ISO 42001 for Boards: The Operational Companion to Caremark
ISO 42001 for Boards: The Operational Companion to Caremark
BoardSight Analysis · Reading time: ~9 minutes Category: Thought Leadership · Published April 16, 2026 · Updated July 2026 · Author: James Waddell, Cognitive Corp
This is BoardSight's analysis, not legal advice. Sources are listed at the end. Where a claim about the standard's legal or market status is often overstated, we say what is actually established.
Abstract
ISO/IEC 42001 — the first international management-system standard for artificial intelligence — was published in December 2023 and moved into the certification market in 2024. It does for AI governance what ISO 27001 did for information security: it turns a board-level duty into an auditable management system. This brief makes the case that ISO 42001 is a useful board-level instrument, because its Annex A controls and its plan-do-check-act (PDCA) cycle map cleanly onto the Caremark question — is there a system, and is it working? It also corrects three claims that are frequently made about the standard and are not (yet) supported: that ISO 42001 is the EU AI Act's route to presumption of conformity, that insurers price against it, and that plaintiffs plead it as the standard of care.
1. Why ISO 42001 is board-relevant — accurately stated
ISO 42001 was published in December 2023 and began attracting certifications in 2024. Its board relevance is real, but it is worth being precise about why, because the standard is often oversold.
Standards bodies and governments reference it — verifiably. NIST published an official crosswalk mapping its AI Risk Management Framework to ISO/IEC 42001. The UK's Department for Science, Innovation and Technology cites ISO 42001 in its Introduction to AI Assurance. Singapore's AI Verify Foundation published a crosswalk between AI Verify and ISO 42001. These are real, published references that make ISO 42001 an interoperable point of comparison across regimes.
On the EU AI Act — a common overstatement, corrected. It is often said that the EU AI Act “leans on ISO 42001 as the presumed-conformity route.” That is not accurate. The AI Act does use harmonized standards for a presumption of conformity (Article 40) — but the harmonized standards are being developed by CEN-CENELEC's JTC 21 as EU-specific standards (for example, the draft prEN 18286, a quality-management standard for AI Act purposes), not by adopting ISO 42001. Those European standards are not yet finalized — the original April 2025 delivery date was missed, and the first batch is expected around or after the high-risk obligations take effect in 2026, covering the Act's requirements only in part. So ISO 42001 is a complementary international standard that helps you prepare; it is not, by itself, the EU route to presumption of conformity. Boards should not assume certification equals AI Act compliance.
On insurers and plaintiffs — emerging, not established. Two further claims are commonly made and are currently unsupported by public evidence: that D&O/cyber insurers embed ISO 42001 conformance in underwriting, and that plaintiff counsel plead ISO 42001 as the standard of care. Governance analysts report they are not aware of insurers tying premiums to ISO 42001 today, and we are not aware of a filed complaint that cites it as the standard of care. Both may come — the standard is a natural reference point — but they are forward-looking, not present facts, and we frame them that way.
What remains, stated conservatively, is enough: ISO 42001 is the most widely recognized procedural backbone for AI governance, referenced by NIST, the UK, and Singapore, and structured in a way that maps directly onto a board's oversight duty.
2. What ISO 42001 actually requires
The standard follows the same Annex SL structure as ISO 27001: a management system defined by a PDCA cycle, mandatory Clauses 4 through 10, and an Annex A control set the organization must evaluate for applicability.
The mandatory clauses establish: Context (4) — issues, interested parties, and the scope of the AI management system; Leadership (5) — top-management commitment, an AI policy, and assigned roles and authorities; Planning (6) — risks, opportunities, and measurable objectives; Support (7) — resources, competence, awareness, communication, documentation; Operation (8) — AI system impact assessments, lifecycle controls, data and third-party management; Performance evaluation (9) — monitoring, internal audit, and management review; and Improvement (10) — nonconformity handling and continual improvement. Annex A adds 38 controls across nine control categories (A.2–A.10), from AI policy and internal organization through impact assessment, data, and third-party relationships.
A precision point often gotten wrong: ISO management-system standards direct their leadership duties at “top management,” defined as whoever “directs and controls the organization at the highest level.” That is scope-relative, and ISO 42001 does not explicitly name the board or governing body. Where the AI management system is enterprise-wide, “top management” reaches the board in substance — but directors should not be told the standard “names” them; it reaches them by function, not by title.
