Skip to content

Evidence request lists

ISO/IEC 42001:2023

Evidence request list. 83 controls, 74 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Annex A AIMS controls - A.10 Third-party and customer relationships

A.10.2
Allocating responsibilities

Ensure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.

Artefacts an auditor will ask for
  • RACI or equivalent covering each life cycle stage and each external party
  • contract clauses that state who is accountable for what
  • evidence the allocation is reviewed when the arrangement changes
Where this commonly fails
  • responsibilities assumed rather than allocated
  • gaps where no party owns a life cycle stage
  • allocation never revisited after a supplier change
A.10.3
Suppliers

Establish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.

Artefacts an auditor will ask for
  • supplier assessment criteria covering responsible AI
  • completed assessments for AI suppliers including model, dataset and component providers
  • contract terms binding suppliers to the organization's AI requirements
Where this commonly fails
  • standard security due diligence used with nothing AI specific
  • datasets and pre-trained models sourced with no assessment
  • no reassessment when the supplier changes its model
A.10.4
Customers

Ensure the organization's approach to the responsible development and use of AI systems takes account of customer expectations and needs.

Artefacts an auditor will ask for
  • record of customer expectations gathered for AI systems
  • evidence those expectations fed the AI policy or system requirements
  • customer facing terms describing responsible AI commitments
Where this commonly fails
  • customer expectations never captured
  • commitments made in sales material that the AIMS does not implement
  • no route for customers to raise AI concerns

Annex A AIMS controls - A.2 Policies related to AI

A.2.2
AI policy

The organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.

Artefacts an auditor will ask for
  • AI policy
  • Approval records
  • AI-specific policy (distinct from general IT policy)
  • Coverage of development, deployment, use
  • Strategic alignment evidence
Where this commonly fails
  • Does the AI policy address AI-specific concerns beyond restating IT policy?
A.2.3
Alignment with other organizational policies

The AI policy shall be aligned with other organizational policies (privacy, security, quality, ethics, HR).

Artefacts an auditor will ask for
  • Policy cross-reference matrix
  • Mapping AI policy to ISMS, PIMS, QMS, HR policies
  • Conflict resolution evidence
Where this commonly fails
  • Are policy conflicts identified and resolved?
A.2.4
Review of the AI policy

The AI policy shall be reviewed at planned intervals or if significant changes occur to ensure continuing suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Policy review schedule
  • Review records
  • Annual review evidence
  • Trigger-based reviews after major changes
  • Updated version with change history
Where this commonly fails
  • Has the policy been reviewed since publication or is it stale?

Annex A AIMS controls - A.3 Internal organization

A.3.2
AI roles and responsibilities

Roles and responsibilities for AI shall be defined and allocated according to the organization's needs.

Artefacts an auditor will ask for
  • Role descriptions
  • RACI matrix
  • Org chart
  • AI-specific roles (AI ethics officer, model risk manager, AI system owner, data steward)
  • Allocation across functions
  • Segregation of duties where appropriate
Where this commonly fails
  • Are AI-specific roles defined or rolled into existing IT roles?
A.3.3
Reporting of concerns

A process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.

Artefacts an auditor will ask for
  • Concern reporting procedure
  • Whistleblower channel evidence
  • Concern register
  • Documented channels (anonymous if possible)
  • Non-retaliation policy
  • Investigation and resolution records
Where this commonly fails
  • Is the reporting channel actually used and concerns addressed?

Annex A AIMS controls - A.4 Resources for AI systems

A.4.2
Resource documentation

Resources needed for the AI life cycle (data, tooling, compute, human) shall be identified and documented.

Artefacts an auditor will ask for
  • Resource inventory
  • Capacity planning records
  • Per-system resource documentation
  • Compute, storage, data, human expertise listed
Where this commonly fails
  • Is resource documentation maintained per AI system or only generic?
A.4.3
Data resources

As part of identifying resources, the organization shall document information about the data resources utilized for the AI system.

Artefacts an auditor will ask for
  • Data inventory
  • Data lineage records
  • Datasheets
  • Data sources, types, volumes, sensitivity
  • Provenance and licensing
  • Data quality metadata
Where this commonly fails
  • Is data lineage maintained from source to model?
A.4.4
Tooling resources

The organization shall document information about the tooling resources utilized for the AI system.

Artefacts an auditor will ask for
  • Tooling inventory
  • Tool risk assessments
  • Development frameworks, libraries, MLOps platforms
  • Version control
  • License and security review of tools
Where this commonly fails
  • Are open-source AI tools risk-assessed for security and licensing?
A.4.5
System and computing resources

The organization shall document information about the system and computing resources utilized.

Artefacts an auditor will ask for
  • Infrastructure inventory
  • Capacity plans
  • Compute (CPU/GPU), storage, network resources
  • Cloud vs on-prem allocation
  • Environmental impact noted where relevant
Where this commonly fails
  • Is environmental impact of AI compute considered?
A.4.6
Human resources

The organization shall document information about the human resources and their competencies utilized.

