Build the AI management system, not just the policy.
Most "AI governance" stops at a policy PDF nobody operationalises. An AI management system (AIMS) is different: it's the roles, evidence, and control cadence that let you prove, at audit, that AI is actually governed day to day. This page maps that operating model against ISO/IEC 42001, clause by clause.
What an AIMS actually requires
AIMS operating model
The AI management system boundary, leadership roles, and accountability structure — defined before a single detailed control gets written.
Policy and decision rights
A policy hierarchy, approval path, and review cadence, so AI usage is governed consistently rather than case by case.
Evidence and audit readiness
The records, logs, and approval artefacts that show governance is working in practice, not just documented in principle.
Seven clauses, each with a concrete evidence expectation.
ISO/IEC 42001 shares the Annex SL structure with ISO 27001 and ISO 9001 — if you already run an ISMS, the management-system scaffolding transfers directly. The AI-specific work is concentrated in the evidence column below.
| Clause | Annex A | Requirement | Evidence |
|---|---|---|---|
| 4 — Context & parties | A.2, A.3 | Identify internal/external issues, interested parties, and which AI roles you actually hold — provider, developer, deployer, or a mix. | AIMS boundary definition, stakeholder matrix, RACI chart |
| 5 — Leadership & policy | A.2.2 | Top management approves the AI policy and the values supporting responsible use. | Board-approved AI policy, version-controlled acceptable-use policy |
| 6 — Planning & risk | A.5 | Assess AI-specific risks and impacts, and set measurable AIMS objectives. | AI system impact assessments, risk register, Statement of Applicability |
| 7 — Support & resources | A.4 | Allocate and document compute, data, tooling, and human competence. | Competency logs, compute/tooling inventories, third-party contracts |
| 8 — Operation & control | A.6, A.7 | Control the AI system lifecycle, data lineage, and validation procedures. | Model cards, data provenance records, validation logs, version history |
| 9 — Performance evaluation | A.9 | Monitor operational metrics and drift, and run internal audits. | Telemetry evidence, internal audit reports, human-override logs |
| 10 — Improvement | A.9.2 | Detect nonconformities and drive corrective action. | Remediation tracking, corrective action register |
Nine control groups, thirty-eight normative controls.
The clause table above tells you what management-system activity to run. Annex A is where the specific controls live — grouped here by what each group is actually for.
Policies related to AI
The AI policy itself and how it cascades into subordinate policy.
Internal organisation
Roles, responsibilities, and reporting lines for AI governance.
Resources for AI systems
Compute, data, tooling, and the competence to use them responsibly.
Assessing impacts of AI systems
Impact assessment for individuals, groups, and society, not just the organisation.
AI system life cycle
Controls spanning design, development, verification, deployment, and retirement.
Data for AI systems
Data quality, provenance, and lineage requirements specific to training and inference.
Information for interested parties
What you disclose, to whom, and how — the transparency layer.
Use of AI systems
Operational use controls, monitoring, and the evaluation feeding Clause 9.
Third-party and customer relationships
Vendor and customer-facing AI risk, including supply chain.
The management-system work carries over. The evidence doesn't.
Because both standards share the Annex SL structure, an existing ISMS gives you working versions of Clauses 4–10 already — context, leadership, planning, support, operation, evaluation, improvement. What it doesn't give you is AI-specific evidence: data provenance records, algorithm explainability logs, and impact assessments covering bias, safety, and fundamental rights. That's the incremental build, not a parallel one.
See how this becomes an engagement.
AIMS Implementation is one of five defined engagement areas — scoped against exactly this clause structure.