Annex A control areas / AI governance

ISO 42001 AI Control Areas

Use these areas to build a practical Statement of Applicability for AI systems. Select controls based on risk, impact, legal obligations, and how your organisation develops, provides, or uses AI.

High-risk AI control stack showing governance, risk, data, model, monitoring and human oversight checkpoints.
AI control stack / 11 KB WebP
A.2

AI policies

Set direction for responsible AI use and make policy expectations clear to builders, buyers, operators, and users.

A.3

Internal organization

Assign accountability and decision rights for AI governance across leadership, product, engineering, legal, security, privacy, and operations.

A.4

Resources for AI systems

Ensure the organisation has the people, tools, data, infrastructure, and budget needed to govern AI systems properly.

A.5

AI system impact assessment

Understand who may be affected by an AI system and what harms, benefits, rights impacts, or business impacts may occur.

A.6

AI system lifecycle

Control AI systems from idea and design through data work, model selection, testing, release, operation, change, and retirement.

A.7

Data for AI systems

Govern data used for AI so it is lawful, suitable, representative enough for the purpose, protected, and traceable.

A.8

Information for interested parties

Provide appropriate transparency to users, customers, staff, regulators, auditors, and affected people.

A.9

Use of AI systems

Control how AI systems are used in practice so outputs are reviewed, limitations are understood, and misuse is detected.

A.10

Third-party and customer relationships

Manage AI risks introduced by model providers, SaaS tools, implementation partners, customers, and downstream users.

A.11

Responsible use

Make responsible AI principles operational, including fairness, accountability, transparency, privacy, security, safety, and human agency.

A.12

AI objectives and metrics

Define measurable objectives for AI performance and governance so the AIMS can be evaluated and improved.

Audit-ready next steps

ISO 42001 documents, evidence, and software path

AI inventory, approved-use policy, impact assessment, supplier review, human oversight, monitoring, and incident records.