ISO/IEC 42001:2023 / clause 5

Leadership

Make senior leadership accountable for responsible AI, policy approval, role assignment, and integration with business processes.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEClause 5 AI ControlsPOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01Approve an AI policy that defines acceptable use, prohibited use, escalation paths, and decision authority.
  2. 02Name an executive owner for the AI management system and assign operational owners for AI risk, data, security, legal, product, and model operations.
  3. 03Set up an AI governance forum with the authority to approve high-impact AI use cases and stop unsafe deployments.
  4. 04Define who can approve new AI systems, material model changes, training data changes, and exceptions to AI policy.
  5. 05Ensure AI objectives are not only technical goals, but include risk, transparency, human oversight, and stakeholder protection.

Evidence to keep

  • - Approved AI policy
  • - AI governance charter
  • - Role descriptions or RACI
  • - Steering committee minutes
  • - Approval records for AI use cases

Common mistakes

  • - Making AI governance an engineering-only responsibility
  • - Approving policy without assigning authority
  • - Letting product launch pressure override risk decisions

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map