How should teams handle Risk Controls under ISO/IEC 42001?
Follow the Clause 6.1.3 sequence for each assessed risk: select a treatment option; determine every ; compare that set with Annex A to check for omissions; consider relevant Annex A controls and Annex B implementation guidance; add different or additional controls where needed; produce the ; formulate the treatment plan; and obtain designated-management approval of the plan and .
Annex A is normative as a reference control set within ISO/IEC 42001, but not every listed control applies to every organisation or system. Annex B is normative implementation guidance, although the organisation does not have to document or justify the inclusion or exclusion of that guidance in the . The risk assessment, chosen treatment, objectives, and applicable external requirements determine the actual control set; a team may need controls beyond Annex A.
Use system-specific examples to test the reasoning. A supplied AI service can require supplier documentation, intended-use instructions, logging, monitoring, and incident routes. A model trained internally can also require data acquisition, quality, provenance, preparation, verification, release, and change controls. An AI tool affecting people can require impact assessment, accessible user information, adverse-impact reporting, and meaningful human oversight. These examples are not a universal checklist.
The must contain the necessary controls and justify their inclusion and exclusion. An exclusion can be justified when a control is not necessary under the risk assessment or an applicable external requirement does not require it or provides an exception. The statement is not permission to omit a control that the selected treatment or an external requirement makes necessary.
- Do not treat Annex A as an automatic universal checklist.
- For each included control, state the risk or requirement, objective, scope, owner, implementation, evidence, effectiveness measure, exception route, and review trigger.
- For each excluded control, state why it is unnecessary for the scoped system or activity and identify the evidence and approver supporting that conclusion.
- Document different or additional controls needed beyond Annex A and map them into the same treatment and evidence chain.
- Obtain designated-management approval for the treatment plan and acceptance of residual AI risks before relying on that acceptance.
ISO/IEC 42001:2023 Clause 6.1.3 sets the required treatment sequence, Annex A comparison, Annex B consideration, statement of applicability, treatment plan, and management approval of residual risk.
ISO/IEC 23894:2023 is the companion guidance standard for organisations managing AI-related risk; it does not replace ISO/IEC 42001's auditable requirements.