How should teams handle AI Policy under ISO/IEC 42001?
Top management must establish the AI policy. It must fit the organisation's purpose, provide a framework for AI objectives, commit to applicable requirements and continual improvement of the AIMS, refer to other organisational policies where relevant, be documented and communicated internally, and be available to interested parties as appropriate. Availability does not always mean public posting; record which parties need access, in what form, and why.
Annex B guidance says the policy should reflect business strategy, values and culture, risk tolerance, AI-system risk, legal and contractual requirements, the risk environment, and impacts on interested parties. It should also set guiding principles and a process for deviations and exceptions. It can cross-reference topic policies instead of repeating security, privacy, safety, quality, procurement, data, or product rules.
- Record top management's establishment or approval and name the role responsible for development, review, and evaluation.
- Map each policy commitment to the relevant AI objective, process, control, owner, and operating evidence; a policy statement alone does not prove implementation.
- Communicate the policy and keep awareness evidence appropriate to each role.
ISO/IEC 42001:2023 Clause 5.2 sets the mandatory policy content, documentation, communication, cross-policy reference, and availability requirements; Annex B.2 gives implementation guidance.