Artefacts an auditor will ask for
  • Skills matrix
  • Competence records
  • Roles, expertise, certifications
  • Reliance on external expertise documented
Where this commonly fails
  • Are dependencies on individual experts identified as key-person risks?

Annex A AIMS controls - A.5 Assessing impacts of AI systems

A.5.2
AI system impact assessment process

The organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.

Artefacts an auditor will ask for
  • AI impact assessment procedure
  • Assessment template
  • Methodology covering individuals, groups, societies
  • Trigger criteria (new system, material change)
  • Roles for conducting and approving assessments
Where this commonly fails
  • Does the procedure require consultation with affected stakeholders?
A.5.3
Documentation of AI system impact assessments

Documented information on the AI system impact assessment shall be maintained and made available to relevant interested parties.

Artefacts an auditor will ask for
  • Completed assessments
  • Distribution records
  • Per-system assessment reports
  • Availability to affected parties (e.g., model card)
  • Version history
Where this commonly fails
  • Are assessments made available externally where required (e.g., EU AI Act)?
A.5.4
Assessing AI system impact on individuals or groups

The organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.

Artefacts an auditor will ask for
  • Per-system impact assessments
  • Fairness analysis
  • Privacy impact (link to PIA where relevant)
  • Autonomy and rights considerations
Where this commonly fails
  • Are demographic-specific impacts analyzed where relevant?
A.5.5
Assessing societal impacts of AI systems

The organization shall assess and document the potential societal impacts of its AI systems.

Artefacts an auditor will ask for
  • Societal impact analyses
  • Impacts on labor, environment, democracy, public discourse
  • Mitigations or acknowledgements
Where this commonly fails
  • Are societal impacts considered or dismissed as out of scope?

Annex A AIMS controls - A.6 AI system life cycle

A.6.1.2
Objectives for responsible development of AI systems

The organization shall identify and document objectives to guide the responsible development of AI systems.

Artefacts an auditor will ask for
  • Responsible AI objectives
  • Development standards
  • Documented objectives (fairness, robustness, transparency, accountability, safety, privacy)
  • Linkage to risk treatment and policy
Where this commonly fails
  • Are objectives integrated into development methodology, not just a poster?
A.6.1.3
Processes for responsible design and development of AI systems

The organization shall define and document specific processes for the responsible design and development of AI systems.

Artefacts an auditor will ask for
  • AI development lifecycle (AI SDLC) procedure
  • Design review records
  • Stage gates and reviews
  • Responsible AI checkpoints
  • Sign-off records
Where this commonly fails
  • Are responsible AI checkpoints embedded in SDLC or bolted on?
A.6.2.2
AI system requirements and specification

Requirements and specifications shall be defined for new or substantially modified AI systems, including responsible AI requirements.

Artefacts an auditor will ask for
  • Requirements specifications
  • Acceptance criteria
  • Functional and non-functional requirements
  • Fairness, robustness, explainability requirements
  • Approval records
Where this commonly fails
  • Are responsible AI requirements treated as first-class, not optional nice-to-haves?
A.6.2.3
Documentation of AI system design and development

Documentation of AI system design and development activities shall be maintained.

Artefacts an auditor will ask for
  • Design documents
  • Architecture diagrams
  • Model documentation
  • Algorithm choices and rationale
  • Model cards or equivalent
  • Code repositories with provenance
Where this commonly fails
  • Is documentation sufficient to reconstruct decisions later?
A.6.2.4
AI system verification and validation

AI systems shall be verified and validated, and the results documented. Verification confirms requirements are met; validation confirms intended use is achieved.

Artefacts an auditor will ask for
  • V&V plans
  • Test results
  • Acceptance reports
  • Test plans covering accuracy, robustness, bias, security
  • Independent verification where required
  • Documented sign-off
Where this commonly fails
  • Are V&V results signed off independently from developers?
A.6.2.5
AI system deployment

The organization shall document a deployment plan and ensure requirements are met before deployment.

Artefacts an auditor will ask for
  • Deployment plans
  • Go-live checklists
  • Approval records
  • Pre-deployment checklist (security, V&V, monitoring readiness)
  • Approver identified
  • Rollback plan
Where this commonly fails
  • Are deployment gates enforced or routinely bypassed?
A.6.2.6
AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Artefacts an auditor will ask for
  • Operations runbooks
  • Monitoring dashboards
  • Incident logs
  • Drift, performance, fairness monitoring
  • Alerting thresholds
  • Incident response evidence
Where this commonly fails
  • Is monitoring active and alerts acted upon?
A.6.2.7
AI system technical documentation

Technical documentation for the AI system shall be provided to interested parties (e.g., users, partners, regulators).

