ISO/IEC 42001:2023 / clause 10

Improvement

Correct failures, learn from incidents and audits, and continually improve the AI management system.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEClause 10 AI ControlsPOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01Define how AI nonconformities are recorded, assessed, corrected, and verified.
  2. 02Investigate root causes for AI incidents, control failures, policy breaches, assessment gaps, and supplier issues.
  3. 03Assign corrective actions with owners, due dates, evidence expectations, and verification steps.
  4. 04Feed lessons learned into policy updates, lifecycle gates, model monitoring, training, and supplier requirements.
  5. 05Review whether improvement actions reduce residual risk rather than only closing tickets.

Evidence to keep

  • - Nonconformity register
  • - Root cause analyses
  • - Corrective action records
  • - Updated policies and procedures
  • - Verification evidence

Common mistakes

  • - Closing findings without proof of effectiveness
  • - Treating AI incidents as one-off product bugs
  • - Not updating risk assessments after failures

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map