ISO/IEC 42001:2023
The register cites 20 of its 38 clauses, on 12 policy types. Rendered when the buyer ticks "ISO/IEC 42001:2023".
Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Open the standard on the compliance platform. What it expects of a policy set: the ISO 42001 regime page.
Clauses cited
20 of 38ISO 42001 A.2.2 AI policyThe organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.3 Alignment with other organizational policiesThe AI policy shall be aligned with other organizational policies (privacy, security, quality, ethics, HR).
Common gap: Are policy conflicts identified and resolved?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.4 Review of the AI policyThe AI policy shall be reviewed at planned intervals or if significant changes occur to ensure continuing suitability, adequacy, and effectiveness.
Common gap: Has the policy been reviewed since publication or is it stale?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.2 AI roles and responsibilitiesRoles and responsibilities for AI shall be defined and allocated according to the organization's needs.
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.3 Reporting of concernsA process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.
Common gap: Is the reporting channel actually used and concerns addressed?
Source: ISO/IEC 42001:2023
ISO 42001 A.4.6 Human resourcesThe organization shall document information about the human resources and their competencies utilized.
Common gap: Are dependencies on individual experts identified as key-person risks?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.2 AI system impact assessment processThe organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.
Common gap: Does the procedure require consultation with affected stakeholders?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.3 Documentation of AI system impact assessmentsDocumented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.
Common gap: Are assessments made available externally where required (e.g., EU AI Act)?
Source: ISO/IEC 42001:2023
ISO 42001 A.5.4 Assessing AI system impact on individuals or groupsThe organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.
Common gap: Are demographic-specific impacts analyzed where relevant?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.1.3 Processes for responsible design and development of AI systemsThe organization shall define and document specific processes for the responsible design and development of AI systems.
Common gap: Are responsible AI checkpoints embedded in SDLC or bolted on?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.4 AI system verification and validationAI systems shall be verified and validated, and the results documented. Verification confirms requirements are met; validation confirms intended use is achieved.
Common gap: Are V&V results signed off independently from developers?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
Common gap: Is monitoring active and alerts acted upon?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.8 AI system event loggingEvent logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.
Common gap: Are logs sufficient to reconstruct an incident or audit a decision?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.2 Data for development and enhancement of AI systemsThe organization shall define, document, and implement processes to determine data requirements and ensure data quality for AI system development and enhancement.
Common gap: Is data quality measured or assumed?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.4 Quality of data for AI systemsThe organization shall define and document quality requirements for data and ensure they are met.
Common gap: Is representativeness and bias assessed for training data?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.5 Data provenanceThe organization shall document the provenance of data used in AI systems to enable evaluation and traceability.
Common gap: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
ISO 42001 A.8.4 Communication of incidentsThe organization shall determine and document a plan for communicating incidents to relevant interested parties.
Common gap: Is notification timing aligned to regulatory requirements (e.g., EU AI Act, GDPR)?
Source: ISO/IEC 42001:2023
ISO 42001 A.9.2 Processes for responsible use of AI systemsThe organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.
Source: ISO/IEC 42001:2023
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
Common gap: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023
ISO 42001 A.10.3 SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
Common gap: standard security due diligence used with nothing AI specific
Source: ISO/IEC 42001:2023
See which clauses your list answers
Paste the list and every document names the clauses behind it, filtered to the regimes that apply to you. Eight documents free, no account.
Build a register