Who should approve Risk Controls decisions under ISO/IEC 42001?
Control owners design, implement, operate, and monitor controls within their authority. Risk owners evaluate the remaining exposure. The designated management authority approves the risk-treatment plan and accepts residual AI risk. AIMS governance can check coverage and consistency, while top management addresses resources or risk decisions outside delegated authority.
Security, privacy, safety, supplier, legal, product, and business owners should approve matters within their authority. Acceptance of residual AI risk under the AIMS cannot waive a binding legal, contractual, or sector requirement.
- Name the control owner, risk owner, evidence owner, residual-risk approver, and escalation authority.
- Separate control design and testing from residual-risk acceptance where practical.
- Keep approval records with the evidence rather than in disconnected email threads.
ISO/IEC 42001:2023 Clauses 5.3 and 6.1.3 require assigned authorities and designated management approval of treatment and residual AI risks.
ISO/IEC 23894:2023 provides supporting guidance for risk ownership and treatment decisions.