Artefacts an auditor will ask for
  • Technical documentation packages
  • Distribution records
  • Sufficient detail for users to understand capabilities and limits
  • Format suited to recipient
  • Updates managed
Where this commonly fails
  • Is technical documentation aligned with EU AI Act Annex IV where applicable?
A.6.2.8
AI system event logging

Event logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.

Artefacts an auditor will ask for
  • Logging standards
  • Log samples
  • Log retention policy
  • Logged events (inputs, outputs, overrides, anomalies)
  • Tamper protection
  • Retention aligned to regulatory requirements
Where this commonly fails
  • Are logs sufficient to reconstruct an incident or audit a decision?

Annex A AIMS controls - A.7 Data for AI systems

A.7.2
Data for development and enhancement of AI systems

The organization shall define, document, and implement processes to determine data requirements and ensure data quality for AI system development and enhancement.

Artefacts an auditor will ask for
  • Data requirements specification
  • Data quality procedure
  • Defined data requirements per AI system
  • Quality criteria (accuracy, completeness, timeliness, representativeness)
  • Quality measurement records
Where this commonly fails
  • Is data quality measured or assumed?
A.7.3
Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

Artefacts an auditor will ask for
  • Data acquisition records
  • Provenance documentation
  • Consent records
  • Source identification
  • Licensing or consent evidence
  • Selection criteria and rejection rationale
Where this commonly fails
  • Is data provenance traceable to lawful sources?
A.7.4
Quality of data for AI systems

The organization shall define and document quality requirements for data and ensure they are met.

Artefacts an auditor will ask for
  • Data quality standards
  • Quality assessment reports
  • Quality dimensions defined (accuracy, completeness, representativeness, bias)
  • Measurement evidence
  • Remediation records
Where this commonly fails
  • Is representativeness and bias assessed for training data?
A.7.5
Data provenance

The organization shall document the provenance of data used in AI systems to enable evaluation and traceability.

Artefacts an auditor will ask for
  • Provenance records
  • Lineage diagrams
  • End-to-end data lineage from source to model
  • Transformations documented
  • Datasheets
Where this commonly fails
  • Is lineage maintained automatically or relies on manual updates?
A.7.6
Data preparation

The organization shall define and document criteria for selecting data preparations and the data preparation methods used.

Artefacts an auditor will ask for
  • Data preparation procedures
  • Transformation scripts
  • Approval records
  • Preparation methods (cleaning, labeling, augmentation, balancing)
  • Decisions and rationale
  • Reproducibility evidence
Where this commonly fails
  • Are labeling decisions reviewed for bias?

Annex A AIMS controls - A.8 Information for interested parties of AI systems

A.8.2
System documentation and information for users

The organization shall determine and provide the necessary information for users of the AI system.

Artefacts an auditor will ask for
  • User documentation
  • Instructions for use
  • Training materials
  • Capabilities and limitations described
  • Intended use cases
  • Misuse warnings
  • Update notifications
Where this commonly fails
  • Are limitations communicated as clearly as capabilities?
A.8.3
External reporting

The organization shall provide mechanisms for external interested parties to report concerns or impacts.

Artefacts an auditor will ask for
  • External reporting channels
  • Concern register
  • Public-facing contact (email, form)
  • Response SLAs
  • Concern resolution records
Where this commonly fails
  • Is the channel publicized and findable?
A.8.4
Communication of incidents

The organization shall determine and document a plan for communicating incidents to relevant interested parties.

Artefacts an auditor will ask for
  • Incident communication plan
  • Incident notification records
  • Notification criteria and timing
  • Templates for users, regulators, affected parties
  • Records of past notifications
Where this commonly fails
  • Is notification timing aligned to regulatory requirements (e.g., EU AI Act, GDPR)?
A.8.5
Information for interested parties

The organization shall determine and document its approach to provide information about the AI system to interested parties.

Artefacts an auditor will ask for
  • Information disclosure policy
  • Disclosure records
  • Tiered information by stakeholder type
  • Transparency reports
  • Model cards or factsheets
Where this commonly fails
  • Are disclosures truthful and current?

Annex A AIMS controls - A.9 Use of AI systems

A.9.2
Processes for responsible use of AI systems

The organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.

Artefacts an auditor will ask for
  • Responsible use procedure
  • Acceptable use policy for AI
  • Training records
  • Guidance on internal use of generative AI tools
  • Approved tools list
  • Prohibited use cases
  • Human oversight requirements
Where this commonly fails
  • Does the AUP address generative AI tools (ChatGPT, Copilot) and shadow AI?
A.9.3
Objectives for responsible use of AI system

The organization shall identify and document objectives to guide the responsible use of AI systems.

Artefacts an auditor will ask for
  • Responsible use objectives
  • Objectives covering human oversight, escalation, prohibited uses
  • Linkage to risk treatment
Where this commonly fails
  • Are use objectives distinct from development objectives?
A.9.4
Intended use of the AI system

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

Artefacts an auditor will ask for
  • Intended use statements
  • Use case approval records
  • Monitoring of use
  • Documented intended use per system
  • Approval workflow for new use cases
  • Detection of off-label use
Where this commonly fails
  • Is off-label use detected and addressed?

