ISO/IEC 42001:2023
Requires an AI policy aligned with the other organisational policies and reviewed, AI roles, a reporting channel, an impact assessment process, responsible-use rules, event logging on AI systems and terms for AI suppliers.
Tick ISO/IEC 42001:2023 on the register and these documents are expected and these clauses attach. Open the standard.
The documents it expects
8 documents expectedEach becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).
Governance and the management system
- Information security roles and responsibilities (record; accepted folded into the information security policy): ISO 42001 A.3.2. Owner: The information security lead (CISO or ISMS manager). No template yet.
Assets, data and classification
- Data governance policy (policy): ISO 42001 A.7.2, ISO 42001 A.7.4, ISO 42001 A.7.5. Owner: The AI governance lead (CTO, CDO or head of data science). Template: Data governance policy.
Suppliers and third parties
- Supplier and third-party security policy (policy): ISO 42001 A.10.3. Owner: Procurement or the vendor manager, with the information security lead. Template: Third party risk management policy.
Resilience and incidents
- Incident response plan (plan): ISO 42001 A.8.4. Owner: The information security lead (CISO or ISMS manager). Template: Incident response plan.
AI and automated decisions
- AI governance policy (policy): ISO 42001 A.2.2, ISO 42001 A.2.3, ISO 42001 A.2.4, ISO 42001 A.3.2, ISO 42001 A.3.3. Owner: The AI governance lead (CTO, CDO or head of data science). Template: Ai governance policy.
- AI system impact assessment procedure (procedure; accepted folded into the ai governance policy): ISO 42001 A.5.2, ISO 42001 A.5.3, ISO 42001 A.5.4. Owner: The AI governance lead (CTO, CDO or head of data science). No template yet.
- AI use policy (acceptable AI use) (policy): ISO 42001 A.2.2, ISO 42001 A.9.2, ISO 42001 A.9.4. Owner: The AI governance lead (CTO, CDO or head of data science). Template: Ai acceptable use policy.
Conduct
- Whistleblowing policy (policy): ISO 42001 A.3.3. Owner: Legal or the compliance officer. Template: Whistleblower and reporting policy.
Every document it reaches
12 types carry at least one of its clausesThe clauses, quoted
20 of 38 in the frameworkRequirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.
ISO 42001 A.10.3 SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
Common gap: standard security due diligence used with nothing AI specific
Source: ISO/IEC 42001:2023
ISO 42001 A.2.2 AI policyThe organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.3 Alignment with other organizational policiesThe AI policy shall be aligned with other organizational policies (privacy, security, quality, ethics, HR).
Common gap: Are policy conflicts identified and resolved?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.4 Review of the AI policyThe AI policy shall be reviewed at planned intervals or if significant changes occur to ensure continuing suitability, adequacy, and effectiveness.
Common gap: Has the policy been reviewed since publication or is it stale?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.2 AI roles and responsibilitiesRoles and responsibilities for AI shall be defined and allocated according to the organization's needs.
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.3 Reporting of concernsA process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.
Common gap: Is the reporting channel actually used and concerns addressed?
Source: ISO/IEC 42001:2023
ISO 42001 A.4.6 Human resourcesThe organization shall document information about the human resources and their competencies utilized.
Common gap: Are dependencies on individual experts identified as key-person risks?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.2 AI system impact assessment processThe organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.
Common gap: Does the procedure require consultation with affected stakeholders?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.3 Documentation of AI system impact assessmentsDocumented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.
Common gap: Are assessments made available externally where required (e.g., EU AI Act)?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.4 Assessing AI system impact on individuals or groupsThe organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.
Common gap: Are demographic-specific impacts analyzed where relevant?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.1.3 Processes for responsible design and development of AI systemsThe organization shall define and document specific processes for the responsible design and development of AI systems.
Common gap: Are responsible AI checkpoints embedded in SDLC or bolted on?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.4 AI system verification and validationAI systems shall be verified and validated, and the results documented. Verification confirms requirements are met; validation confirms intended use is achieved.
Common gap: Are V&V results signed off independently from developers?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
Common gap: Is monitoring active and alerts acted upon?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.8 AI system event loggingEvent logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.
Common gap: Are logs sufficient to reconstruct an incident or audit a decision?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.2 Data for development and enhancement of AI systemsThe organization shall define, document, and implement processes to determine data requirements and ensure data quality for AI system development and enhancement.
Common gap: Is data quality measured or assumed?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.4 Quality of data for AI systemsThe organization shall define and document quality requirements for data and ensure they are met.
Common gap: Is representativeness and bias assessed for training data?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.5 Data provenanceThe organization shall document the provenance of data used in AI systems to enable evaluation and traceability.
Common gap: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
ISO 42001 A.8.4 Communication of incidentsThe organization shall determine and document a plan for communicating incidents to relevant interested parties.
Common gap: Is notification timing aligned to regulatory requirements (e.g., EU AI Act, GDPR)?
Source: ISO/IEC 42001:2023
ISO 42001 A.9.2 Processes for responsible use of AI systemsThe organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.
Source: ISO/IEC 42001:2023
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
Common gap: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023
See what it expects of your list
Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.
Build a register