Policy Register

ISO/IEC 42001:2023

Requires an AI policy aligned with the other organisational policies and reviewed, AI roles, a reporting channel, an impact assessment process, responsible-use rules, event logging on AI systems and terms for AI suppliers.

Tick ISO/IEC 42001:2023 on the register and these documents are expected and these clauses attach. Open the standard.

The documents it expects

8 documents expected

Each becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).

Governance and the management system

Assets, data and classification

Suppliers and third parties

Resilience and incidents

AI and automated decisions

Conduct

Every document it reaches

12 types carry at least one of its clauses

The clauses, quoted

20 of 38 in the framework

Requirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.

ISO 42001 A.10.3 Suppliers

Establish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.

Evidence an auditor accepts: supplier assessment criteria covering responsible AI; completed assessments for AI suppliers including model, dataset and component providers; contract terms binding suppliers to the organization's AI requirements
Common gap: standard security due diligence used with nothing AI specific
Source: ISO/IEC 42001:2023
ISO 42001 A.2.2 AI policy

The organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.

Evidence an auditor accepts: AI policy; approval records; aI-specific policy (distinct from general IT policy)
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.3 Alignment with other organizational policies

The AI policy shall be aligned with other organizational policies (privacy, security, quality, ethics, HR).

Evidence an auditor accepts: Policy cross-reference matrix; mapping AI policy to ISMS, PIMS, QMS, HR policies; conflict resolution evidence
Common gap: Are policy conflicts identified and resolved?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.4 Review of the AI policy

The AI policy shall be reviewed at planned intervals or if significant changes occur to ensure continuing suitability, adequacy, and effectiveness.

Evidence an auditor accepts: Policy review schedule; review records; annual review evidence
Common gap: Has the policy been reviewed since publication or is it stale?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.2 AI roles and responsibilities

Roles and responsibilities for AI shall be defined and allocated according to the organization's needs.

Evidence an auditor accepts: Role descriptions; rACI matrix; org chart
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.3 Reporting of concerns

A process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.

Evidence an auditor accepts: Concern reporting procedure; whistleblower channel evidence; concern register
Common gap: Is the reporting channel actually used and concerns addressed?
Source: ISO/IEC 42001:2023
ISO 42001 A.4.6 Human resources

The organization shall document information about the human resources and their competencies utilized.

Evidence an auditor accepts: Skills matrix; competence records; roles, expertise, certifications
Common gap: Are dependencies on individual experts identified as key-person risks?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.2 AI system impact assessment process

The organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.

Evidence an auditor accepts: AI impact assessment procedure; assessment template; methodology covering individuals, groups, societies
Common gap: Does the procedure require consultation with affected stakeholders?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.3 Documentation of AI system impact assessments

Documented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.

Evidence an auditor accepts: Completed assessments; distribution records; per-system assessment reports
Common gap: Are assessments made available externally where required (e.g., EU AI Act)?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.4 Assessing AI system impact on individuals or groups

The organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.

Evidence an auditor accepts: Per-system impact assessments; fairness analysis; privacy impact (link to PIA where relevant)
Common gap: Are demographic-specific impacts analyzed where relevant?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.1.3 Processes for responsible design and development of AI systems

The organization shall define and document specific processes for the responsible design and development of AI systems.

Evidence an auditor accepts: AI development lifecycle (AI SDLC) procedure; design review records; stage gates and reviews
Common gap: Are responsible AI checkpoints embedded in SDLC or bolted on?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.4 AI system verification and validation

AI systems shall be verified and validated, and the results documented. Verification confirms requirements are met; validation confirms intended use is achieved.

Evidence an auditor accepts: V&V plans; test results; acceptance reports
Common gap: Are V&V results signed off independently from developers?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Evidence an auditor accepts: Operations runbooks; monitoring dashboards; incident logs
Common gap: Is monitoring active and alerts acted upon?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.8 AI system event logging

Event logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.

Evidence an auditor accepts: Logging standards; log samples; log retention policy
Common gap: Are logs sufficient to reconstruct an incident or audit a decision?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.2 Data for development and enhancement of AI systems

The organization shall define, document, and implement processes to determine data requirements and ensure data quality for AI system development and enhancement.

Evidence an auditor accepts: Data requirements specification; data quality procedure; defined data requirements per AI system
Common gap: Is data quality measured or assumed?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.4 Quality of data for AI systems

The organization shall define and document quality requirements for data and ensure they are met.

Evidence an auditor accepts: Data quality standards; quality assessment reports; quality dimensions defined (accuracy, completeness, representativeness, bias)
Common gap: Is representativeness and bias assessed for training data?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.5 Data provenance

The organization shall document the provenance of data used in AI systems to enable evaluation and traceability.

Evidence an auditor accepts: Provenance records; lineage diagrams; end-to-end data lineage from source to model
Common gap: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
ISO 42001 A.8.4 Communication of incidents

The organization shall determine and document a plan for communicating incidents to relevant interested parties.

Evidence an auditor accepts: Incident communication plan; incident notification records; notification criteria and timing
Common gap: Is notification timing aligned to regulatory requirements (e.g., EU AI Act, GDPR)?
Source: ISO/IEC 42001:2023
ISO 42001 A.9.2 Processes for responsible use of AI systems

The organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.

Evidence an auditor accepts: Responsible use procedure; acceptable use policy for AI; training records
Source: ISO/IEC 42001:2023
ISO 42001 A.9.4 Intended use of the AI system

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

Evidence an auditor accepts: Intended use statements; use case approval records; monitoring of use
Common gap: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023

See what it expects of your list

Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.

Build a register