ISO/IEC 42001:2023 places management-system requirements in Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, and improvement.
Annex A and Annex B are normative, but they have different jobs: Annex A is the reference control set used in risk treatment, while Annex B is adaptable implementation guidance. Annexes C and D are informative.
Use this guide to map the licensed ISO/IEC 42001:2023 text to owners, processes, and evidence. The first edition was published in December 2023 and applies to organisations of any size, type, or sector that provide or use products or services using AI systems. It specifies requirements for an organisational . Conformity or certification does not by itself establish the accuracy, safety, or legal compliance of an individual AI system.
The annexes support those clauses. Annex A is a reference set of control objectives and controls. Annex B is normative implementation guidance for the Annex A controls. Annex C is informative and lists potential AI-related organisational objectives and risk sources. Annex D is informative and discusses use of the AIMS across domains or sectors.
status does not make every Annex A control universally mandatory. Clause 6.1.3 requires the organisation to determine necessary controls, compare them with Annex A, consider relevant Annex A controls and Annex B guidance, add other controls where needed, and document the necessary controls and inclusion or exclusion reasons in the .
Annex B guidance is not a fixed checklist. The standard says an organisation can extend or modify the guidance or define its own implementation when it is not suitable or sufficient, and organisations do not have to justify inclusion or exclusion of Annex B guidance in the .
ISO International Standards are voluntary and do not replace national law. An applicable law, contract, procurement condition, or other external requirement can still make particular outcomes or use of the standard relevant to an organisation. Certification to ISO/IEC 42001 is also voluntary, is performed by an independent certification body rather than ISO, and assesses the defined AIMS scope rather than granting legal approval to an individual AI system.
Clause 4: determine context, relevant and requirements, roles for AI systems, the documented AIMS scope, and the management-system processes and interactions.
Clause 5: require top-management leadership, an AI policy, integration into business processes, resources, and assigned responsibilities and authorities.
Clause 6: establish risk criteria and repeatable risk assessment, risk treatment, impact assessment, objectives, and planned changes.
Clause 7: provide resources, competence, awareness, communications, and controlled .
Clause 8: operate planned processes and controls, manage changes and external provision, and repeat risk, treatment, and impact assessments at the specified triggers.
Clause 9: define monitoring and measurement, conduct internal audits, and complete management reviews at planned intervals.
Clause 10: improve the AIMS and correct nonconformities through cause analysis, corrective action, and effectiveness review.
Clause 4 starts with the organisation's purpose, internal and external issues, intended AI-system purposes, organisational roles, relevant and requirements, and the documented AIMS boundary. The organisation must determine whether climate change is a relevant issue. These inputs control which activities, risks, objectives, and controls the management system must address.
The roles considered can include AI providers; developers, deployers, operators, testers, and impact assessors; customers and users; integrators and data providers; people affected by the system; and relevant authorities. These are context examples, not fixed categories. The organisation's actual roles and jurisdiction affect which requirements and controls apply and how far they apply.
Clause 5 makes top management accountable for the AIMS. It must align the AI policy and objectives with strategic direction, integrate AIMS requirements into business processes, provide resources, communicate the importance of effective management, and assign responsibility for conformance and performance reporting.
Clause 6 requires risk criteria, a repeatable AI risk-assessment process, treatment decisions, an process, measurable objectives where practicable, and planned AIMS changes. Clause 7 covers the resources, competence, awareness, communications, and controls needed to support that work.
The standard prescribes some but does not prescribe the file names or templates below. Treat them as practical examples and keep only the records needed to meet the stated requirements and show that the scoped AIMS operates as planned.
Example Clause 4 evidence: context and climate-relevance analysis, AI-role map, interested-party register, documented scope, process map, and an AI-system inventory supporting the boundary.
Example Clause 5 evidence: approved AI policy, policy communications, objectives, resource decisions, role descriptions, authorities, and performance reports to top management.
Example Clause 6 evidence: risk criteria, assessment method and results, impact-assessment method and results, , treatment plan, residual-risk approval, objectives, and change plans.
