT Licence. See LICENSE.md for the full terms.

You are free to use, copy, modify, and distribute these cards for any purpose, personal or commercial. Attribution is not required, but is always appreciated:

ISO 42001 Visual Library by Nelson Ambrose β€” https://github.com/nelsambrose/ISO-42001-Visual-Library

Creator: Nelson Ambrose

If you find these useful, please leave a ⭐

Disclaimer

This repository is an independent learning resource. It is not affiliated with, endorsed by, or certified by ISO, IEC, or any certification body.

The materials are intended as learning aids and should not be treated as a replacement for the official ISO/IEC 42001:2023 standard, legal advice, audit advice, or certification guidance.

About the Author

A personal visual overview of the author's AI governance focus and role in building the library.

ISO 42001 Visual Library - Author Overview - Nelson Ambrose AI Governance