Named a Leader in the Gartner® Competitive Landscape: Conversational Solutions™, 2025Get the report

ISO 42001: What Is an AI Management System?

Risk assessment, human oversight, explainability and the model lifecycle.

ISO/IEC 42001 is the international standard for artificial intelligence management systems, published in 2023. It binds how organisations develop, deploy and supervise AI to the discipline of a management system.

The logic of the standard is familiar: what ISO 27001 does for information security, ISO 42001 sets up as a comparable frame for AI. It focuses not on the technology but on the management of the technology.

What does the standard frame?

Risk assessment

An AI system is expected to have its impact assessed before it goes live. Which decision does it affect, who does it affect, and what happens when it works incorrectly? In a collections context that question is concrete: giving debt information to the wrong person, or communicating the wrong amount, produces serious consequences for both the customer and the institution.

Human oversight

Which decisions can proceed automatically and which require human approval are defined in advance. That definition is part of the design; it is not a safety net added afterwards.

In TAHSİLDAR the split is the institution's rule: routine disclosure and standard payment plans run automatically, while disputes and out of boundary requests are handed to a person. Where those handover points sit is decided at the start of the project.

Explainability

It has to be possible to answer the question "why did the model make this decision". In a collections call that means being able to trace which step was taken on the basis of which information: which record was read, which rule came into play, and why the conversation was transferred to a person.

The model lifecycle

The standard covers the process from development through to retirement: validation, monitoring, performance tracking and withdrawal where needed. A system that is set up once and forgotten does not fit this frame.

How does CBOT approach these principles?

We design digital employee projects with these principles in view. Defined authority boundaries, handover points agreed in advance, a trace kept of every interaction and role based limits on access are standard practice for us. We describe the whole of that approach on our AI governance and safety page.

Why is this being discussed now?

As the role of AI inside institutions grows, the question "does it work well" is joined by "how is it governed". The European Union's AI Act and, in Turkey, the data protection authority's guidance on generative AI point in the same direction.

The practical value of ISO 42001 is that it turns those expectations into an auditable management system. In a regulated process such as collections, that frame means being prepared for the questions an institution will be asked. We cover the regulatory side on the collections regulation and compliance page.