Example Clause 7 evidence: resource plans, competence criteria and records, awareness records, communication plan and outputs, document approvals, access controls, versions, retention rules, and protected records.
Clause 8 requires the organisation to plan, implement, and control the processes needed to meet the AIMS requirements and carry out Clause 6 actions. It must set process criteria, operate the selected controls, monitor their effectiveness, control planned changes, review unintended changes, and control relevant externally provided processes, products, and services.
AI risk assessments must be performed at planned intervals or when significant changes are proposed or occur. AI-system impact assessments must be performed at planned intervals or when significant changes are proposed. Risk treatment must follow the approved plan, be checked for effectiveness, and be repeated when new risks need treatment or existing treatment options are ineffective.
Retain the results of every AI risk assessment, risk treatment, and AI-system impact assessment. The standard does not prescribe one universal interval; the organisation must perform the assessments at planned intervals and apply the specified change triggers.
Set operational criteria for each AIMS process and identify the records that show the criteria were followed.
Link lifecycle gates and change requests to risk, impact, treatment, and approval records.
Monitor selected controls and consider corrective action when intended results are not achieved.
Define supplier requirements, evidence, review frequency, exceptions, and responsibility allocation for externally provided AI-related services or components.
Keep planned-interval and significant-change triggers distinct so a material proposal is not delayed until the next scheduled review.
Annex A groups reference controls under AI policy, internal organisation, AI-system resources, impact assessment, lifecycle, data, information for , responsible use, and third-party and customer relationships. Use it as a completeness comparison during risk treatment, not as a substitute for the risk assessment.
The must contain all controls determined necessary, including additional controls not listed in Annex A, and justify inclusion and exclusion. A control can be excluded when it is not necessary based on the risk assessment and is not required by an applicable external requirement, including where an external requirement provides an exception.
Annex B explains ways to implement the Annex A controls, but the organisation remains responsible for choosing an implementation that meets its own control requirements and treatment needs.
Do not mark every Annex A control applicable without linking it to risk treatment or another documented need.
Do not omit a necessary control because Annex A lacks an exact label for it.
Do not treat Annex B wording as the only permitted implementation.
Do not use the without the current risk assessment, treatment plan, and management approval of residual risks.
Clause 9 requires the organisation to decide what to monitor and measure, which methods will produce valid results, when measurement occurs, and when results are analysed and evaluated. It must evaluate AIMS performance and effectiveness and retain evidence of results.
Internal audits must occur at planned intervals and test conformance to the organisation's own AIMS requirements and ISO/IEC 42001, plus effective implementation and maintenance. Top management must review the AIMS at planned intervals using previous actions, context and interested-party changes, performance trends, audit results, and improvement opportunities.
Clause 10 requires continual improvement. When a occurs, the organisation must control and correct it, deal with consequences, evaluate causes and possible recurrence elsewhere, implement needed corrective action, review effectiveness, and change the AIMS if needed.
The records below are practical examples, not ISO-prescribed forms. Each organisation can choose its format as long as the required is controlled and provides the necessary evidence.
Example monitoring record: defined measure, method, owner, frequency, result, analysis, threshold, exception, and action.
Example internal-audit record: programme, audit objectives, criteria, scope, objective and impartial auditor assignment, samples, findings, and reports to relevant managers.
Example management-review record: required inputs, decisions on improvement and AIMS changes, owners, resources, and follow-up status.
Example corrective-action record: , immediate correction, consequences, cause analysis, similar-condition review, action, owner, due date, and effectiveness result.
Official ISO explanation that International Standards are voluntary, do not replace national law, and use shall for requirements, should for recommendations, and may for permission.
Official ISO explanation that ISO/IEC 42001 certification is voluntary, ISO does not certify organisations, and independent certification bodies perform certification.
Clauses 9 and 10 of the licensed standard establish monitoring, internal-audit, management-review, continual-improvement, and corrective-action requirements.