Black Shard

Insights20 September 2026

ISO 42001 requirements clause by clause, and the audit evidence

ISO/IEC 42001:2023 carries its requirements in clauses 4 to 10, and adds 38 AI-specific controls in Annex A, selected against an AI risk assessment and an AI system impact assessment and recorded in a Statement of Applicability. The standard applies the harmonized structure used across ISO management system standards, so clauses 4 to 10 carry the same numbers and titles as ISO/IEC 27001:2022, with AI-specific sub-clauses added under planning and operation. Certification runs under a separate standard, ISO/IEC 17021-1:2015, which sets the two-stage initial audit and the three-year cycle an accredited certification body works to.

Numbered index cards fanned across a dark desk under violet edge lighting.

What ISO 42001 requires

ISO 42001 requires seven clauses of management system practice, numbered 4 to 10, plus Annex A controls selected by risk. Clauses 1 to 3 hold the scope, the normative references and the terms and definitions. The seven requirement clauses are context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds 38 AI-specific controls grouped under nine control objectives. The organisation selects them against the AI risk assessment and the AI system impact assessment, and records the selection in a Statement of Applicability.

Clause 4.3 requires the scope of the AI management system to be held as documented information. The scope determines the organisation's activities against the requirements on the AI management system, leadership, planning, support, operation, performance, evaluation, improvement, controls and objectives. Certification against the standard is governed by separate documents. An accredited certification body works to ISO/IEC 17021-1:2015, which sets the audit stages, the surveillance pattern and the length of the certification cycle. It also works to ISO/IEC 42006:2025, which supplements ISO/IEC 17021-1:2015 with requirements for bodies that audit and certify an AI management system.

What each clause covers

ISO/IEC 42001:2023 applies the harmonized structure developed to align ISO management system standards: identical clause numbers, clause titles, text, and common terms and core definitions. An organisation already running ISO/IEC 27001:2022 operates that machinery today. ISO/IEC 42001:2023 points it at AI systems. Its Introduction treats the management of concerns related to the trustworthiness of AI systems as one of the crucial management processes to design for, and names those concerns as security, safety, fairness, transparency, data quality and the quality of AI systems throughout their life cycle.

  • Clause 4, context of the organization: determine the external and internal issues that affect the management system (4.1), and the needs and expectations of interested parties (4.2). Determine the scope and hold it as documented information (4.3), and establish the management system itself (4.4). Clause 4.1 also requires the organisation to determine its roles with respect to the AI systems it develops, provides or uses. The roles the standard lists include AI provider, AI producer, AI customer, AI partner, AI subject and relevant authority.
  • Clause 5, leadership: top management demonstrates leadership and commitment (5.1), establishes an AI policy (5.2), and assigns roles, responsibilities and authorities (5.3).
  • Clause 6, planning: define the AI risk assessment process (6.1.2) and the AI risk treatment process that selects controls and produces the Statement of Applicability (6.1.3). Define the AI system impact assessment process (6.1.4), set AI objectives and plan how to achieve them (6.2), and plan changes to the management system (6.3).
  • Clause 7, support: resources (7.1), competence (7.2), awareness (7.3), communication (7.4) and documented information (7.5). The AI policy, the risk assessment and the impact assessment are documented information, created, updated and controlled under 7.5.2 and 7.5.3.
  • Clause 8, operation: plan and control the processes needed to meet the requirements (8.1). Then perform the AI risk assessment (8.2), the AI risk treatment (8.3) and the AI system impact assessment (8.4). Clause 6 requires those three processes to be defined; clause 8 requires them to be performed, and generates the records an audit samples.
  • Clause 9, performance evaluation: monitoring, measurement, analysis and evaluation (9.1), an internal audit programme (9.2.2), and management review with defined inputs (9.3.2) and recorded results (9.3.3).
  • Clause 10, improvement: continual improvement of the suitability, adequacy and effectiveness of the management system (10.1), and nonconformity and corrective action (10.2).

What sits in Annex A?

Annex A of ISO/IEC 42001:2023 is normative and titled reference control objectives and controls. It holds 38 controls under nine control objectives, numbered A.2 to A.10. Annex B, also normative, carries implementation guidance for each control. Annex C and Annex D are informative, covering potential AI-related organizational objectives and risk sources, and use of the management system across domains or sectors.

The standard defines a Statement of Applicability as documentation of all necessary controls with justification for their inclusion or exclusion, and records two positions on Annex A directly. An organisation may not require every control Annex A lists. An organisation may also exceed that list with controls it establishes itself. Every identified risk, and every control established to address it, has to be reflected in the Statement of Applicability.

  • A.2, policies related to AI: a documented policy for the development or use of AI systems, kept aligned with the organisation's other policies and reviewed.
  • A.3, internal organization: roles and responsibilities for AI allocated and defined within the organisation.
  • A.4, resources for AI systems: the data, tooling, computing, systems and human resources an AI system depends on, identified and documented.
  • A.5, assessing impacts of AI systems: the process for assessing the impact an AI system can have on individuals, groups of individuals and societies.
  • A.6, AI system life cycle: controls across objectives, requirements, design, development, verification, validation, deployment, operation and monitoring.
  • A.7, data for AI systems: the provenance, quality, preparation and governance of the data an AI system is developed on and run against.
  • A.8, information for interested parties of AI systems: what users and other affected parties are told about the system and its intended use.
  • A.9, use of AI systems: the responsible use of AI systems by the organisation, including systems it did not build.
  • A.10, third-party and customer relationships: the AI-specific obligations allocated between the organisation, its suppliers and its customers.

