Key Takeaways
- ISO/IEC 42001:2023 applies the ISO harmonised structure, sharing identical clause numbers and titles with ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001. That enables integration, though it does not require it.
- Annex D addresses cross-sector use directly. Titled "Use of the AI management system across domains or sectors", it covers applying the AI management system alongside generic and sector-specific management system standards.
- An IOGP Report 510 operating management system supplies the containers for AI governance, across risk, competence, management of change, contractor conformance and assurance. It does not automatically supply the content.
- Parallel systems create duplicate controls and interface risk at the points where AI participates in operational decisions the operating management system already governs.
- Certification is not operational governance, and ISO/IEC 42001 does not confer presumption of conformity under the EU AI Act. Deloitte's 2026 survey of 3,235 leaders found only 21% report a mature governance model for agentic AI.
A predictable thing happens when a regulated industry meets a new management system standard. Someone is made accountable for it, a new manual is written, a new register is created, and a new set of controls begins operating alongside, but not inside, the systems the organisation already runs. It happened with quality, with safety, and with environment before harmonisation forced integration.
It is happening now with artificial intelligence, and the cost of repeating the pattern is higher this time. AI does not respect the boundary between the new manual and the old ones. It participates in the decisions the old manuals govern.
This article makes the structural case for a different approach. ISO/IEC 42001 was written to sit alongside the management systems an organisation already runs, and an IOGP Report 510 operating management system is the kind of structure capable of carrying it. For owners in the Energy, Minerals and Resources (EMR) sector, the decision to integrate ISO 42001 with existing management systems rather than build a parallel one is a design choice made early and paid for repeatedly thereafter. The argument applies most forcefully to operational AI, meaning systems that inform or execute decisions about safety, assets, process and production. It applies more loosely to AI in commercial and corporate functions, and that distinction is drawn out below.
What Is ISO/IEC 42001 Actually Designed to Do?
ISO/IEC 42001:2023, "Information technology, Artificial intelligence, Management system", was published on 18 December 2023. It is the first certifiable international standard for AI management systems, specifying requirements for the policies, roles, risk processes, impact assessments, lifecycle controls and supplier requirements through which an organisation governs its development and use of AI.
The critical design fact is its architecture. The standard states in its own introduction that it "applies the harmonized structure (identical clause numbers, clause titles, text and common terms and core definitions) developed to enhance alignment among management system standards", and that this common approach "facilitates implementation and consistency with other management system standards, e.g. related to quality, safety, security and privacy".
The clause skeleton is therefore the familiar one: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. Clause 6.3, planning of changes, sits exactly where an operating management system would expect to find change control. Alongside the normative Annex A reference controls and Annex B implementation guidance, the informative Annex D is titled "Use of the AI management system across domains or sectors", addressing application in different sectors and integration with other management system standards.
Two points of precision matter. Annex D is informative rather than normative, and the harmonised structure enables integration without mandating it. A standalone AI management system can be entirely conformant. The argument for absorption is therefore not one of conformance but of cost and coherence: a separate system duplicates machinery the organisation already funds, and it separates AI governance from the decisions AI actually participates in.
What Does an IOGP 510 Operating Management System Already Provide?
IOGP Report 510, "Operating Management System Framework for controlling risk and delivering high performance in the oil and gas industry", was published in 2014 by the International Association of Oil and Gas Producers with IPIECA. It defines the operating management system framework used across upstream oil and gas and, increasingly, mining and broader resources operators, either directly or through corporate equivalents built on the same logic.
The framework has two interdependent components. Four Fundamentals: leadership, risk management, continuous improvement, and implementation. And ten Elements:
- Commitment and accountability
- Policies, standards and objectives
- Organisation, resources and capability
- Stakeholders and customers
- Risk assessment and control
- Asset design and integrity
- Plans and procedures
- Execution of activities
- Monitoring, reporting and learning
- Assurance, review and improvement

IOGP describes the framework as offering an integrated approach with the flexibility to address a wide range of risks, including occupational health and safety, environmental and social responsibility, process safety, quality and security. The operating management system was built to absorb multiple risk disciplines under one structure.
The argument that follows uses IOGP Report 510 as the reference framework because it is the most widely adopted structured OMS in upstream oil and gas and because its Element architecture maps cleanly onto ISO 42001's harmonised clauses. The logic holds regardless of the specific framework an organisation operates under, benchmarks against, or holds certification in. Whether the OMS in question is built on ISO 9001, ISO 45001, an ISO 14001-anchored integrated management system, a corporate equivalent of IOGP 510, or a sector-specific regulatory framework, the structural argument is the same: the harmonised clause architecture of ISO 42001 was designed to be absorbed into systems that already use it. The design question is not which standard you run.
