ISO/IEC 42001:2023 / clause 4

Context of the organization

Define why AI matters to the organisation, who is affected by it, and what parts of the business sit inside the AI management system.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEClause 4 AI ControlsPOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01List internal and external issues that affect AI governance, including regulation, customer expectations, product strategy, data access, model suppliers, and risk appetite.
  2. 02Identify interested parties such as customers, users, employees, regulators, partners, model providers, and people affected by AI outputs.
  3. 03Set the AIMS scope by business unit, product, geography, AI system type, and third-party dependency.
  4. 04Create an AI system inventory so the scope is tied to real systems rather than abstract policy language.
  5. 05Map each AI system to owner, intended use, user group, data sources, model provider, risk tier, and monitoring needs.

Evidence to keep

  • - AIMS scope statement
  • - AI system inventory
  • - Interested-party register
  • - AI context and obligations register
  • - Boundary diagram for in-scope AI systems

Common mistakes

  • - Leaving employee AI tools out of scope
  • - Treating vendor AI as out of scope because it is not built internally
  • - Writing a scope that auditors cannot trace to real systems

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map