FAQGlobalISO/IEC 42001

ISO/IEC 42001 FAQ AI Policy

What must an ISO/IEC 42001 AI policy contain, who approves it, how does it connect to organisational purpose, objectives, roles, and other policies, and when must it be reviewed?

The policy is leadership evidence and a direction-setting control. It must be communicated and available as appropriate, but it does not replace system-level risk, impact, control, monitoring, and improvement records.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Clause 5.2 requires to establish an appropriate to the organisation's purpose, supportive of AI objectives, and committed to applicable requirements and continual improvement. Annex A.2 contains reference controls for documenting, aligning, and reviewing the policy; Annex B.2 gives implementation guidance. The Annex A controls are selected and justified through the organisation's risk-treatment and statement-of-applicability process rather than treated as an automatic checklist.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams handle AI Policy under ISO/IEC 42001?

must establish the . It must fit the organisation's purpose, provide a framework for AI objectives, commit to applicable requirements and continual improvement of the AIMS, refer to other organisational policies where relevant, be documented and communicated internally, and be available to as appropriate. Availability does not always mean public posting; record which parties need access, in what form, and why.

Annex B guidance says the policy should reflect business strategy, values and culture, risk tolerance, AI-system risk, legal and contractual requirements, the risk environment, and impacts on . It should also set guiding principles and a process for deviations and exceptions. It can cross-reference topic policies instead of repeating security, privacy, safety, quality, procurement, data, or product rules.

  • Record 's establishment or approval and name the role responsible for development, review, and evaluation.
  • Map each policy commitment to the relevant AI objective, process, control, owner, and operating evidence; a policy statement alone does not prove implementation.
  • Communicate the policy and keep awareness evidence appropriate to each role.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clause 5.2 sets the mandatory policy content, documentation, communication, cross-policy reference, and availability requirements; Annex B.2 gives implementation guidance.

Question 2

What evidence should prove AI Policy is current under ISO/IEC 42001?

Keep the current approved policy, version history, review record, communication evidence, and records showing that people under the organisation's control know the policy and understand their contribution and the consequences of nonconformity. Trace commitments to AI objectives, responsible-development or use processes, risk-treatment decisions, and any affected topic policies. For an exception, retain the request, affected commitment, rationale, risk or impact review, approving authority, conditions, expiry date, and closure or renewal decision.

  • Keep version, approval, communication, and review records.
  • Link each commitment to an AI objective, owner, operating process, and measurable result where practicable.
  • Record exceptions as risk, corrective-action, or management-review inputs.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clauses 5.2, 6.2, 7.3, and 7.5 support policy control, objective planning, awareness, and controlled documented information.

Recommended next step

Put the AI policy guidance into practice

Capture owners, evidence, decisions, and review dates in one workflow record so AI governance controls and escalation points stay auditable over time.

Question 3

Who should approve AI Policy decisions under ISO/IEC 42001?

establishes the policy and remains responsible for leadership and commitment. Management may approve a role to develop, review, and evaluate it, but assigning maintenance does not transfer top management's accountability.

Owners of affected security, privacy, safety, quality, procurement, data, product, legal, or risk policies should review proposed changes within their authority. Route changes in organisational direction, risk tolerance, commitments, or resources back to .

  • Assign and communicate policy responsibilities and authorities.
  • Separate drafting and consultation from 's establishment of the policy.
  • Keep approval records with the evidence rather than in disconnected email threads.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Clauses 5.1-5.3 place leadership, policy, and assignment of relevant roles with top management; Annex B.2.4 recommends a management-approved review role.

Question 4

When should AI Policy be reviewed under ISO/IEC 42001?

Review the policy at planned intervals and additionally when needed to ensure continuing suitability, adequacy, and effectiveness. ISO/IEC 42001 does not set one universal review frequency. Relevant triggers can include changes to the AIMS scope, organisational environment, business circumstances, legal or contractual conditions, technical environment, AI objectives, risk tolerance, AI uses, material impact findings, or management-review results.

Record the review result even when no change is needed; when the policy changes, update affected objectives, procedures, communications, awareness material, control ownership, and operating evidence rather than treating approval as the final step.

