ISO 42001 and human oversight

The standard treats oversight as a governance theme to design and evidence, not as a fixed legal rule. The EU AI Act takes the opposite approach.

ISO 42001's Annex A addresses human oversight as one of its control themes, at a high level, without prescribing binding legal duties. The EU AI Act, by contrast, makes oversight a binding duty for high-risk systems under Article 14.

ISO/IEC 42001

Human oversight is where a person can understand, question or step into an AI system's operation. ISO 42001 and the EU AI Act both care about it, but they do different jobs: one is a voluntary organisational standard, the other a binding law for high-risk systems (ISO/IEC 42001:2023). This page names the standard's treatment at a high level and does not reproduce its text.

How does ISO 42001 treat human oversight?

ISO 42001's Annex A addresses human oversight as one of its control themes, at a high level, without prescribing binding legal duties (ISO/IEC 42001:2023). The standard puts oversight inside the management system, so it is something you design, resource and review as part of governing AI, and the depth is proportionate to the risk of the use.

Because the standard leaves the how to the organisation, two organisations can meet it with very different oversight arrangements, provided each is deliberate and evidenced.

Where does it appear in the management system?

It runs through the operating clauses rather than sitting in one place: the planning that identifies where oversight matters, the support that resources it, the operation that puts it into practice, and the performance evaluation that checks it is working (Clauses 6 to 9).

So oversight is not a single document you produce once. It is a set of decisions about which uses need a human able to intervene, kept current as your AI use changes.

How does it differ from the EU AI Act's Article 14?

The EU AI Act makes human oversight a binding legal duty for high-risk systems under Article 14: providers must design those systems so they can be effectively overseen by a person during use. ISO 42001 is voluntary and treats oversight as a governance theme, so it does not carry that legal force.

The practical consequence: certifying to ISO 42001 is not the same as meeting Article 14, and an organisation with high-risk systems in EU scope has to satisfy the Act's specific duty on top of any standard it holds. The high-risk and Annex III guide covers when that duty attaches, and the standard-versus-Act guide works through the wider relationship.

What does evidence of oversight look like?

For the standard, evidence is your own: a record of which AI uses were judged to need human oversight and why, how that oversight is provided, who is responsible, and what happened when someone had to intervene. The point is that the oversight is real and reviewable, not that it matches a prescribed control.

The readiness check includes the impact and operational-control themes where oversight decisions live, so it is a way to see whether yours are recorded or still implicit, and the blank gap sheet covers the same ground offline.

Common questions

How does ISO 42001 handle human oversight of AI systems?
ISO 42001's Annex A addresses human oversight as one of its control themes, at a high level, without prescribing binding legal duties. It sits inside the management system, so oversight is something the organisation designs, resources and reviews as part of governing its AI, rather than a fixed rule the standard spells out.
What is the role of human oversight in ISO 42001?
It is one of the ways the management system keeps AI use accountable: deciding where a person needs to be able to understand, question or intervene, and making sure that is resourced and recorded. The standard leaves the how to the organisation, so the evidence is your own design and records rather than a prescribed control.
How does this differ from the EU AI Act?
The EU AI Act makes human oversight a binding legal duty for high-risk systems under Article 14. ISO 42001 is a voluntary management system standard that treats oversight as a governance theme. Conformity with the standard is not compliance with the Act, and the Act's duty is more specific and legally enforceable.