Build the AI management system, not just the policy.
Most "AI governance" stops at a policy PDF nobody operationalises. An AI management system (AIMS) is different: it's the roles, evidence, and control cadence that let you prove, at audit, that AI is actually governed day to day. This page maps that operating model against ISO/IEC 42001, clause by clause.
Last reviewed: 2026-07-29
What an AIMS actually requires
AIMS operating model
The AI management system boundary, leadership roles, and accountability structure, defined before a single detailed control gets written.
Policy and decision rights
A policy hierarchy, approval path, and review cadence, so AI usage is governed consistently rather than case by case.
Evidence and audit readiness
The records, logs, and approval artefacts that show governance is working in practice, not just documented in principle.
Seven clauses, each with a concrete evidence expectation.
ISO/IEC 42001 shares the Annex SL structure with ISO 27001 and ISO 9001. If you already run an ISMS, the management-system scaffolding transfers directly. The AI-specific work is concentrated in the evidence column below.
| Clause | Annex A | Requirement | Evidence |
|---|---|---|---|
| 4: Context & parties | A.2, A.3 | Identify internal/external issues, interested parties, and which AI roles you actually hold: provider, developer, deployer, or a mix. | AIMS boundary definition, stakeholder matrix, RACI chart |
| 5: Leadership & policy | A.2.2 | Top management approves the AI policy and the values supporting responsible use. | Board-approved AI policy, version-controlled acceptable-use policy |
| 6: Planning & risk | A.5 | Assess AI-specific risks and impacts, and set measurable AIMS objectives. | AI system impact assessments, risk register, Statement of Applicability |
| 7: Support & resources | A.4 | Allocate and document compute, data, tooling, and human competence. | Competency logs, compute/tooling inventories, third-party contracts |
| 8: Operation & control | A.6, A.7 | Control the AI system lifecycle, data lineage, and validation procedures. | Model cards, data provenance records, validation logs, version history |
| 9: Performance evaluation | A.9 | Monitor operational metrics and drift, and run internal audits. | Telemetry evidence, internal audit reports, human-override logs |
| 10: Improvement | A.9.2 | Detect nonconformities and drive corrective action. | Remediation tracking, corrective action register |
Nine control groups, thirty-eight normative controls.
The clause table above tells you what management-system activity to run. Annex A is where the specific controls live, grouped here by what each group is actually for.
Policies related to AI
The AI policy itself and how it cascades into subordinate policy.
Internal organisation
Roles, responsibilities, and reporting lines for AI governance.
Resources for AI systems
Compute, data, tooling, and the competence to use them responsibly.
Assessing impacts of AI systems
Impact assessment for individuals, groups, and society, not just the organisation.
AI system life cycle
Controls spanning design, development, verification, deployment, and retirement.
Data for AI systems
Data quality, provenance, and lineage requirements specific to training and inference.
Information for interested parties
What you disclose, to whom, and how: the transparency layer.
Use of AI systems
Operational use controls, monitoring, and the evaluation feeding Clause 9.
Third-party and customer relationships
Vendor and customer-facing AI risk, including supply chain.
The management-system work carries over. The evidence doesn't.
Because both standards share the Annex SL structure, an existing ISMS gives you working versions of Clauses 4–10 already: context, leadership, planning, support, operation, evaluation, improvement. What it doesn't give you is AI-specific evidence: data provenance records, algorithm explainability logs, and impact assessments covering bias, safety, and fundamental rights. That's the incremental build, not a parallel one.
Risks and controls in this domain.
Pulled live from the Risk Library and Control Library — every entry tagged Governance in the full Risk & Control spine, not a hand-maintained duplicate.
17 risks
- AI literacy gap in the deploying organisation medium
- AI system lifecycle controls gap medium
- Disparate impact monitoring gap high
- Inadequate AI resourcing and competence medium
- Inadequate AI vendor due diligence high
- Inadequate explainability for affected individuals high
- Inadequate fairness testing before deployment medium
- Inadequate human oversight design high
- Missing AI impact assessment process high
- No documented AI policy high
- Proxy discrimination via correlated features high
- Sub-outsourcing visibility gap medium
- Third-party model and dataset provenance medium
- Training data bias and discriminatory outcomes high
- Unclear AI ownership and accountability medium
- Undisclosed AI interaction medium
- Vendor concentration and exit strategy gap high
9 controls
- AI acceptable use policy
- AI impact assessment process
- AI literacy programme
- AI ownership and accountability framework
- AI transparency and disclosure labelling
- Bias testing and fairness monitoring
- Human-in-the-loop review
- Third-party model and vendor due diligence
- Vendor exit strategy and concentration management
Frequently asked questions
What does ISO/IEC 42001 Clause 5 require?
Top management approves the AI policy and the values supporting responsible use, evidenced through a board-approved AI policy and a version-controlled acceptable-use policy.
What does ISO/IEC 42001 Clause 6 require?
Assessing AI-specific risks and impacts, and setting measurable AIMS objectives, evidenced through AI system impact assessments, a risk register, and a Statement of Applicability.
What is an AI management system (AIMS)?
The roles, evidence, and control cadence that let an organisation prove, at audit, that AI is actually governed day to day, not just documented in a policy PDF nobody operationalises.
Does an existing ISO 27001 ISMS help with ISO/IEC 42001?
Yes for the management-system scaffolding: both standards share the Annex SL structure, so an existing ISMS gives working versions of Clauses 4–10 already. It does not give you the AI-specific evidence: data provenance records, algorithm explainability logs, and impact assessments covering bias, safety, and fundamental rights.
How many controls does ISO/IEC 42001 Annex A contain?
Nine control groups and thirty-eight normative controls, spanning AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, transparency, operational use, and third-party relationships.
This is one of the areas Andrew advises on.
AIMS Implementation is one of five areas of expertise on the services page, grounded in exactly this clause structure.