Skip to main content

Elevate

Elevate Consult · Menú móvil

ISO 42001 Requirements: Clauses 4 to 10 and Annex A Controls

ISO 42001 requirements come in two parts that a certification audit examines together: the management system clauses numbered 4 through 10, which define how an organization runs its AI management system, and the Annex A controls, which are the AI-specific measures the organization selects and applies. Understanding both, and how they connect, is what turns ISO 42001 from an abstract standard into a concrete program you can build and evidence. This guide maps the clause requirements, explains the role of the Annex A controls, and sets out the evidence an AI management system needs before certification.

The reason to see the requirements as two connected parts rather than one long list is that they do different jobs. The clauses require you to build and operate a management system, a repeatable way of governing AI, while the Annex A controls are the specific safeguards that system puts in place based on your risks. A certification audit checks that the system exists and runs, and that the controls you selected are implemented and effective, so preparing for one without the other leaves half the requirement unmet.

The Two Parts of ISO 42001 Requirements

The first part of ISO 42001 requirements is the set of management system clauses, 4 through 10, that follow the harmonized structure ISO uses across its management system standards. These are the certifiable obligations: they require an organization to establish the context and scope of its AI management system, provide leadership and an AI policy, plan for AI risks and opportunities, support the system with resources and competence, operate it, evaluate its performance, and improve it. They describe the system, not the individual safeguards.

The second part is Annex A, a set of AI-specific controls that the organization draws on to treat the risks its planning identifies. Where the clauses are mandatory in full, the controls are selected according to relevance, and the organization documents which apply and why in a Statement of Applicability. The two parts work as a pair: the clauses build the system that decides, applies, and evidences the controls, and the controls are the concrete measures the system manages. Certification requires both to be in place and working.

The Management System Clauses (4 to 10)

The clauses are where most of the management system requirement lives, and each adds a distinct obligation. The table maps them to what each requires of an AI management system.

ClauseWhat it requires
4. Context of the organizationDetermine the AIMS scope, the internal and external issues that affect it, and the interested parties and their needs
5. LeadershipSecure top management commitment, establish an AI policy, and assign roles and responsibilities
6. PlanningAssess and address AI risks and opportunities, conduct AI risk and impact assessment, and set objectives
7. SupportProvide the resources, competence, awareness, communication, and documented information the system needs
8. OperationImplement the operational planning and controls needed to manage AI across its lifecycle
9. Performance evaluationMonitor, measure, and analyze the system, conduct internal audits, and hold management reviews
10. ImprovementAddress nonconformities with corrective action and continually improve the AIMS

The clauses build on one another rather than standing alone: context and leadership set the direction, planning translates risks into objectives and control decisions, support and operation put the system into practice, and performance evaluation and improvement keep it working over time. An auditor examines each clause, but also whether they connect into a coherent system, so an organization that treats them as a checklist of separate boxes rather than a working cycle tends to struggle. The distinctive AI element sits mainly in Clause 6, where the AI risk assessment and the AI impact assessment, the consideration of how an AI system affects individuals and society, drive which controls the organization needs.

The Annex A Controls

Annex A sets out the AI-specific controls an organization draws on to treat the risks identified in its planning, spanning areas such as AI policies, internal organization and roles, resources and data for AI systems, impact assessment, the AI system lifecycle, and information for interested parties. Annex B of the standard provides implementation guidance for these controls, and the organization records which controls apply, and the justification for any excluded, in its Statement of Applicability. The controls are selected by risk rather than adopted wholesale, so two organizations with different AI risk profiles will apply different subsets.

Because the enumerated control set is what most implementers want to work through line by line, it is treated in depth in the ISO 42001 controls overview, which walks the Annex A controls in detail. For organizations that already hold ISO 27001, the guide to ISO 42001 and ISO 27001 Annex A overlap and gaps shows where existing security controls carry over and where the AI-specific requirements go beyond them. The key requirement-level point is that the controls are not a fixed compliance list but a menu the management system selects from and justifies.

