Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What are the ISO 42001 Annex A controls?

Last verified

ISO 42001 Annex A defines nine AI control areas. Each has a control objective to address if applicable in the SoA; implementation is the organisation's choice. Not legal advice.

Controls explained, last verified 10 September 2026 against ISO/IEC 42001:2023 Annex A and Annex B. Nine themes match the framework guide on this site. Not legal advice.

Control objective vs implementation

The standard requires YOU to determine which Annex A controls apply and to achieve their objectives. Annex B gives implementation guidance — advisory, not mandatory wording. One organisation might use a committee; another a RACI matrix. Neither is mandated as the only approach.

Internal organization

Objective: define roles, responsibilities, and reporting for AI governance. Example: AI governance committee, named AIMS manager, escalation to risk committee.

Resources for AI systems

Objective: identify and provide resources — data, tooling, compute, skilled people. Example: resource budget line, capacity planning for GPU/ML ops.

Assessing impacts of AI systems

Objective: assess impacts on individuals, groups, and society. Example: AI system impact assessment per ISO/IEC 42005-style process before deployment.

AI system life cycle

Objective: govern development from objectives through verification, deployment, and retirement. Example: stage gates, model cards, change control for retraining.

Data for AI systems

Objective: manage data quality, provenance, and governance across the lifecycle. Example: dataset catalogues, bias checks, licensing records.

Information for interested parties

Objective: provide documentation and transparency to users and affected parties. Example: user-facing model limitations, internal runbooks.

Use of AI systems

Objective: ensure responsible operation and monitoring in production. Example: drift monitoring, human oversight for high-impact decisions.

Third-party and customer relationships

Objective: allocate AI responsibilities across suppliers, partners, and customers. Example: DPAs with model vendors, customer AI addenda.

What to do now

  • Walk each theme with YOUR SoA — mark applicable, justify exclusions.
  • Assign one owner per applicable theme before writing procedures.
  • Open the evidence-requirements page to list artifacts per theme.

Checklist

  • ☐ All nine themes considered in SoA?
  • ☐ Implementation examples documented without claiming they are mandatory?
  • ☐ Impact assessment process linked to lifecycle gates?

Where this shows up in ShipReady Metrics

The 24-framework crosswalk includes ISO 42001 with canonical control mapping and crosswalk-density honesty. AI risk register entries can tag Annex A themes YOU assign. Coverage display is not a pass/fail verdict.

Frequently asked questions