ISO 42001 AI Change Management Procedure Template

by Poorva Dange

Introduction

In an era when Artificial Intelligence (AI) is becoming increasingly widespread, the ability to control and manage its development is critically important. Organizations that deploy AI systems or use AI-enabled products and services face challenges that include ethical concerns, bias, data privacy, security, and regulatory compliance. ISO 42001, the international standard for Artificial Intelligence Management Systems (AIMS), provides a structured framework for managing AI responsibly and harnessing its benefits. An effective AI Change Management Procedure is an important part of this framework and helps organizations control changes to AI systems efficiently, consistently, and responsibly.

ISO 42001 AI Change Management Procedure Template

The Changing Nature of AI and the Need for Control

Artificial Intelligence is dynamic. New algorithms, datasets, models, and capabilities are continuously developed and integrated into existing AI systems. Every modification can have positive or adverse effects, depending on the nature of the change and how it is managed.

Potential adverse effects include:

  • Reduced performance: A new model or configuration may perform worse than the version it replaces.

  • New or increased bias: Changes to data, algorithms, or decision rules may create unfair outcomes.

  • Ethical concerns: A change may alter how the system affects individuals or stakeholders.

  • Security vulnerabilities: New components or integrations may introduce exploitable weaknesses.

  • Privacy risks: Changes to data collection or processing may create new risks to personal information.

  • Operational disruption: A modification may affect connected systems, users, or business processes.

ISO 42001 and Its Importance to AI Management

ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AIMS. It supports the responsible development and use of AI through a management system approach.

For organizations seeking to benefit from AI while maintaining suitable governance, risk controls, and ethical safeguards, ISO 42001 provides an important framework. A defined AI Change Management Procedure supports that framework by ensuring that proposed changes are reviewed, assessed, approved, implemented, and documented in a controlled manner.

Why an AI Change Management Procedure Is Necessary

AI systems and models have characteristics that differ from conventional software. Their outputs may be sensitive to changes in training data, algorithms, prompts, operational conditions, or user behavior. A structured procedure helps ensure that organizational, technical, ethical, and compliance objectives continue to be met.

  • Maintain ethical integrity: Confirm that model updates, new data, or algorithm changes do not introduce unacceptable bias or compromise ethical commitments.

  • Support regulatory compliance: Evaluate changes against applicable laws, regulations, contractual duties, and internal policies.

  • Manage risk: Identify and mitigate technical, security, privacy, ethical, and operational risks created or modified by a change.

  • Maintain stakeholder trust: Demonstrate that the organization manages AI changes responsibly and predictably.

  • Protect performance: Confirm that a proposed change produces the intended improvement without unacceptable side effects.

ISO 42001 Requirements for Managing Change in AI Systems

Management system standards generally require organizations to control changes that could affect the management system and its intended outcomes. ISO 42001 does not prescribe a single detailed change procedure for every organization. However, organizations should establish suitable processes for planning, reviewing, approving, implementing, and documenting changes affecting the AIMS or the AI systems it governs.

The process should use a risk-based approach and consider how a proposed change may affect AI objectives, system performance, ethics, privacy, security, compliance, and stakeholder expectations.

ISO 42001 AI Change Management Procedure Template Explained

An AI Change Management Procedure provides a step-by-step method for controlling changes within the AIMS. The following components should be included.

1. Purpose and Scope

The purpose defines why the procedure is required. It should establish a systematic process for requesting, assessing, approving, implementing, verifying, communicating, and documenting AI-related changes.

The scope defines the systems, activities, and organizational areas covered by the procedure. It should also explain what qualifies as a change, including:

  • Model changes: Retraining, fine-tuning, replacement, or changes to model parameters.

  • Data changes: New datasets, data sources, labeling methods, preprocessing activities, or retention practices.

  • Algorithm changes: Introduction or modification of algorithms and decision rules.

  • Operational changes: Changes to the system’s intended use, operating environment, deployment infrastructure, or integrations.

  • Prompt changes: Significant changes to system prompts, prompt templates, or prompt-governance rules.

  • Control changes: Modifications to monitoring, human oversight, security, privacy, or risk controls.

  • Management system changes: Changes to AIMS policies, processes, objectives, responsibilities, or documentation.