Clause A – ISO/IEC 42001:2023

A.10
Third-party and customer relationships

Annex A category heading. See the controls within Third-party and customer relationships for the requirements themselves.

A.2
Policies related to AI

Annex A category heading. See the controls within Policies related to AI for the requirements themselves.

A.3
Internal organization

Annex A category heading. See the controls within Internal organization for the requirements themselves.

A.4
Resources for AI systems

Annex A category heading. See the controls within Resources for AI systems for the requirements themselves.

A.5
Assessing impacts of AI systems

Annex A category heading. See the controls within Assessing impacts of AI systems for the requirements themselves.

A.6
AI system life cycle

Annex A category heading. See the controls within AI system life cycle for the requirements themselves.

A.7
Data for AI systems

Annex A category heading. See the controls within Data for AI systems for the requirements themselves.

A.8
Information for interested parties of AI systems

Annex A category heading. See the controls within Information for interested parties of AI systems for the requirements themselves.

A.9
Use of AI systems

Annex A category heading. See the controls within Use of AI systems for the requirements themselves.

Context of the organization – ISO/IEC 42001:2023

4.1
Understanding the organization and its context

Determine the external and internal issues that affect the organisation's ability to achieve the intended outcomes of its AI management system. Establish and record the role or roles the organisation plays with respect to AI, such as provider, producer, user or partner, since the obligations that follow differ by role. Record the intended purposes of the AI systems in scope, because purpose is what later determines whether a use is appropriate.

Artefacts an auditor will ask for
  • Register of internal and external issues relevant to the AIMS
  • Recorded determination of the organisation's AI role or roles (provider, producer, user, partner)
  • Statement of intended purpose for each AI system in scope
  • Records of periodic review of context and roles
Where this commonly fails
  • {'finding': 'No Monitoring of Environmental Impact of AI Systems', 'what_is_missing': 'Consideration of sustainability and environmental risks as part of AI system planning.', 'how_to_close': ['Assess energy consumption and carbon footprint of AI infrastructure', 'Choose efficient model architectures and green data centers', 'Document environmental considerations in AI risk assessments']}
  • {'finding': 'AI-Driven Systems Lack Localization or Regional Adaptation', 'what_is_missing': 'Localization planning and testing for diverse user groups.', 'how_to_close': ['Adapt AI outputs, tone, and logic to regional needs', 'Test systems in local languages with local users', 'Include cultural advisors in product and testing phases']}
  • {'finding': 'No Assessment of Long-Term Societal Impact of AI Technologies', 'what_is_missing': 'Forward-looking analysis of systemic AI impact.', 'how_to_close': ['Include societal impact in AI ethics and governance reviews', 'Evaluate feedback loops, content amplification, and behavioral change', 'Consult external ethics advisors for critical systems']}
  • {'finding': 'No Process to Phase Out Unsustainable AI Practices', 'what_is_missing': 'Governance for identifying and replacing environmentally unsustainable practices.', 'how_to_close': ['Track compute usage and emissions of AI workloads', 'Phase out inefficient models or processes', 'Evaluate trade-offs between performance and sustainability']}
4.2
Understanding the needs and expectations of interested parties

Determine which interested parties are relevant to the AI management system, which of their requirements the organisation must meet, and which of those requirements it adopts as requirements of the management system itself. Interested parties here extend beyond customers and regulators to the individuals and groups affected by an AI system's outputs.