It is whether the system you run is actually operating, and whether the people governing AI decisions are inside it or alongside it.
Where Do the Two Frameworks Map Onto Each Other?
Set them side by side and the mapping is direct.
- AI risk assessment and impact assessment extend Element 5, risk assessment and control. ISO/IEC 42005:2025 gives guidance on AI system impact assessment and how to integrate it into existing risk management.
- Lifecycle and change controls belong inside management of change, which sits across Elements 7 and 8.
- Competence requirements extend Element 3, organisation, resources and capability, to roles that now supervise algorithmic outputs. This is the management system counterpart to the practical question of governing delivery when AI joins the team.
- Supplier and vendor requirements extend existing contractor conformance expectations to AI vendors and model providers.
- Performance evaluation and improvement land in Elements 9 and 10, the monitoring, learning, assurance and review machinery the operator already runs.
The operator does not lack a home for AI governance. What it lacks, in most cases, is the content to put in it.
Structure is not the same as capability
This is where integration arguments become glib. Element 5 provides a risk assessment process, but it was written for hazards with physical mechanisms and established failure modes. It does not, without deliberate extension, accommodate model risk and algorithmic bias, data drift and provenance, explainability sufficient to support human oversight, model supply chain risk including foundation models the operator does not control, continuous deployment where the governed object changes between assurance cycles, or adversarial and AI-specific cybersecurity exposure.
The operating management system supplies the containers. Absorption that consists only of amending documentation will produce a structure that looks integrated and governs nothing. Integration requires capability the operator may not currently hold: data science, machine learning operations, model validation, and AI risk assessment competence sitting close enough to operations to be useful. That capability has to be built or bought either way. Building it inside the existing system is cheaper than building it twice.
Why Does the Safety Case Make Integration Urgent?
The strongest argument for absorption is not efficiency. It is the safety-critical decision loop.
ISO 45001:2018 shares the same harmonised structure, which is why it integrates with ISO 9001 and with the revised environmental management requirements of ISO 14001:2026, and by extension with ISO 42001. Where an AI system informs an operational decision that the occupational health and safety management system governs, the two cannot sensibly be assured separately. The advisory and the action belong to one chain of accountability.
Management of change is where this becomes concrete. Recognised process safety guidance defines MOC as a structured process for any non like-for-like change to equipment, processes, procedures or organisation, and the IChemE Safety Centre guidance explicitly includes changes to human-machine interface design and control room layout. Work published in 2026 extends this logic to AI. Reviews in the Journal of Loss Prevention in the Process Industries situate AI governance within established process safety management elements and identify model fragility under changing operational conditions as a core assurance problem, and recent work on structured safety cases for AI systems describes a continuous evolution pattern in which retraining, version updates and data refreshes each alter risk characteristics and invalidate static evidence.
Absorbing model change into MOC is necessary but not sufficient. A full safety case for an AI-supported operational decision requires hazard identification specific to AI failure modes, allocation of safety requirements, verification and validation of model behaviour, analysis of human and automation interaction, and monitoring for degradation in service. Those are engineering disciplines in their own right. The management system question is where they are commissioned, assured and reviewed, and the answer should be the system that already commissions, assures and reviews everything else.
This framing is not yet codified in a published ISO 45001 clause or CCPS text. It is a reasoned position supported by current literature rather than an established requirement. The regulatory analogue already exists: the EU AI Act treats substantial modification of a high-risk AI system as a trigger for renewed conformity obligations.

What Goes Wrong When the Systems Run in Parallel?
Three failure modes are predictable.
Duplicate control with divergent content
Two risk processes assess the same operational decision loop under different criteria. One of them is wrong, and nobody knows which. The academic literature on integrated management systems identifies duplication, excessive bureaucracy, inefficient resource use and audit fatigue as recurring costs of maintaining separate systems.
Interface risk at the point of consequence
When an AI-supported decision contributes to an operational event, the investigation finds that the AI management system governed the model while the operating management system governed the operation, and the decision fell between them.
Bureaucratic decay
The parallel system, owned by a small central function and disconnected from operations, becomes documentation that is laminated rather than lived. It is a familiar finding in independent reviews of capital project governance, and there is no reason to expect AI governance to be exempt.
The gap between written policy and operational governance is already wide. Deloitte's State of AI in the Enterprise report, its eighth edition published in 2026 and based on a survey of 3,235 business and technology leaders across 24 countries including energy, resources and industrials, found that while 74% of respondents expect to use AI agents at least moderately by 2027, only 21% say their organisations have a mature governance model in place for agentic AI. A Cloud Security Alliance and Google Cloud survey of around 300 security and IT professionals, published in December 2025, found only 26% reported comprehensive AI security governance policies in place.