The evidence an assessor samples against each clause

ISO/IEC 17021-1:2015 sets what a stage two audit evaluates: the implementation of the management system, including its effectiveness. It names the areas the audit covers on site. Those are information and evidence of conformity, performance monitoring, measuring, reporting and reviewing against key performance objectives and targets, and performance against applicable statutory, regulatory and contractual requirements. They also include operational control of the client's processes, internal auditing and management review, and management responsibility for the client's policies.

ClauseRequirementEvidence an assessor samples
Clause 4, contextScope of the AI management system, and the organisation’s roles with respect to its AI systemsThe documented scope statement, and the record of role determination under 4.1
Clause 5, leadershipAn AI policy, and assigned roles, responsibilities and authoritiesThe AI policy as issued, and the named holders of the AI roles it assigns
Clause 6, planningDefined AI risk assessment, AI risk treatment and AI system impact assessment processes, and AI objectivesThe documented processes, the Statement of Applicability they produce, and the measurable AI objectives
Clause 7, supportCompetence, awareness and controlled documented informationCompetence records for the roles that build, operate or oversee AI systems, and version control on the AI policy
Clause 8, operationThe clause 6 processes performed, and operational planning and controlA completed risk assessment and impact assessment for one named AI system in production
Clause 9, performance evaluationMonitoring and measurement, an internal audit programme, and management reviewAn internal audit report carrying findings, and management review results under 9.3.3
Clause 10, improvementNonconformity and corrective action, and continual improvementA corrective action record closed out against a specific nonconformity

ISO/IEC 42001:2023 clauses 4 to 10: requirement and the evidence an assessor samples

Stage one, stage two, and the three-year cycle

ISO/IEC 17021-1:2015 requires the initial certification audit of a management system to be conducted in two stages. Stage one reviews the documented management system, evaluates the client's preparedness for stage two, and reviews the client's status and understanding of the requirements of the standard. Stage one also obtains the information needed on scope, plans stage two, and evaluates whether the internal audits and management reviews are being planned and performed. Stage two takes place on site and evaluates implementation and effectiveness.

The audit programme for initial certification runs a two-stage initial audit, then surveillance audits in the first and second years following the certification decision, then a recertification audit in the third year before certification expires. The first three-year cycle begins with the certification decision. Surveillance audits run at least once a calendar year, except in recertification years. They are on-site audits and need not cover the full system. Each one reviews the internal audits and the management review, along with the actions taken on nonconformities raised at the previous audit.

Stage one already evaluates whether internal audits and management reviews are being planned and performed. The internal audit and management review cycle therefore has to be operating before the initial audit. Every surveillance audit through the three-year cycle reviews it again.

Running ISO 42001 alongside an existing ISO 27001 system

ISO/IEC 42001:2023 and ISO/IEC 27001:2022 both apply the harmonized structure, so clauses 4 to 10 carry the same numbers and the same titles in each. The Annex A sets differ. ISO/IEC 27001:2022 Annex A holds 93 information security controls organised into four themes, organizational, people, physical and technological, replacing the 14-domain structure of the 2013 edition. ISO/IEC 42001:2023 Annex A holds 38 AI controls under nine objectives. Each management system produces its own Statement of Applicability from its own risk treatment.

One set of policies, one internal audit programme and one management review can serve both systems. The AI risk assessment, the AI system impact assessment and the Annex A selections for ISO/IEC 42001:2023 still have to be recorded as their own line of evidence, because a certification audit samples them against that standard. The two scopes stay distinct. The information security management system is scoped under ISO/IEC 27001:2022 clause 4.3 to the boundaries and applicability the organisation determined for it, considering its clause 4.1 issues, its clause 4.2 requirements, and the interfaces and dependencies between its activities and those performed by other organisations. The AI management system is scoped under clause 4.3 to the AI systems inside its boundary, and to the roles the organisation determined under clause 4.1. Both scope statements have to say so.

Where to start on readiness

Start at clause 4. Determine the organisation's roles with respect to every AI system it develops, provides or uses, including the third-party AI tools a team adopted without a record. Write the scope as documented information. Define the clause 6 processes next, then perform them under clause 8. Run them against systems already in production or close to it, because stage two evaluates the implementation of the management system, including its effectiveness.

Build the Statement of Applicability from the risk treatment. Record the justification for every Annex A control included and every control excluded, and reflect every identified risk and its controls in it. Start the internal audit and management review cycle before the initial audit, because ISO/IEC 17021-1:2015 has stage one evaluate whether both are being planned and performed. A gap analysis and remediation sequence often has to run against a fixed date: a tender close, a board deadline or a certification audit. The ISO 42001 readiness assessment does that work, led by a certified ISO/IEC 27001:2022 Lead Auditor who runs this clause structure for information security management systems.

Tell us what AI you need secured.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au