Artefacts an auditor will ask for
  • Interested party register, including individuals and groups affected by AI outputs
  • Mapping of interested party requirements to AIMS requirements
  • Records of consultation or engagement with affected parties
  • Evidence the mapping is reviewed when requirements change
Where this commonly fails
  • {'finding': 'Lack of Stakeholder Engagement in AI Design', 'what_is_missing': 'Structured stakeholder engagement during AI system planning and development.', 'how_to_close': ['Identify internal and external stakeholders early', 'Use surveys, focus groups, or ethics panels to gather input', 'Document how feedback influences design choices']}
  • {'finding': 'No Review of AI System Impact on Human Rights', 'what_is_missing': 'An ethical impact assessment addressing AI’s effect on fundamental rights.', 'how_to_close': ['Conduct Human Rights Impact Assessments (HRIAs) for high-risk', 'Involve external advisors or civil society where applicable', 'Include mitigation strategies for identified risks']}
  • {'finding': 'Lack of Regulatory Mapping for AI Use Cases', 'what_is_missing': 'Mapping of AI use cases to legal and regulatory requirements (e.g., GDPR, HIPAA, EU AI Act).', 'how_to_close': ['Conduct legal reviews for every high-risk AI use case', 'Maintain a compliance matrix aligned with jurisdictions and AI', 'Involve legal counsel early in AI product development']}
  • {'finding': 'No Assessment of Social Impact for AI Applications', 'what_is_missing': 'Social impact assessments for high-impact AI deployments.', 'how_to_close': ['Evaluate societal effects (inclusion, bias, accessibility) during planning', 'Include community stakeholders in the assessment process', 'Use findings to refine model goals and governance controls']}
  • {'finding': 'AI Systems Built Without Stakeholder Risk Workshops', 'what_is_missing': 'Stakeholder-driven risk identification during early planning phases.', 'how_to_close': ['Conduct cross-functional risk workshops involving HR, legal, product,', 'Document concerns from all parties and address them in the AI risk', 'Update risk mitigation strategies based on stakeholder insights']}
  • {'finding': 'No Consideration of Cultural Sensitivity in AI Outputs', 'what_is_missing': 'Cultural sensitivity and localization reviews during AI design.', 'how_to_close': ['Involve linguists and cultural experts in high-impact AI projects', 'Test outputs in multilingual and multicultural contexts', 'Set redlines for cultural content and offensive output filtering']}
  • {'finding': 'No Process to Assess the Ethical Use of AI in Marketing', 'what_is_missing': 'Ethical assessment for AI-driven persuasion or behavioral targeting.', 'how_to_close': ['Review marketing use cases for manipulation, profiling, or', 'Establish red lines (e.g., no targeting based on sensitive attributes)', 'Involve ethics officers or external advisors in high-risk reviews']}
4.3
Determining the scope of the management system

Determine the boundaries and applicability of the AI management system and record its scope. The scope must account for the issues identified in 4.1, the requirements identified in 4.2, and the interfaces and dependencies between activities the organisation performs and those performed by others. The scope is maintained as documented information.

Artefacts an auditor will ask for
  • Documented AIMS scope statement
  • Definition of boundaries, interfaces and dependencies with other parties
  • Justification for anything excluded from scope
  • Evidence the scope reflects the issues and requirements in 4.1 and 4.2
Where this commonly fails
  • {'finding': 'Inconsistent Application of AI Controls Across Business Units', 'what_is_missing': 'A harmonized AIMS that applies consistently across the entire organization.', 'how_to_close': ['Clearly define the AIMS scope to include all business units using or', 'Standardize governance tools, documentation, and training', 'Conduct cross-functional reviews to ensure consistent application']}
4.4
Management system

Establish, implement, maintain and continually improve an AI management system, including the processes it needs and their interactions, in accordance with the requirements of this document.

Artefacts an auditor will ask for
  • AIMS process map showing processes and their interactions
  • Index of documented procedures supporting the AIMS
  • Evidence of maintenance and continual improvement of the system itself
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.

Improvement – ISO/IEC 42001:2023

10.1
Continual improvement

Continually improve the suitability, adequacy and effectiveness of the AI management system.

Artefacts an auditor will ask for
  • Improvement register
  • Trend analysis showing where the AIMS is being improved
  • Evidence of changes actually made
Where this commonly fails
  • {'finding': 'Lack of Procedures to Retire AI Features That Cause Harm', 'what_is_missing': 'A clear path to sunset harmful features quickly and transparently.', 'how_to_close': ['Build deactivation into your incident response process', 'Monitor for harm and escalate rapidly', 'Communicate deprecations clearly to users and internal teams']}
10.2
Nonconformity and corrective action

When a nonconformity occurs, react to it, control and correct it, and deal with its consequences. Evaluate whether action is needed to eliminate its causes so that it does not recur or occur elsewhere, by reviewing the nonconformity, determining its causes, and determining whether similar nonconformities exist or could occur. Implement any action needed, review its effectiveness, and change the AI management system where necessary. Corrective actions must be appropriate to the effects of the nonconformities encountered. Retain documented information on the nature of the nonconformities, the actions taken and the results.

Artefacts an auditor will ask for
  • Nonconformity log recording nature and consequences
  • Root cause analyses
  • Corrective action plans with owners and dates
  • Review of corrective action effectiveness
  • Records of resulting changes to the AIMS
Where this commonly fails
  • {'finding': 'No Post-Mortem Analysis for AI Incidents', 'what_is_missing': 'Post-incident learning and preventive process enhancement.', 'how_to_close': ['Conduct structured post-mortems for every significant AI issue', 'Include root cause, contributing factors, and corrective actions', 'Feed insights into training, documentation, and governance updates']}
  • {'finding': 'Failure to Track and Learn from Industry AI Failures', 'what_is_missing': 'External learning and adaptive governance.', 'how_to_close': ['Track AI-related news, legal cases, and regulator updates', 'Add a “Lessons Learned” section to your AIMS documentation', 'Review external incidents quarterly and apply improvements']}

Leadership – ISO/IEC 42001:2023

5.1
Leadership and commitment

Top management must demonstrate leadership and commitment to the AI management system: ensuring the AI policy and objectives are established and compatible with the organisation's strategic direction, integrating the management system's requirements into the organisation's own processes, making the necessary resources available, communicating why effective AI management matters, ensuring the system achieves its intended outcomes, directing and supporting the people who contribute to it, promoting continual improvement, and supporting other managers to lead within their own areas.

