ISO/IEC 42001 for AI Agents: Building an AI Management System

Last updated: 10 October 2026

ISO/IEC 42001 is the international standard for an artificial intelligence management system, commonly referred to as an AIMS.

The standard provides a management-system framework for organisations that develop, provide or use AI systems. For organisations deploying autonomous AI agents, the important concept is that AI governance should become an ongoing organisational process rather than a one-time technical exercise.

An AI management system needs mechanisms for establishing responsibilities, identifying risks, implementing controls, monitoring performance and improving the system over time. Autonomous AI agents make this particularly important because their behaviour can change depending on the task, data, tools, permissions, policies and operating environment.

A useful AI agent governance architecture therefore needs to connect:

AI policy
risk management
operational controls
monitoring
evidence
improvement

FirstHelm supports this operational layer through capabilities including missions, constraints, activity monitoring, approvals, interventions, analytics and audit trails. These capabilities can support an organisation's AI management system. They do not constitute ISO/IEC 42001 certification.

Why ISO 42001 matters for autonomous AI

Traditional AI governance often concentrates on the model. An autonomous agent requires a wider view. The deployed system may contain:

  • a foundation model
  • prompts
  • agent instructions
  • tools
  • APIs
  • databases
  • external services
  • permissions
  • business rules
  • human approvals
  • monitoring systems

The risk therefore belongs to the AI-enabled process, not simply the model. ISO/IEC 42001 provides a management-system perspective that is well suited to this problem. The organisation needs to understand:

  • what AI systems it operates
  • why they are used
  • who owns them
  • what risks they introduce
  • what controls apply
  • how those controls are monitored
  • how issues are addressed
  • how governance is continually improved

The AI management system lifecycle

A useful way to think about AI management is as a continuous cycle:

Plan
Do
Check
Act

This is particularly relevant to autonomous agents.

Plan

The organisation defines:

  • AI objectives
  • responsibilities
  • risks
  • policies
  • missions
  • constraints
  • approval requirements

Do

The controls operate in the real environment. Agents execute missions, constraints are evaluated and approval workflows are triggered when required.

Check

The organisation reviews:

  • activity
  • violations
  • interventions
  • costs
  • performance
  • approval activity
  • incidents
  • changes in risk

Act

The organisation adjusts the controls based on what it has learned. This may include:

  • changing constraints
  • modifying approval thresholds
  • adjusting autonomy
  • changing permissions
  • updating missions
  • introducing additional monitoring

This is the difference between a static AI policy and a functioning management system.

AI agent inventory and organisational context

One of the first practical requirements of effective AI governance is knowing what AI systems exist. An organisation may have agents operating across:

  • customer service
  • software engineering
  • sales
  • finance
  • research
  • operations
  • internal IT
  • compliance

Without an inventory, it becomes difficult to establish consistent governance. An AI agent inventory should ideally identify:

  • agent name
  • owner
  • purpose
  • framework
  • capabilities
  • connected systems
  • data access
  • autonomy
  • risk level
  • applicable policies
  • approval requirements

FirstHelm provides agent registration and central management so organisations can maintain visibility over the agents connected to the control plane.

AI risk management and agent constraints

Risk management needs to translate into operational controls. Suppose an organisation identifies the following risks:

  • excessive spend
  • unauthorised data access
  • unsafe external communications
  • production changes
  • excessive API usage

A governance framework can document these risks. A control system should also be capable of enforcing them. For example:

RiskOperational control
Excessive spendCost constraint
Unauthorised actionPermission and policy control
External communicationApproval gate
Production changeMandatory human approval
Excessive API activityRate or volume constraint

The important principle is that governance requirements should be connected to the system that actually executes the AI workflow — the constraints that bound the agent.

Human oversight and accountability

AI management requires clear responsibility. For autonomous agents, this means establishing who is responsible for:

  • approving high-risk actions
  • reviewing violations
  • changing policies
  • monitoring performance
  • responding to incidents
  • determining appropriate autonomy

Approval workflows can make some of these responsibilities explicit. A useful approval record identifies:

  • the proposed action
  • the agent
  • the risk level
  • the decision
  • the operator
  • the time
  • the reason
  • any modified payload

This creates a stronger accountability chain than an informal approval through chat or email.

Monitoring and continual improvement

An AI management system should not assume that controls are permanently correct. Agents evolve. Models change. Tools change. Business processes change. New risks emerge. Monitoring therefore needs to feed back into governance. For example:

Agent activity
Monitoring
Risk / violation detected
Review
Control changed
New operating behaviour
Monitoring

This feedback loop supports continual improvement. FirstHelm's activity logging and analytics provide operational information that can be used in this process.

