Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What are the ISO 42001 Annex A controls?
Last verifiedISO 42001 Annex A defines nine AI control areas. Each has a control objective to address if applicable in the SoA; implementation is the organisation's choice. Not legal advice.
Controls explained, last verified 10 September 2026 against ISO/IEC 42001:2023 Annex A and Annex B. Nine themes match the framework guide on this site. Not legal advice.
Control objective vs implementation
The standard requires YOU to determine which Annex A controls apply and to achieve their objectives. Annex B gives implementation guidance — advisory, not mandatory wording. One organisation might use a committee; another a RACI matrix. Neither is mandated as the only approach.
Internal organization
Objective: define roles, responsibilities, and reporting for AI governance. Example: AI governance committee, named AIMS manager, escalation to risk committee.
Resources for AI systems
Objective: identify and provide resources — data, tooling, compute, skilled people. Example: resource budget line, capacity planning for GPU/ML ops.
Assessing impacts of AI systems
Objective: assess impacts on individuals, groups, and society. Example: AI system impact assessment per ISO/IEC 42005-style process before deployment.
AI system life cycle
Objective: govern development from objectives through verification, deployment, and retirement. Example: stage gates, model cards, change control for retraining.
Data for AI systems
Objective: manage data quality, provenance, and governance across the lifecycle. Example: dataset catalogues, bias checks, licensing records.
Information for interested parties
Objective: provide documentation and transparency to users and affected parties. Example: user-facing model limitations, internal runbooks.
Use of AI systems
Objective: ensure responsible operation and monitoring in production. Example: drift monitoring, human oversight for high-impact decisions.
Third-party and customer relationships
Objective: allocate AI responsibilities across suppliers, partners, and customers. Example: DPAs with model vendors, customer AI addenda.
What to do now
- Walk each theme with YOUR SoA — mark applicable, justify exclusions.
- Assign one owner per applicable theme before writing procedures.
- Open the evidence-requirements page to list artifacts per theme.
Checklist
- ☐ All nine themes considered in SoA?
- ☐ Implementation examples documented without claiming they are mandatory?
- ☐ Impact assessment process linked to lifecycle gates?
Where this shows up in ShipReady Metrics
The 24-framework crosswalk includes ISO 42001 with canonical control mapping and crosswalk-density honesty. AI risk register entries can tag Annex A themes YOU assign. Coverage display is not a pass/fail verdict.