2. Roles and Responsibilities

The procedure should define accountability throughout the change lifecycle.

  • Change Initiator: Proposes the change and provides the information required for its assessment.

  • AI System Owner: Remains accountable for the affected AI system, its performance, and its controlled operation.

  • AI Ethics Committee or Officer: Reviews potential ethical effects, including bias, fairness, transparency, and harm.

  • Data Protection Officer: Evaluates privacy and data protection implications when applicable.

  • Risk Management Team: Identifies new or modified risks and evaluates whether they remain within approved tolerance levels.

  • Legal or Compliance Team: Reviews the change against applicable laws, regulations, contracts, and internal requirements.

  • Technical Teams: Design, implement, test, validate, deploy, and support the change.

  • AIMS Manager: Oversees the change process and confirms alignment with the organization’s AIMS requirements.

  • Approving Authority: Approves, rejects, or conditionally approves the change according to its risk and impact level.

3. Change Identification and Request

The procedure should explain how a change is identified and formally requested. Triggers may include:

  • Maintenance needs: Corrective maintenance, defect resolution, or component replacement.

  • Performance improvement: Efforts to improve accuracy, reliability, efficiency, or user experience.

  • New data: Availability of new datasets or changes to existing data sources.

  • Regulatory change: New or revised legal, regulatory, or contractual requirements.

  • Security concerns: Newly identified vulnerabilities, threats, or incidents.

  • Stakeholder feedback: Requests or concerns raised by customers, users, employees, or other affected parties.

  • Business change: New opportunities, strategic priorities, services, or operating environments.

A standardized change request should record the change description, justification, affected systems and components, proposed implementation date, expected benefits, known risks, and initial impact assessment.

ISO 42001 AI Governance Framework

4. Impact and Risk Assessment

Every proposed change should be assessed according to its nature, significance, and risk. The assessment should consider:

  • Technical impact: Effects on model performance, accuracy, reliability, speed, latency, integrations, and resource use.

  • Data impact: Changes to datasets, sources, labeling, processing, quality, representativeness, data drift, or concept drift.

  • Ethical impact: Potential effects on bias, fairness, transparency, accountability, human rights, or the risk of harm.

  • Legal and regulatory impact: Continued compliance with applicable laws, regulations, contracts, and AIMS requirements.

  • Security impact: New vulnerabilities, threats, attack surfaces, or changes to existing security controls.

  • Privacy impact: Risks involving personal data, re-identification, data leakage, excessive processing, or inappropriate use.

  • Operational impact: Effects on users, support needs, maintenance, workflows, suppliers, and business continuity.

  • Risk treatment: New or modified risks, their severity and likelihood, required controls, risk owners, and residual risk.

5. Approval Process

The approval route should reflect the change’s assessed impact and risk.

  • Low-risk changes: May be approved by the AI System Owner or another delegated authority.

  • Moderate-risk changes: May require review by technical, risk, privacy, security, or compliance personnel.

  • High-impact or high-risk changes: May require approval from senior management, the AI Ethics Committee, Legal or Compliance, the Data Protection Officer, and other relevant authorities.

All approvals, conditions, deferrals, and rejections should be documented. A change should not proceed until the required authorization has been obtained.

6. Planning, Implementation, and Verification

Once approved, the change should be planned, implemented, tested, and verified in a controlled manner.

  1. Prepare the implementation plan: Define activities, responsibilities, resources, dependencies, timelines, testing, communications, and acceptance criteria.

  2. Develop a rollback plan: Establish how the organization will restore the previous stable state if the change fails or produces unacceptable effects.

  3. Implement in a controlled environment: Where practical, introduce and test the change in a development or staging environment before production deployment.

  4. Conduct verification and validation: Perform suitable testing, which may include unit, integration, performance, security, bias, explainability, and adversarial testing.

  5. Review test results: Confirm that acceptance criteria have been met and identified risks are controlled.

  6. Authorize deployment: Obtain any required production-release approval.

  7. Monitor after deployment: Evaluate actual performance, incidents, feedback, drift, and unintended effects after release.

7. Documentation, Communication, and Review

The procedure should establish requirements for maintaining a complete audit trail and evaluating the effectiveness of each change.

