ISO 42001 AI Control Areas
Use these areas to build a practical Statement of Applicability for AI systems. Select controls based on risk, impact, legal obligations, and how your organisation develops, provides, or uses AI.

AI policies
Set direction for responsible AI use and make policy expectations clear to builders, buyers, operators, and users.
A.3Internal organization
Assign accountability and decision rights for AI governance across leadership, product, engineering, legal, security, privacy, and operations.
A.4Resources for AI systems
Ensure the organisation has the people, tools, data, infrastructure, and budget needed to govern AI systems properly.
A.5AI system impact assessment
Understand who may be affected by an AI system and what harms, benefits, rights impacts, or business impacts may occur.
A.6AI system lifecycle
Control AI systems from idea and design through data work, model selection, testing, release, operation, change, and retirement.
A.7Data for AI systems
Govern data used for AI so it is lawful, suitable, representative enough for the purpose, protected, and traceable.
A.8Information for interested parties
Provide appropriate transparency to users, customers, staff, regulators, auditors, and affected people.
A.9Use of AI systems
Control how AI systems are used in practice so outputs are reviewed, limitations are understood, and misuse is detected.
A.10Third-party and customer relationships
Manage AI risks introduced by model providers, SaaS tools, implementation partners, customers, and downstream users.
A.11Responsible use
Make responsible AI principles operational, including fairness, accountability, transparency, privacy, security, safety, and human agency.
A.12AI objectives and metrics
Define measurable objectives for AI performance and governance so the AIMS can be evaluated and improved.
ISO 42001 documents, evidence, and software path
AI inventory, approved-use policy, impact assessment, supplier review, human oversight, monitoring, and incident records.