Build the AI management system, not just the policy.

Most "AI governance" stops at a policy PDF nobody operationalises. An AI management system (AIMS) is different: it's the roles, evidence, and control cadence that let you prove, at audit, that AI is actually governed day to day. This page maps that operating model against ISO/IEC 42001, clause by clause.

Last reviewed: 2026-07-29

What an AIMS actually requires

AIMS operating model

The AI management system boundary, leadership roles, and accountability structure, defined before a single detailed control gets written.

Policy and decision rights

A policy hierarchy, approval path, and review cadence, so AI usage is governed consistently rather than case by case.

Evidence and audit readiness

The records, logs, and approval artefacts that show governance is working in practice, not just documented in principle.

Seven clauses, each with a concrete evidence expectation.

ISO/IEC 42001 shares the Annex SL structure with ISO 27001 and ISO 9001. If you already run an ISMS, the management-system scaffolding transfers directly. The AI-specific work is concentrated in the evidence column below.

ClauseAnnex ARequirementEvidence
4: Context & partiesA.2, A.3Identify internal/external issues, interested parties, and which AI roles you actually hold: provider, developer, deployer, or a mix.AIMS boundary definition, stakeholder matrix, RACI chart
5: Leadership & policyA.2.2Top management approves the AI policy and the values supporting responsible use.Board-approved AI policy, version-controlled acceptable-use policy
6: Planning & riskA.5Assess AI-specific risks and impacts, and set measurable AIMS objectives.AI system impact assessments, risk register, Statement of Applicability
7: Support & resourcesA.4Allocate and document compute, data, tooling, and human competence.Competency logs, compute/tooling inventories, third-party contracts
8: Operation & controlA.6, A.7Control the AI system lifecycle, data lineage, and validation procedures.Model cards, data provenance records, validation logs, version history
9: Performance evaluationA.9Monitor operational metrics and drift, and run internal audits.Telemetry evidence, internal audit reports, human-override logs
10: ImprovementA.9.2Detect nonconformities and drive corrective action.Remediation tracking, corrective action register

Nine control groups, thirty-eight normative controls.

The clause table above tells you what management-system activity to run. Annex A is where the specific controls live, grouped here by what each group is actually for.

A.2

Policies related to AI

The AI policy itself and how it cascades into subordinate policy.

A.3

Internal organisation

Roles, responsibilities, and reporting lines for AI governance.

A.4

Resources for AI systems

Compute, data, tooling, and the competence to use them responsibly.

A.5

Assessing impacts of AI systems

Impact assessment for individuals, groups, and society, not just the organisation.

A.6

AI system life cycle

Controls spanning design, development, verification, deployment, and retirement.

A.7

Data for AI systems

Data quality, provenance, and lineage requirements specific to training and inference.

A.8

Information for interested parties

What you disclose, to whom, and how: the transparency layer.

A.9

Use of AI systems

Operational use controls, monitoring, and the evaluation feeding Clause 9.

A.10

Third-party and customer relationships

Vendor and customer-facing AI risk, including supply chain.

The management-system work carries over. The evidence doesn't.

Because both standards share the Annex SL structure, an existing ISMS gives you working versions of Clauses 4–10 already: context, leadership, planning, support, operation, evaluation, improvement. What it doesn't give you is AI-specific evidence: data provenance records, algorithm explainability logs, and impact assessments covering bias, safety, and fundamental rights. That's the incremental build, not a parallel one.

Risks and controls in this domain.

Pulled live from the Risk Library and Control Library — every entry tagged Governance in the full Risk & Control spine, not a hand-maintained duplicate.

Frequently asked questions

What does ISO/IEC 42001 Clause 5 require?

Top management approves the AI policy and the values supporting responsible use, evidenced through a board-approved AI policy and a version-controlled acceptable-use policy.

What does ISO/IEC 42001 Clause 6 require?

Assessing AI-specific risks and impacts, and setting measurable AIMS objectives, evidenced through AI system impact assessments, a risk register, and a Statement of Applicability.

What is an AI management system (AIMS)?

The roles, evidence, and control cadence that let an organisation prove, at audit, that AI is actually governed day to day, not just documented in a policy PDF nobody operationalises.

Does an existing ISO 27001 ISMS help with ISO/IEC 42001?

Yes for the management-system scaffolding: both standards share the Annex SL structure, so an existing ISMS gives working versions of Clauses 4–10 already. It does not give you the AI-specific evidence: data provenance records, algorithm explainability logs, and impact assessments covering bias, safety, and fundamental rights.

How many controls does ISO/IEC 42001 Annex A contain?

Nine control groups and thirty-eight normative controls, spanning AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, transparency, operational use, and third-party relationships.

This is one of the areas Andrew advises on.

AIMS Implementation is one of five areas of expertise on the services page, grounded in exactly this clause structure.