The Evidence an AIMS Needs

Meeting ISO 42001 requirements is ultimately demonstrated through evidence, because a certification audit assesses documented information and records, not intentions. The evidence an AI management system needs includes the AI policy and the defined scope, the AI risk assessment and the AI impact assessment, the Statement of Applicability recording control decisions, the objectives and plans to meet them, records of the operational controls in use, and the results of monitoring, internal audits, and management reviews. Together these show both that the system was designed to the standard and that it operates.

The evidence requirement is where implementation most often falls short, because building a system is visible work while evidencing it is easy to defer. An organization that made good decisions but cannot show the risk assessment that drove them, or the internal audit that checked them, has a documentation gap an auditor will treat as a conformity gap. The AIMS Manual gives organizations a starting structure for the documented information the standard expects, and AI governance training that produces audit evidence helps teams generate the records an audit looks for as a byproduct of running the system.

How the Requirements Fit Together

The clauses, the controls, and the evidence form a single chain, and seeing it as one is what makes the requirements manageable. The clauses require the organization to understand its context, assess its AI risks and impacts, and decide how to treat them. Those decisions determine which Annex A controls apply, recorded in the Statement of Applicability. The controls are then implemented and operated, and the evidence, from the risk assessment through the management review, proves that the whole chain functioned. Break any link and the requirement is unmet: controls without a risk assessment behind them are arbitrary, and a risk assessment with no controls or evidence behind it is inert.

This is also why ISO 42001 rewards a system built once and run continuously rather than assembled for an audit. Because performance evaluation and improvement are themselves requirements, the standard expects the system to have operated, been audited internally, and been reviewed by management before a certification audit, which cannot happen in a last-minute push. An advisor who holds the ISO 42001 lead auditor credential can help ensure the chain is complete and evidenced the way an auditor will expect to see it.

How to Meet ISO 42001 Requirements Before Certification

Meeting the requirements before a certification audit follows the chain in order. Start by establishing context, leadership, and scope, then conduct the AI risk and impact assessment that drives everything downstream. Use those results to select the Annex A controls, record them in the Statement of Applicability, and implement them. Then operate the system long enough to generate evidence, run an internal audit, and hold a management review, so that by the time the certification audit arrives, the system has demonstrably worked rather than merely been designed.

The sequence matters because the later requirements depend on the earlier ones having run for a while, which is why organizations that plan backward from a certification date, allowing time for the system to operate and be evidenced, fare better than those that treat certification as a document exercise. The guide to getting ISO 42001 certified covers that path in full. The requirements are demanding but coherent, and an organization that builds the system as a working cycle meets them as a matter of course.

Where Organizations Fall Short of ISO 42001 Requirements

The requirements organizations most often fail to meet are not the obscure ones but the AI-specific and evidence-related ones, and knowing them in advance is the most practical use of a requirements map. The most common shortfall sits in Clause 6: an AI impact assessment done thinly or skipped, when it is the analysis that distinguishes an AI management system from a generic one and drives which controls are needed. Without a genuine impact assessment, the control selection that follows has no defensible basis, and an auditor sees a Statement of Applicability that asserts choices it cannot justify.

A related shortfall is control selection disconnected from risk. When Annex A controls are adopted because they seem prudent rather than because the risk and impact assessment called for them, the Statement of Applicability becomes a list rather than a set of reasoned decisions, and the requirement that controls treat identified risks goes unmet even though controls are in place. The reverse also occurs, where risks are identified but no control or evidence addresses them, leaving the chain broken at the other end.

The final common gap is in Clause 9 and the evidence it demands. Organizations frequently reach a certification audit having built the system but not yet run it as a cycle, with no completed internal audit and no management review, so there is no evidence the system operated and improved. Because those activities are themselves requirements and take time to perform, they cannot be manufactured at the end. The pattern across all three shortfalls is that the requirements are met on paper but not as a functioning, evidenced system, which is the distinction a certification audit is designed to draw.