  • Document the change: Retain the request, assessments, test evidence, approvals, implementation details, deployment records, and verification results.

  • Record decisions: Document the reasons for approval, rejection, conditions, exceptions, and accepted residual risks.

  • Communicate with stakeholders: Notify affected internal and external stakeholders about the change, its impact, planned timing, and any required actions.

  • Conduct a post-implementation review: Confirm whether the change achieved its intended outcome and whether unexpected effects occurred.

  • Capture lessons learned: Record improvement opportunities and apply them to future changes.

  • Review the procedure: Periodically evaluate and improve the AI Change Management Procedure itself.

Benefits of an Effective AI Change Management Procedure

An effective procedure can provide the following benefits:

  • Regulatory and contractual alignment: Changes are reviewed against applicable laws, regulations, commitments, and internal requirements.

  • Stakeholder confidence: Harmful or poorly controlled changes are less likely to reach production, supporting trust in the organization’s AI practices.

  • Improved risk management: New and modified risks are identified and addressed before implementation.

  • Better system performance: Changes are tested and verified to ensure that improvements do not adversely affect other parts of the system.

  • Stronger accountability: Defined responsibilities and retained records demonstrate who assessed, approved, implemented, and reviewed each change.

  • Audit readiness: Documented evidence supports internal reviews, external assessments, and ISO 42001 certification activities.

ISO 42001 AI Governance Framework

Challenges in Implementing AI Change Management

Organizations may face several challenges when implementing the procedure:

  • Incomplete documentation: Poor records of impacts and risks can weaken verification, validation, incident investigation, and rollback activities.

  • Dynamic AI behavior: The effects of a change may be difficult to predict because AI systems can respond differently as data and operating conditions evolve.

  • Model complexity: Deep-learning and other complex models may make it difficult to understand how a change influences outputs.

  • System interdependencies: Connections among data, models, infrastructure, users, and third parties may complicate impact assessment.

  • Limited specialist resources: Effective review may require expertise in engineering, data science, ethics, privacy, security, legal compliance, and risk management.

  • Rapid technological change: Procedures, skills, tools, and controls must evolve as AI technologies and related risks develop.

Organizations can address these challenges through multidisciplinary review, suitable monitoring and testing tools, clear documentation, and ongoing competence development.

Conclusion

A structured AI Change Management Procedure helps organizations develop, deploy, and modify AI systems responsibly. It supports alignment with ISO 42001 by ensuring that proposed changes are assessed, authorized, tested, documented, communicated, and reviewed according to their impact and risk. Although ISO 42001 certification is generally voluntary unless required by a contract, customer, regulator, or other obligation, its management system approach can provide valuable governance for organizations using AI. By controlling change effectively, organizations can improve AI performance, maintain stakeholder trust, support compliance, and reduce the technical, ethical, security, privacy, and operational risks associated with evolving AI systems.


Implement ISO Faster with a Complete Documentation System

You're currently viewing a single template. Most ISO implementations require a complete set of policies, procedures, and records. Choose what fits your needs.
BEST FOR single ISO STANDARD

ISO Toolkit for Your Standard

Audit ReadyToolkits

Pick your toolkit from 8 ready-to-use ISO toolkits available: ISO 27001, 9001, 14001, 45001, 22301, 20000, and 42001 (AI Governance).

✔ Complete ISO documentation framework
✔ Policies, procedures, templates, and records
✔ Risk management & internal audit templates
✔ Management Review and Nonconformance
✔ ISO Standard Mapped Implementation Plan

💡 All toolkits come with instant download, one-time payment, and unlimited email & chat support.

View ISO Toolkits Collection →
BEST FOR MULTIPLE ISO STANDARDS

ISO PowerPack Bundle

All 8 ISO Toolkits in One Power Pack

Designed for teams, organizations, and consultants managing multiple ISO implementations across projects and clients.

✔ Unlimited internal and client use
✔ Deliver ISO services from day one
✔ Impress clients and auditors
✔ Skip months of document creation
✔ Grow your consulting business

💡All the benefits of our ISO toolkits combined in one powerful bundle — save over $1,000 compared to buying the toolkits individually.

View ISO PowerPack →