  • Assess continuing suitability, adequacy, and effectiveness.
  • Update aligned policies, objectives, controls, and communications together.
  • Carry unresolved resource or direction decisions into management review.
Citations
ISO/IEC 42001:2023 standard page

ISO/IEC 42001:2023 Annex A.2.4 and Annex B.2.4 set planned and need-based review and identify organisational, business, legal, and technical changes plus management-review results as inputs.

Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 42001:2023 Annex A.2.4 and Annex B.2.4 set planned and need-based review and identify organisational, business, legal, and technical changes plus management-review results as inputs.
"requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System"
Related guides

Explore more topics

ISO/IEC 42001 AI Impact Assessment Template
ISO/IEC 42001 AI-system impact assessment template for consequences, affected people, foreseeable misuse, context, evidence, approval, and reassessment.
ISO/IEC 42001 AI Management FAQ
Plain-language ISO/IEC 42001 FAQ covering scope, policy, Annex controls, risk and impact assessment, suppliers, monitoring, certification, and legal limits.
ISO/IEC 42001 AI System Inventory Guide
Build an ISO/IEC 42001 AI inventory covering purpose, owners, lifecycle roles, data, resources, suppliers, impacts, risks, controls, and monitoring.
ISO/IEC 42001 AI System Inventory Workflow
ISO/IEC 42001 workflow for creating, approving, maintaining, changing, and retiring AI-system inventory records with accountable evidence.
ISO/IEC 42001 AIMS Scope Decision Guide
Define an auditable ISO/IEC 42001 AIMS boundary across organisational units, AI activities, products, services, interfaces, suppliers, and customers.
ISO/IEC 42001 AIMS Scope Decision Workflow
ISO/IEC 42001 AIMS scope workflow for context, interested parties, AI activities, external dependencies, boundary approval, and change review.
ISO/IEC 42001 Certification FAQ
ISO/IEC 42001 certification scope, readiness evidence, internal audit, management review, corrective action, and claim limits.
ISO/IEC 42001 Compliance Guide
ISO/IEC 42001 conformance guide for Clauses 4-10, risk treatment, controls, operating evidence, internal audit, management review, and correction.
ISO/IEC 42001 Controls and Governance Model Guide
ISO/IEC 42001 governance model linking leadership, policy, risk and impact assessment, Annex controls, lifecycle roles, monitoring, audit, and improvement.
ISO/IEC 42001 Generative AI FAQ
Apply ISO/IEC 42001 to generative AI development, procurement, integration, employee use, supplier evidence, impacts, controls, and monitoring.
ISO/IEC 42001 High Risk AI FAQ
Separate ISO/IEC 42001 organisational risk criteria from legal high-risk AI classifications, with evidence, approval, and reassessment triggers.
ISO/IEC 42001 Human Oversight FAQ
Design and evidence effective human oversight under ISO/IEC 42001, including competence, information, intervention authority, testing, and review.
ISO/IEC 42001 Model Monitoring Evidence Guide
ISO/IEC 42001 monitoring evidence for AIMS performance, AI-system outcomes, impacts, control effectiveness, supplier signals, escalation, and correction.
ISO/IEC 42001 Post Market Monitoring FAQ
Distinguish ISO/IEC 42001 operational monitoring from legal post-market monitoring and connect real-world evidence to risk, review, incidents, and correction.
ISO/IEC 42001 Provider and Deployer Roles FAQ
Map ISO/IEC 42001 lifecycle responsibilities across developers, users, suppliers, customers, and third parties while keeping legal operator roles separate.
ISO/IEC 42001 Requirements Guide
ISO/IEC 42001:2023 requirements explained across Clauses 4-10, Annex A controls, Annex B guidance, evidence, audit, review, and improvement.
ISO/IEC 42001 Risk Controls FAQ
Select, justify, approve, operate, and review ISO/IEC 42001 risk controls, including Annex A comparison, the statement of applicability, residual risk, and evidence.
ISO/IEC 42001 vs EU AI Act Comparison
Compare voluntary ISO/IEC 42001 AIMS certification with binding EU AI Act roles, classifications, duties, evidence, dates, and enforcement.
ISO/IEC 42001 vs ISO/IEC 23894 Comparison
Compare certifiable ISO/IEC 42001 AIMS requirements with ISO/IEC 23894 AI risk-management guidance and see how to integrate their evidence.
ISO/IEC 42001 vs NIST AI RMF Comparison
Compare ISO/IEC 42001 AIMS requirements with the voluntary NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions and evidence.