Does Certification Answer the Regulatory Question?
Not on its own, and this matters for owners building a compliance case.
Under the Digital Omnibus agreed in 2026, the EU AI Act high-risk deadlines have moved. Annex III standalone high-risk systems are deferred to 2 December 2027, and Annex I embedded high-risk systems, meaning AI within products already covered by EU product safety law, to 2 August 2028. The Article 50 transparency obligations were not deferred and apply from 2 August 2026.
ISO/IEC 42001 certification is widely used as evidence of credible AI governance, but it does not confer legal presumption of conformity with the Act. Presumption of conformity requires harmonised European standards cited in the Official Journal, and CEN-CENELEC confirmed in December 2025 that ISO/IEC 42001 does not cover all the quality management requirements of the Act. Work on prEN 18286, the first European AI quality management standard, is intended to close that gap and draws on ISO 42001 Annex A controls.
The practical implication is that ISO 42001 functions as the management system backbone while the Act imposes system-specific technical obligations on top. Technical obligations attached to individual AI systems still need a management system to sit within, and the operator already has one.
When Is a Separate Structure Actually Defensible?
The case for absorption is strong but not universal. Three situations warrant a discrete boundary, at least initially.
AI outside the operational envelope
Much enterprise AI use sits in commercial, corporate, legal and human resources functions the operating management system was never written to govern. Forcing that activity into risk and change processes designed for plant and wells produces a poor fit in both directions. A corporate AI governance function with a defined interface to the operating management system is more honest than a strained mapping.
Certification as the near-term commercial driver
Where certification is required by a client, a partner or a tender within a fixed window, a tightly scoped standalone system is easier to define, evidence and audit than amendments distributed across ten Elements. This sits in tension with the earlier point that certification is not operational governance, and the tension is real rather than resolvable. Certification is a commercial fact even where it is not a governance outcome. The trade-off is that a boundary drawn for audit convenience tends to persist long after the audit.
An operating management system that cannot carry the weight
Absorption assumes the receiving system works. Where the operating management system is documented but not operating, where Elements are owned nominally and assured rarely, integrating ISO 42001 into it transfers that weakness into AI governance and hides it behind a compliant-looking structure. The same pattern explains why AI deployment fails before the algorithm runs. In that situation the question is not how to integrate but whether the base system is fit to receive anything at all.
What Does Absorption Look Like in Practice?
Integration is clause-level design work, not a policy statement. It means mapping each ISO 42001 requirement to the Element that will carry it, amending that Element's documentation, expectations and accountabilities, and closing the gaps the mapping exposes rather than building new structure around them.
In practice that produces:
- One operational risk register, with AI-specific risk criteria added to the existing criteria set. AI risk that is legally distinct, covering data protection, intellectual property, employment and competition exposure, is better held in the registers that already own those obligations, with a defined interface rather than a forced merge
- One management of change procedure, whose triggers include model retraining, version change, deployment environment change and material shifts in training data
- One competence framework, whose role profiles include supervision of algorithmic outputs
- One supplier conformance process, extended to AI vendors and model providers
- One assurance programme, whose scope includes the AI governance envelope
Sector adoption is still early, which is an argument for designing this properly now rather than inheriting a parallel structure later. TechnipFMC announced ISO/IEC 42001 certification of its AI management system in July 2026, and is among the few energy sector organisations to have publicly announced certification to date. In mining, Anglo American's 2025 Annual Report describes AI governance delivered through an AI Centre of Excellence with embedded governance and risk capability, which is integration into existing structures rather than a standalone certified system.
Where Should an Owner Start?
Sequencing matters more than speed.
The mapping cannot begin until the owner knows the current state of both sides: how mature the operating management system actually is in operation rather than on paper, and how far AI has already penetrated decision loops, formally or informally. The distinction between a system that is documented and a system that is operating is the central question in independent assessment of an operating management system. Shadow adoption is common and rarely visible from the centre.
Answering that before designing the integration is the difference between absorbing ISO 42001 into a living system and stapling it to a broken one. As McKinsey put it in its September 2025 analysis of the agentic organisation, "governance cannot remain a periodic, paper-heavy exercise. As agents operate continuously, governance must become real time, data driven, and embedded". For most EMR owners, the operating management system is the structure best equipped to carry that load, because it is already the one that runs continuously.
PDAS provides independent, owner-side assurance of operating models and management systems across the Energy, Minerals and Resources sector, benchmarking operating management system maturity, culture and AI-specific readiness in a single fixed-scope engagement.