Artefacts an auditor will ask for
  • Approved AI policy signed by top management
  • Board or executive minutes evidencing direction and oversight of AI
  • Resource and budget approvals for the AIMS
  • AIMS performance reporting to top management
  • Evidence AIMS requirements are integrated into business processes
Where this commonly fails
  • {'finding': 'No AI Ethics Review Board or Oversight Mechanism', 'what_is_missing': 'Formal ethical governance to assess, review, and approve AI systems with societal or individual impact.', 'how_to_close': ['Establish an AI Ethics Review Board with cross-functional members', 'Mandate reviews for high-impact or high-risk AI use cases', 'Document findings and decisions as part of the AIMS governance record']}
  • {'finding': 'Lack of Integration Between AI and Data Privacy Teams', 'what_is_missing': 'Cross-team coordination to ensure privacy is embedded in AI design.', 'how_to_close': ['Involve the DPO in all high-risk AI development and reviews', 'Establish joint workflows between AI, compliance, and legal', 'Embed privacy impact assessments (PIAs) into the AI lifecycle']}
  • {'finding': 'No Independent Oversight of High-Risk AI Projects', 'what_is_missing': 'Neutral, cross-functional oversight for projects with elevated societal impact.', 'how_to_close': ['Mandate external review boards or independent internal committees', 'Rotate reviewers and include ethical or public-interest representatives', 'Document dissenting opinions and how they were addressed']}
5.2
Policy

Establish an AI policy that is appropriate to the organisation's purpose, provides a framework for setting AI objectives, and commits the organisation to satisfying applicable requirements and to continually improving the AI management system. The policy is maintained as documented information, communicated within the organisation, and made available to interested parties where appropriate.

Artefacts an auditor will ask for
  • Approved AI policy appropriate to the organisation's purpose
  • Version history and approval record
  • Evidence of communication within the organisation
  • Evidence of availability to interested parties where appropriate
Where this commonly fails
  • {'finding': 'No Policy for Responsible AI Deployment', 'what_is_missing': 'An overarching Responsible AI policy aligned with ISO 42001 principles.', 'how_to_close': ['Define acceptable use cases, prohibited applications, and ethical', 'Align the policy with ISO 42001 and your organizational values', 'Communicate and train employees on the policy regularly']}
  • {'finding': 'No Policy for Responsible Use of Generative AI', 'what_is_missing': 'Governance over the use of generative AI, including prompt safety, copyright concerns, and hallucination risks.', 'how_to_close': ['Define acceptable use cases for generative AI', 'Train employees on risks and output validation', 'Implement approval processes and disclosure guidelines for public-']}
5.3
Roles, responsibilities and authorities

Assign and communicate the responsibilities and authorities for the roles relevant to the AI management system, including responsibility for ensuring the system conforms to this document and for reporting on its performance to top management.

Artefacts an auditor will ask for
  • RACI or equivalent for AIMS roles
  • Role descriptions or appointment records for AI accountabilities
  • Documented delegation of authority
  • Defined reporting line to top management on AIMS performance
Where this commonly fails
  • {'finding': 'Lack of Defined AI Roles and Responsibilities', 'what_is_missing': 'Clearly defined roles for every stage of the AI lifecycle and AIMS accountability.', 'how_to_close': ['Assign ownership for model development, governance, ethics, and', 'Map roles in a RACI chart and integrate with org structure', 'Review role responsibilities annually or when teams shift']}
  • {'finding': 'No Defined Roles for AI Model Review and Sign-Off', 'what_is_missing': 'Assigned accountability for final review and sign-off before launch.', 'how_to_close': ['Assign clear model sign-off authority (AI governance lead, ethics officer,', 'Require documented approval for every production deployment', 'Link sign-off to validation, testing, and compliance checklists']}

Operation – ISO/IEC 42001:2023

8.1
Operational planning and control

Plan, implement and control the processes needed to meet the AI management system's requirements and to carry out the actions determined under Clause 6. Establish criteria for those processes and control them in accordance with the criteria. Keep documented information sufficient to have confidence the processes have been carried out as planned. Control planned changes, review the consequences of unintended changes, and act to mitigate any adverse effects. Ensure that processes, products or services relevant to the AI management system that are provided externally are controlled.