Autonomy should be managed, not assumed

A particularly important governance question for AI agents is: How much autonomy should this agent have? An agent that successfully performs low-risk tasks may be suitable for more autonomy. An agent repeatedly violating constraints may require tighter controls.

This suggests that autonomy should be treated as a governance variable rather than simply a technical configuration. FirstHelm uses autonomy levels as part of its operating model, with agent history including success, failures and interventions informing how autonomy can be managed. The precise governance policy remains an organisational decision.

Evidence for an AI management system

Management-system governance depends on evidence. For AI agents, useful evidence may include:

  • inventory records
  • defined missions
  • constraints
  • policy decisions
  • approvals
  • interventions
  • violations
  • activity logs
  • performance metrics
  • review history

The objective is to demonstrate that the organisation has established controls and operates them consistently. A central audit trail makes this significantly easier than attempting to reconstruct evidence from multiple agent frameworks and application logs.

ISO 42001 and AI agent security

AI management and AI security overlap but are not identical. Security focuses heavily on protecting systems, data, identities and infrastructure. AI management covers a broader set of organisational issues including:

  • governance
  • roles
  • objectives
  • risk management
  • AI lifecycle processes
  • monitoring
  • accountability
  • continual improvement

An autonomous agent may therefore be technically secure while still lacking appropriate governance. For example, an agent could have encrypted credentials and strong authentication but still possess excessive autonomy for the task it performs. The management system needs to address both dimensions — see AI agent security in depth.

ISO 42001 and AI agent auditability

Auditability is essential because governance decisions should be demonstrable. Consider two organisations.

Organisation A says

"Our AI agents are subject to human oversight."

Organisation B can show

"Agent 14 attempted action X. The action triggered policy Y. Approval request Z was created. Operator A rejected it. The action was not executed."

Organisation B has much stronger operational evidence. This does not automatically establish certification or compliance, but it gives auditors, risk teams and management substantially better evidence to work with.

Implementing an AI management system for agents

A practical implementation can follow these stages.

Stage 1: InventoryIdentify all agents and AI-enabled workflows.
Stage 2: OwnershipAssign accountable owners.
Stage 3: Risk assessmentDetermine risks associated with each agent and its use case.
Stage 4: ControlsDefine constraints, permissions, approval gates and intervention procedures.
Stage 5: MonitoringRecord activity, violations, decisions and performance.
Stage 6: ReviewRegularly examine whether controls remain appropriate.
Stage 7: ImprovementUpdate governance based on operational evidence.

This creates a repeatable management cycle rather than a collection of disconnected AI policies.

ISO 42001 implementation checklist for AI agents

Ask:

  • Do we maintain an inventory of AI agents?
  • Does every agent have an accountable owner?
  • Is each agent's purpose documented?
  • Have AI-related risks been assessed?
  • Are controls linked to identified risks?
  • Are high-risk actions subject to appropriate approval?
  • Can agents be interrupted?
  • Are agent actions logged?
  • Are violations recorded?
  • Can management review operational evidence?
  • Are governance controls periodically reviewed?
  • Can the organisation demonstrate continual improvement?

How FirstHelm supports an AI management system

FirstHelm provides operational capabilities that can support an organisation's AI management system. These include:

  • agent inventory
  • missions
  • constraints
  • approvals
  • interventions
  • activity logs
  • analytics
  • autonomy management
  • audit exports

The platform's role is to provide a central control layer between autonomous agent activity and organisational governance. This is particularly useful where an organisation operates agents across multiple frameworks and wants governance controls to remain consistent — including interventions.

Frequently asked questions

Q: Is ISO 42001 specifically for AI agents?

A: ISO/IEC 42001 is an AI management-system standard rather than an AI-agent-specific standard. Its management principles can nevertheless be applied to organisations developing or using autonomous AI agents.

Q: Does ISO 42001 require an AI agent control plane?

A: The standard does not prescribe a particular software architecture. Organisations can implement controls using different technologies and processes.

Q: Does FirstHelm provide ISO 42001 certification?

A: No. FirstHelm provides capabilities that can support an AI management system and generate operational evidence. Certification requires an appropriate certification process performed by an authorised certification body.

Q: How does monitoring support ISO 42001?

A: Monitoring provides evidence about how AI systems operate in practice. For agents, this can include activity, violations, interventions, approvals and performance information.

Q: Why are constraints important for an AI management system?

A: Constraints turn governance requirements into operational rules that can influence agent behaviour at runtime.

Next steps

ISO/IEC 42001 provides a management-system approach to AI governance. For autonomous agents, the key is connecting organisational policy and risk management with the systems that actually control agent behaviour. Start with an AI inventory, assign ownership, identify risks, define controls, monitor operations and use evidence to improve the system over time.

Explore the broader AI agent governance model, audit trails, or FirstHelm's compliance overview. See the docs to get started.