Conclusion

ISO 42001 requirements are the management system clauses 4 through 10 and the Annex A controls, connected by a chain that runs from context and risk assessment through control selection, implementation, and evidence. The clauses build the system, the controls are the safeguards it selects by risk, and the evidence proves both were designed to the standard and actually operated. A certification audit examines the whole chain, so meeting the requirements means building and running a coherent system, not assembling a document set.

The most reliable path is to build the system as a continuous cycle, generate its evidence as a byproduct of operation, and confirm the chain is complete before the certification audit. To map your organization against ISO 42001 requirements and build an AIMS that meets them, download the AIMS Manual or book a call with an Elevate advisor.

Key Takeaways

ISO 42001 requirements have two connected parts, the management system clauses 4 through 10 and the Annex A controls, joined by an evidence chain.

  • The clauses build the system: clauses 4 through 10 require context, leadership and an AI policy, planning with AI risk and impact assessment, support, operation, performance evaluation, and improvement.
  • Annex A controls are selected by risk: they are not a fixed list but a set the organization draws from based on its AI risks, recorded and justified in a Statement of Applicability.
  • Clause 6 carries the AI-specific core: the AI risk assessment and the AI impact assessment drive which controls an organization needs, distinguishing an AIMS from a generic management system.
  • Evidence is where requirements are proven: a certification audit assesses documented information and records, so the risk assessment, Statement of Applicability, internal audit, and management review must exist and be current.
  • The requirements form one chain: context and risk drive control selection, controls are implemented and operated, and evidence proves the chain worked, so a break at any link leaves the requirement unmet.

FAQs

Q1. What are the requirements of ISO 42001? ISO 42001 requirements come in two connected parts. The first is the set of management system clauses, numbered 4 through 10, that require an organization to establish the context and scope of its AI management system, provide leadership and an AI policy, plan for AI risks and opportunities, support and operate the system, evaluate its performance, and improve it. The second is Annex A, a set of AI-specific controls the organization selects by risk and records in a Statement of Applicability. A certification audit examines both the system built by the clauses and the controls it applies.

Q2. What do clauses 4 to 10 of ISO 42001 require? Clauses 4 through 10 follow the harmonized structure ISO uses across its management system standards. Clause 4 requires determining the context and scope of the AI management system. Clause 5 requires leadership commitment, an AI policy, and assigned roles. Clause 6 requires assessing and addressing AI risks and opportunities, including AI risk and impact assessment, and setting objectives. Clause 7 requires resources, competence, and documented information. Clause 8 requires operating the system and its controls. Clause 9 requires monitoring, internal audit, and management review. Clause 10 requires corrective action and continual improvement.

Q3. What are the Annex A controls in ISO 42001? Annex A of ISO 42001 sets out the AI-specific controls an organization draws on to treat the risks identified in its planning, covering areas such as AI policies, internal organization and roles, resources and data for AI systems, impact assessment, the AI system lifecycle, and information for interested parties. Annex B provides implementation guidance. The controls are selected according to relevance rather than adopted wholesale, and the organization records which apply, with justification for any excluded, in its Statement of Applicability. The enumerated control set is worked through in detail in a dedicated controls overview.

Q4. What evidence does an ISO 42001 audit require? A certification audit assesses documented information and records rather than intentions, so the evidence an AI management system needs includes the AI policy and defined scope, the AI risk assessment and AI impact assessment, the Statement of Applicability recording control decisions, the objectives and plans to meet them, records of the operational controls in use, and the results of monitoring, internal audits, and management reviews. Together these demonstrate that the system was both designed to the standard and actually operated. Missing evidence is treated as a conformity gap even when the underlying work was done.

Q5. How do the ISO 42001 clauses and controls fit together? They form a single chain. The clauses require the organization to understand its context and assess its AI risks and impacts, and those results determine which Annex A controls apply, recorded in the Statement of Applicability. The controls are then implemented and operated, and evidence from the risk assessment through the management review proves the chain functioned. Controls without a risk assessment behind them are arbitrary, and a risk assessment with no controls or evidence is inert, so meeting ISO 42001 requirements means completing every link in the chain, not satisfying the clauses and controls separately.