A county IT director hears that ISO/IEC 42001 is “the certifiable AI standard.” A vendor mentions it on a sales call. A consultant offers a gap assessment against its control list. Six weeks later the county has a spreadsheet of controls marked red, amber and green, and nobody has answered the first question the standard asks.
That question is in Clause 4: what is the organization whose AI management system this is? For a company it takes a sentence. For a county it can take a month, and getting it wrong makes every later clause harder.
This is the second of four posts on how the Integrated Requirements Methodology, the method behind the Encephalon Enterprise AI Governance Practice and Tools, maps to, or draws on, the standards and laws local governments are asked about. Part 1 covers the NIST AI RMF; parts 3 and 4 cover the EU AI Act and Florida law and Chapter 119.
What the standard is, in ISO’s words
ISO describes 42001 as a standard that “specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations.” It is a management system standard. ISO’s guidance describes implementing it as putting in place policies and procedures for AI governance, following a Plan-Do-Check-Act cycle (ISO/IEC 42001 explained).
Its scope clause says it “is applicable to any organization, regardless of size, type and nature.” The rest of that sentence limits it to organizations that provide or use products or services that rely on AI systems. ISO’s own FAQ adds that it is “relevant for public sector agencies as well as companies or non-profits.”
Two things follow, and both are often misstated.
First, certification belongs to the organization, and a consultant cannot sell it. ISO itself does not perform certification or issue certificates (ISO, Certification). Certification “is carried out by independent certification bodies, which may be accredited by national accreditation bodies,” and ISO/IEC 42006, published in July 2025, sets the additional requirements for bodies that audit and certify AI management systems. Certification for 42001 is voluntary (ISO/IEC 42001 explained). A method can map to 42001. It cannot conform to it or be certified against it, because what gets certified is a management system an organization runs, not a document someone wrote for it. When we say our method maps to 42001, that is all we mean.
Second, a vendor’s certificate is about the vendor. If an AI vendor holds a 42001 certificate, that tells you something about how the vendor governs its own AI work. It does not tell you whether your intended use is appropriate, who in your county accepts the outputs, or how those outputs will be retained. Those questions sit in your management system, not theirs.
Why Clause 4 is hard in a county
Clause 4 is titled “Context of the organization,” and it includes 4.3, “Determining the scope of the AI management system.” ISO’s definitions help here. A note to the definition of organization explains that the concept covers an authority, partnership, charity or institution, or part or combination thereof, whether incorporated or not, public or private (ISO Online Browsing Platform).
“Part or combination thereof” is the phrase a county needs. In many states a county is not one organization for governance purposes. Independently elected officers such as clerks, property appraisers and tax collectors run their own offices, hold their own records and adopt their own policies. The county commission cannot write a management system and declare those offices inside it.
So a county has a real choice under 4.3. It can scope an AI management system to the commission side and let other offices adopt their own. It can build a combination that each office joins by its own act. What it cannot do is pretend the choice does not exist, and a gap assessment run before the choice is made is scoring controls for an organization nobody has defined.
The method starts there. Governance instruments are drafted to each governing body’s own form, whether a resolution, an administrative order or an amendment to an existing interlocal agreement, because each body has to bind itself. Each office adopts through its own act and keeps its own records schedule. That is a scoping decision in the Clause 4.3 sense, made before any control is scored.
How the method maps to the clause structure
ISO publishes the clause titles in its public preview of the standard. The full normative text is sold, so the mapping below is to clause titles, and the only text of the standard we quote comes from that preview: the scope clause and ISO’s published definitions.
| 42001 clause (title as published by ISO) | What the method produces for it |
|---|---|
| 4.3 Determining the scope of the AI management system | Per-body governance instruments, each adopted by the body it binds |
| 5.2 AI policy | The enterprise AI policy: authorized use, prohibited use, transparency standards, human oversight expectations |
| 5.3 Roles, responsibilities and authorities | Human-acceptance authority by decision class, named on the Authorization Record |
| 6.1 Actions to address risks and opportunities; 8.2 AI risk assessment; 8.3 AI risk treatment | The risk tiering model, with verification thresholds and sanctioned-model lists attached to each tier |
| 7.2 Competence; 7.3 Awareness | Workforce curriculum design at four levels, from awareness for general staff to briefings for leadership |
| 7.5 Documented information | The Authorization Record, and jurisdictional standards recorded per project |
| 8.1 Operational planning and control | An intake and approval path that names decision rights by risk tier |
| 6.1.4 and 8.4 AI system impact assessment | Input to it, from the decision-point audit described below |
| 9.1 Monitoring, measurement, analysis and evaluation; 10.1 Continual improvement | A periodic assessment cadence and a written operating procedure county staff can run |
The table shows how the method lines up with the clause structure. It is not a completed gap assessment.
Two rows need a caveat.
Clauses 6.1.4 and 8.4 are the ones we map most carefully. ISO defines an AI system impact assessment as a “formal, documented process by which the impacts on individuals, groups of individuals, or both, and societies are identified, evaluated and addressed.” The method’s decision-point audit records, for each candidate use, the decision being made, who holds authority for it today, and what changes if AI participates. That is a necessary input to an impact assessment. It is not the whole assessment, and we do not present it as one.
Clauses 9.2 (internal audit) and 9.3 (management review) are missing from the table on purpose. Those are functions a county runs through its own internal audit and its own governing bodies. A method can design the cadence that feeds them. It cannot perform them for the county.
What we are not mapping yet
Annex A of 42001 contains a table of control objectives and controls. ISO’s preview shows the table’s title and nothing more, and a definition note in the standard says an organization may not need every Annex A control and may add controls of its own. We have not published an Annex A crosswalk, and we will not describe one from secondary summaries of text we have not quoted from ISO.
One more connection is worth a line. Counties often use 42001 and the NIST AI RMF side by side, which is why the method maps to both instead of choosing one; part 1 covers the NIST side.
Encephalon has not yet run this method under a public-sector contract.
If your county is weighing 42001, settle the Clause 4.3 question first and write down who is inside the scope. The whitepaper covers the governance gap and the Kimball roots of the method. To talk through your own scoping question, book a 30-minute discovery call with the founding team.
Primary sources cited
- ISO, ISO/IEC 42001:2023 Information technology, Artificial intelligence, Management system, standard page (description, public-sector applicability FAQ, publication date 2023-12). https://www.iso.org/standard/42001
- ISO Online Browsing Platform, public preview of ISO/IEC 42001:2023 (Clause 1 scope; definitions 3.1, 3.24, 3.26; table of contents clauses 4 to 10; Table A.1 title). https://www.iso.org/obp/ui/en/#iso:std:iso-iec:42001:ed-1:v1:en
- ISO, Certification (ISO’s statement that it does not itself certify). https://www.iso.org/certification.html
- ISO, “ISO/IEC 42001 explained” (voluntary certification; independent certification bodies). https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html
- ISO, ISO/IEC 42006:2025, requirements for bodies providing audit and certification of AI management systems, published 2025-07. https://www.iso.org/standard/42006