Artefacts an auditor will ask for
  • Documented process criteria and operating procedures
  • Records demonstrating processes were carried out as planned
  • Change control records for planned changes
  • Reviews of unintended changes and actions taken to mitigate adverse effects
  • Evidence that externally provided processes, products and services are controlled
Where this commonly fails
  • {'finding': 'No Inventory of AI Assets or Models', 'what_is_missing': 'A complete and up-to-date registry of AI models and assets.', 'how_to_close': ['Build an AI model registry with metadata like purpose, owner, dataset,', 'Assign ownership for each AI asset', 'Conduct biannual reviews of the inventory']}
  • {'finding': 'Lack of Model Lifecycle Management', 'what_is_missing': 'A structured AI lifecycle management process from development to decommissioning.', 'how_to_close': ['Create a model lifecycle framework with defined stages (build, test,', 'Maintain logs for all model changes', 'Link each model to a unique identifier in the asset inventory']}
  • {'finding': 'No Procedure for Decommissioning AI Models', 'what_is_missing': 'A structured decommissioning process to retire outdated or underperforming AI models.', 'how_to_close': ['Define decommissioning criteria (e.g., low accuracy, regulatory changes)', 'Archive old models and clearly mark them as inactive', 'Communicate model retirement to impacted teams or users']}
  • {'finding': 'Lack of Policy for Shadow AI Detection', 'what_is_missing': 'Controls to detect and manage “shadow AI” systems developed without approval.', 'how_to_close': ['Implement a centralized AI system registration process', 'Use internal audits to identify unauthorized AI deployments', 'Enforce disciplinary or corrective measures for policy violations']}
  • {'finding': 'No Formal Process for AI Model Validation Before Deployment', 'what_is_missing': 'A rigorous validation protocol to verify AI model reliability before deployment.', 'how_to_close': ['Establish a checklist of validation steps (fairness, security, stability)', 'Use benchmark datasets and scenario testing', 'Require sign-off by compliance and technical leads']}
  • {'finding': 'No Controls Around AI System Retraining Frequency', 'what_is_missing': 'Retraining schedule and triggers based on data changes or performance drift.', 'how_to_close': ['Define retraining intervals based on use case (e.g., quarterly, post-drift)', 'Use automation to flag models for review when thresholds are breached', 'Log retraining activities and version changes']}
  • {'finding': 'Incomplete Asset Inventory of AI-Related Components', 'what_is_missing': 'A central, current inventory of all AI-related assets.', 'how_to_close': ['Build a structured AI asset registry (models, training datasets, APIs,', 'Assign asset owners and update records quarterly', 'Use automated discovery tools where possible']}
  • {'finding': 'AI Systems Lack End-of-Life Planning', 'what_is_missing': 'Defined criteria and processes for system decommissioning.', 'how_to_close': ['Include “end-of-life” as a required step in AI lifecycle management', 'Document when and how systems will be retired', 'Archive related data, logs, and models securely']}
8.2
AI risk assessment

Perform AI risk assessments in line with the clause 6.1.2 criteria at planned intervals and whenever significant changes are proposed or occur, and retain documented information of every assessment result.

Artefacts an auditor will ask for
  • AI risk assessment records with dates and scope
  • schedule defining planned assessment intervals
  • change log showing which changes triggered a reassessment
Where this commonly fails
  • {'finding': 'No Security Oversight of AI Supply Chain or Third-Party Models', 'what_is_missing': 'Due diligence for third-party models and AI tools.', 'how_to_close': ['Vet all third-party tools with a supplier security checklist', 'Require assurance documentation (e.g., bias testing, license reviews)', 'Include third-party models in AI risk assessments and contracts']}
  • {'finding': 'No Third-Party AI Risk Assessment Process', 'what_is_missing': 'A structured process for evaluating third-party AI risks before onboarding.', 'how_to_close': ['Vet vendors using a formal AI risk checklist', 'Require security, bias, and compliance disclosures from all AI partners', 'Incorporate vendor performance and risk into your own AIMS reviews']}
  • {'finding': 'No Integration of AI Controls into Vendor Contracts', 'what_is_missing': 'Contractual controls to extend your AIMS to third-party AI vendors.', 'how_to_close': ['Include AI governance requirements in all contracts and SLAs', 'Require vendors to adhere to ISO 42001-aligned practices', 'Mandate reporting of incidents, audits, or material changes in their']}
8.3
AI risk treatment

Implement the AI risk treatment plan set under clause 6.1.3 and verify its effectiveness, run the impact assessment process for newly identified risks needing treatment, review and revalidate treatment options that prove ineffective and update the plan, and retain documented information of all treatment results.