3. The Caremark mapping
Delaware's Caremark line holds that boards must make a good-faith effort to implement a reasonable information-and-reporting system for material risks, and then monitor it. Marchand v. Barnhill (Del. 2019) and In re Boeing Co. Derivative Litigation (Del. Ch. 2021) sharpened the duty for “mission-critical” risks. For many issuers — banks, insurers, healthcare systems, critical-infrastructure operators — AI is becoming exactly that.
The Caremark duty has two prongs, and ISO 42001 helps with both. Is there a system? The management system is the system; the PDCA cycle is the monitoring regime; Annex A controls are the reporting lattice. Is it working? Clause 9.3 management reviews, Clause 9.2 internal audits, and Clause 10.1 corrective actions produce the documentary trail that shows monitoring occurred and red flags were addressed. The standard does not displace Caremark; it operationalizes it. Whether a given board's AI use is “mission-critical” remains company-specific and fact-intensive.
4. What directors should actually read
Four documents per cycle are enough to maintain a defensible posture:
The AI Policy (Clause 5.2) — one page, board-approved, current: the organization's stance on AI use, risk tolerance, prohibited uses, and the chain of accountability. The AI System Inventory (Annex A) — a catalog of AI systems built, deployed, or consumed from third parties, classified by risk tier. The most recent Management Review (Clause 9.3) — findings, nonconformities, incident trends, effectiveness measures: the document that answers “is it working.” The Statement of Applicability — which Annex A controls apply, which do not, and why: the clearest single view of the organization's governance posture. Four documents, about an hour of preparation per cycle.
5. Where ISO 42001 does not reach
The standard is a management-system specification, not a risk-tier definition and not an ethics framework. It requires an impact-assessment methodology but does not prescribe one; it does not set fairness thresholds, bias metrics, or acceptable error rates. For boards that is both a feature (domain-agnostic) and a gap (it tells you whether thresholds exist and are tracked, not whether they are the right thresholds). A well-oriented board pairs ISO 42001 as the procedural backbone with a domain-appropriate substantive lens — NIST AI RMF for broad enterprise AI, sector guidance for regulated industries, and Cognitive Corp's Building Constitution for facilities and physical-infrastructure AI. Procedure without substance is conformance theater; substance without procedure is unenforced policy.
6. The board's ISO 42001 question bank
Five questions a board should be able to answer, backed by documents:
- Scope — which AI systems, business units, and lifecycle stages are in the management system, and which are deliberately out?
- Classification — how do we classify AI risk, and what tier are our mission-critical systems in?
- Monitoring — when was the last management review, what did it find, and what corrective actions are open?
- Competence — does the board's own composition support credible AI oversight, and if not, what is the remediation plan?
- Third parties — which vendors provide or embed AI, and are they covered by the controls we apply to our own systems?
7. Implication for BoardSight clients
BoardSight's engagement sequence — audit, advisory, execution — maps onto the ISO 42001 cycle. The 90-day Board AI Oversight Audit produces a conformance posture, a gap analysis, and a prioritized remediation plan in the language of Clauses 4–10 and the Statement of Applicability; advisory drives the system into operation; execution support runs the PDCA cycle through management reviews the board can stand behind. The value is a defensible, documented oversight posture — not a certificate for its own sake.
Sources
- ISO/IEC 42001:2023 (overview): https://www.iso.org/standard/42001
- Annex A controls (38 across 9 categories): https://www.isms.online/iso-42001/annex-a-controls/
- EU AI Act — standard-setting / presumption of conformity (Art. 40) status: https://artificialintelligenceact.eu/standard-setting-overview/
- prEN 18286 vs. ISO 42001 (EU harmonized standard is distinct): https://www.schellman.com/blog/ai-governance/how-pren-18286-aligns-with-iso-42001-for-eu-ai-act-compliance
- NIST AI RMF → ISO/IEC 42001 crosswalk: https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf
- UK DSIT, Introduction to AI Assurance (cites ISO 42001): https://assets.publishing.service.gov.uk/media/65ccf508c96cf3000c6a37a1/Introduction_to_AI_Assurance.pdf
- Singapore AI Verify Foundation – ISO 42001 crosswalk: https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Crosswalk-AIV-and-ISO42001-final.pdf
- Insurers not yet pricing ISO 42001 (analysis): https://blog.stackaware.com/p/cyber-insurance-ai-governance-iso-42001-nist-rmf
- Case law: In re Caremark Int'l, 698 A.2d 959 (Del. Ch. 1996); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); In re Boeing Co. Derivative Litig., 2021 WL 4059934 (Del. Ch. 2021).