DoAIRight
ISO/IEC 42001

AI Provider vs AI User: ISO 42001 Role Obligations

PUBLISHED 06 AUG 2026

Under ISO/IEC 42001:2023, an organization's specific AI Management System (AIMS) obligations depend heavily on whether it operates as an AI provider (building, training, or selling AI systems) or an AI user (deploying third-party AI into its operational processes). While both roles must establish foundational governance—such as executive leadership, risk management, and continuous improvement—their practical Annex A controls diverge. AI providers face extensive requirements regarding model design, data governance, and system transparency (Annex A.6, A.7, and A.8). Conversely, AI users focus on acceptable operational use, monitoring, human oversight, and managing third-party vendor risks (Annex A.9 and A.10).

Defining Your Position in the AI Value Chain

Clause 4 of ISO/IEC 42001 requires organizations to understand their external and internal context, including their specific placement within the AI value chain. Identifying your role isn't just a technical detail—it dictates the scope of your Statement of Applicability (SoA) and determines which Annex A risk controls apply.

  • AI Provider: An entity that develops, builds, tunes, or provides AI products, models, or services to external clients or internal end-users.
  • AI User (Deployer): An entity that uses or integrates an AI system within its business operations to support decision-making, automate tasks, or serve end customers.

Many modern enterprises act in both capacities simultaneously—customizing vendor models while building proprietary internal tools. Establishing clarity around these ISO 42001 roles is the essential first step toward audit readiness.

Specific Obligations for AI Providers

AI providers bear primary technical responsibility for the integrity, safety, and transparency of the AI artifacts they build and distribute. Key operational focuses under ISO 42001 Annex A include:

  • AI System Life Cycle Management (Annex A.6): Implementing disciplined controls across design, development, verification, validation, deployment, and maintenance.
  • Data for AI Systems (Annex A.7): Ensuring data quality, relevance, bias mitigation, provenance tracking, and regulatory alignment throughout training and testing pipelines.
  • Information for Interested Parties (Annex A.8): Supplying accurate system documentation, user manuals, performance limits, known risks, and system capability declarations to end-users.
  • Impact Assessments (Annex A.5): Evaluating system impacts on individuals, specific societal groups, and society as a whole across intended and unintended use cases.

Specific Obligations for AI Users

Organizations that license or deploy AI software are not exempt from ISO 42001 requirements. AI users must verify that tools are used safely, ethically, and in alignment with organizational boundaries. Key control domains include:

  • Use of AI Systems (Annex A.9): Establishing acceptable use policies, human oversight mechanisms, continuous operational monitoring, and protocols for identifying model drift or anomalous behavior.
  • Third-Party and Customer Relationships (Annex A.10): Evaluating and auditing AI suppliers, establishing clear SLA expectations, verifying vendor compliance statements, and managing supply-chain dependencies.
  • Contextual Impact Assessment (Annex A.5): Assessing how deploying the AI tool within a specific operational environment impacts employees, customers, data privacy, and broader society.

Shared Governance Obligations Across All Roles

Regardless of your position on the AI value chain, Clauses 4 through 10 of ISO/IEC 42001 require a foundational management structure that applies universally:

  1. Leadership & Policy (Clause 5): Top management must demonstrate ownership, assign AI roles, and establish an organizational AI Policy (Annex A.2).
  2. Risk & Opportunity Planning (Clause 6): Organizations must proactively identify AI-specific risks, set measurable AI objectives, and plan actions to address potential failures.
  3. Support & Resources (Clause 7): Providing adequate infrastructure, staff competence, awareness training, and documented information.
  4. Operational Control (Clause 8): Running controls consistently and keeping risk and impact assessments up to date.
  5. Performance Evaluation & Improvement (Clauses 9 & 10): Measuring system outcomes, conducting internal audits, performing management reviews, and fixing root causes when nonconformities arise.

Streamlining Your Role-Based AIMS Implementation

Navigating whether your controls should reflect provider duties, user responsibilities, or a hybrid of both can complicate implementation. To clarify your obligations, leverage DoAIRight’s free readiness assessment. DoAIRight helps your team map out your AI value chain position, select applicable controls, and organize documentation to become fully certification-ready.

Keep in mind that while readiness tools prepare your organization for evaluation, official ISO/IEC 42001 certification is awarded exclusively by accredited third-party certification bodies after an independent audit conducted under ISO/IEC 42006 guidelines.

Frequently asked

Can an organization be both an AI provider and an AI user under ISO 42001?

Yes. Organizations that develop proprietary AI tools for external customers while also deploying third-party AI software internally act as both providers and users. In this case, both sets of controls (Annex A.6–A.8 and A.9–A.10) apply within their respective operational contexts.

How do AI impact assessments differ for providers versus users?

Providers assess broader system capabilities, potential downstream misuses, algorithmic bias, and systemic societal risks during design. Users focus on context-specific impacts, such as how operational deployment affects local workforce dynamics, end-user privacy, and domain-specific decision outcomes.

Does using an ISO 42001-certified AI provider make the AI user automatically compliant?

No. While using a certified provider helps satisfy third-party management requirements (Annex A.10), AI users must still demonstrate internal governance, human oversight, acceptable use policies, and operational monitoring (Annex A.9) within their own organization.

Does DoAIRight issue ISO/IEC 42001 certificates?

No. DoAIRight provides readiness tools, gap assessments, and implementation guidance to help organizations build a compliant AI Management System. Official certification must be granted by an independent, accredited certification body following a formal audit.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score