How should teams handle AI Policy under ISO/IEC 42001?
Start with the operational decision: define what AI Policy means in your ISO/IEC 42001 scope, who owns it, and what record proves the decision is current.
For AI governance work, start from the AI system inventory: purpose, role, provider or deployer status, data inputs, impact assessment, control owner, monitoring signal, human oversight, and change trigger. This keeps the answer useful in audits, customer reviews, incidents, supplier reviews, and management review.
- Name the accountable owner and reviewer for AI Policy.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when AI Policy changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
Primary ISO listing for AI management system requirements.
Primary ISO listing for AI risk management guidance.