Why Artificial Intelligence Belongs in the Management System

Manuel Klötzer / 01.09.2026

Few technologies are as widely debated as artificial intelligence (AI). While it holds great promise, it also inevitably raises questions about the risks associated with its use. Companies should therefore not only address the question of how to use AI as profitably as possible; they must also take into account the legal and organizational frameworks as well as the associated requirements. A systematic approach in the content of the management system can help ensure that AI is used responsibly.

Artificial intelligence can facilitate the handling of the challenges of our time in many ways. For example, the analysis of large amounts of data can help improve the quality of products and services, increase productivity and establish new business models. It can also make a contribution to society, for instance by assisting in the detection of diseases in the medical field.

On the other hand, however, AI also gives rise to risks and uncertainties: Because it can analyze very large amounts of data, new opportunities for surveillance, discrimination or cybercrime arise. At the same time, it is not always immediately clear who is liable if an AI system disseminates false information or makes erroneous decisions. Legislative bodies are therefore increasingly addressing the impact of artificial intelligence.

Requirements for the Use of AI

One example of this is the EU Regulation on Artificial Intelligence, also known as the AI Act. It takes a risk-based approach, imposes obligations on providers and deployers of AI systems, among others, and prohibits certain AI practices. Depending on the type and area of application of an AI system, requirements regarding transparency, risk management, documentation and human oversight, among other things, may apply.

In addition to the AI Act, other requirements related to AI may be relevant for companies. These include, for example:

  • Data protection requirements such as the General Data Protection Regulation
  • Cybersecurity requirements such as the Cyber Resilience Act
  • Product liability and product safety requirements such as the Product Liability Directive or the Machinery Regulation
  • Industry-specific requirements such as the Medical Device Regulation

Companies should therefore assess which requirements apply to them and document their compliance accordingly. In addition, they should establish the conditions under which they and their workforce use AI. Such an internal set of rules can, for example, govern permissible tools, the handling of confidential data or verification requirements for AI-generated results.

From a Set of Rules to a Management System

Beyond individual guidelines, a systematic approach to AI issues is recommended. This is because the use of artificial intelligence involves a convergence of various risks, opportunities, legal requirements and the interests of customers and employees. A management system helps to consider these aspects collectively, derive appropriate processes and measures and define responsibilities. Clearly defined and documented procedures can provider greater confidence in the use of AI applications.

ISO/IEC 42001, published at the end of 2023, provides a possible framework by setting out requirements for a management system for artificial intelligence. In addition, many companies already have management systems in place – such as for quality or information security – in which relevant AI topics can be incorporated. It is therefore possible to address AI topics both on the basis of ISO/IEC 42001 and within the management systems already established within the company. Each company must determine for itself which approach makes sense in its specific case, taking into account its own circumstances and requirements.

AI as Part of the Integrated Management System

In any case, AI is just one of many topics that companies have to deal with. An Integrated Management System (IMS) is an ideal way to examine all these topics together within a unified structure, identify interrelationships and leverage synergies. This integrated approach within the IMS is facilitated by the fact that the common management system standards of the International Organization for Standardization (ISO) are based on the Harmonized Structure and are therefore structured similarly.

When establishing and expanding such an Integrated Management System, it is helpful to link risks and opportunities, requirementsprocesses and documents in a meaningful way. This also increases the transparency of the IMS, as all stakeholders within the company can access the relevant information. In many cases, using appropriate software is a good solution for this purpose.

Software Offers Support for Management Systems

Interaction of the modules that help your company to make your QMS or IMS effective

With modules such as Risk Management, Requirements Management or Process Management, the Babtec software supports the handling of all relevant requirements as well as the development and expansion of (Integrated) Management Systems - with intuitive usability and based on a common data master.