Artefacts an auditor will ask for
  • AI risk treatment plan with owners and dates
  • evidence that treatments were verified as effective
  • revalidation records where a treatment failed
  • updated treatment plan versions
Where this commonly fails
  • {'finding': 'No Data Provenance Documentation', 'what_is_missing': 'Data provenance tracking and documentation to ensure compliance, explainability, and fairness.', 'how_to_close': ['Implement data lineage tools or maintain manual documentation', 'Link each dataset to its source, transformation, and consent mechanism', 'Include data provenance in model training logs']}
  • {'finding': 'AI Training Data Stored Without Retention or Deletion Policy', 'what_is_missing': 'A formal data retention and disposal policy tied to AI datasets.', 'how_to_close': ['Set retention periods based on data type and purpose', 'Securely delete training data that’s no longer needed', 'Document deletion logs and align with privacy regulations (e.g., GDPR)']}
  • {'finding': 'No Consent Mechanism for AI Data Collection', 'what_is_missing': 'A mechanism to ensure informed user consent for data used in AI.', 'how_to_close': ['Implement clear opt-in/opt-out options for data usage', 'Document consent logs and integrate with your AIMS', 'Allow users to revoke consent and update models accordingly']}
  • {'finding': 'AI Training Data Collected Without Purpose Limitation', 'what_is_missing': 'Adherence to purpose limitation principles for data reuse.', 'how_to_close': ['Clearly define intended use when collecting data', 'If repurposing data, assess legal, ethical, and consent implications', 'Update privacy notices and get new consent if required']}
  • {'finding': 'No Policy for Handling Public Data in AI Training', 'what_is_missing': 'Guidelines for sourcing and validating publicly available training data.', 'how_to_close': ['Define acceptable sources and criteria for public data use', 'Assess IP, copyright, consent, and bias implications', 'Apply filters or remove sensitive information from public datasets']}
  • {'finding': 'No Guidelines for the Use of Synthetic Data in AI Training', 'what_is_missing': 'Policy and procedures for generating and validating synthetic data.', 'how_to_close': ['Define acceptable use cases for synthetic data', 'Validate synthetic datasets for realism, bias, and privacy', 'Document generation methods and link to model documentation']}
  • {'finding': 'AI Training Pipelines Lack Data Quality Validation Steps', 'what_is_missing': 'Data quality checks during pipeline design and ingestion.', 'how_to_close': ['Validate training data for accuracy, completeness, and consistency', 'Implement automated checks for outliers, duplicates, and label issues', 'Document quality metrics as part of model development artifacts']}
8.4
AI system impact assessment

Perform AI system impact assessments in line with clause 6.1.4 at planned intervals and whenever significant changes are proposed or occur, and retain documented information of every impact assessment result.

Artefacts an auditor will ask for
  • completed AI system impact assessments per system
  • interval schedule and trigger definition for reassessment
  • retained results linked to the AI system inventory
Where this commonly fails
  • {'finding': 'Insufficient Access Controls for AI Systems', 'what_is_missing': 'Granular access control aligned with the principle of least privilege.', 'how_to_close': ['Use role-based access control (RBAC) for AI-related assets', 'Log access to sensitive datasets and model parameters', 'Conduct quarterly access reviews and remove excess privileges']}
  • {'finding': 'Unsecured Access to Training Data and Models', 'what_is_missing': 'Access controls and audit trails to protect sensitive AI-related assets.', 'how_to_close': ['Restrict access using RBAC or ABAC policies', 'Encrypt training data in storage and transit', 'Implement logging to track who accessed what and when']}
  • {'finding': 'No Role-Based Access Control (RBAC) for Model and Data Pipelines', 'what_is_missing': 'Access control by role and least-privilege principles.', 'how_to_close': ['Implement RBAC policies for AI systems and data assets', 'Review access rights quarterly', 'Revoke access when roles change or projects conclude']}

Performance evaluation – ISO/IEC 42001:2023

9.1
Monitoring, measurement, analysis and evaluation

Determine what needs to be monitored and measured, the methods that will produce valid results, when monitoring and measurement will be performed, and when the results will be analysed and evaluated. Use them to evaluate the performance of the organisation's AI systems and the effectiveness of the AI management system, and retain documented evidence of the results.

Artefacts an auditor will ask for
  • Monitoring and measurement plan stating what, when and by what method
  • KPI definitions for AI performance and AIMS effectiveness
  • Measurement records
  • Analysis and evaluation reports
Where this commonly fails
  • {'finding': 'No KPIs for AI Governance Performance', 'what_is_missing': 'Defined performance indicators to monitor AI system effectiveness and compliance.', 'how_to_close': ['Create AI-specific KPIs (e.g., bias detection rate, accuracy drift, audit', 'Review KPIs quarterly and align with business objectives', 'Automate performance tracking using dashboards']}
  • {'finding': 'No Post-Deployment Monitoring of AI Fairness', 'what_is_missing': 'Ongoing evaluation of model fairness, accuracy, and drift post-deployment.', 'how_to_close': ['Define fairness metrics appropriate for your context (e.g., demographic', 'Set thresholds for acceptable variation and retrain when breached', 'Use automated monitoring tools for real-time alerts']}
  • {'finding': 'Inadequate Logging of AI System Activities', 'what_is_missing': 'Comprehensive logging of AI activities, decisions, and data interactions.', 'how_to_close': ['Log inputs, outputs, errors, access events, and overrides', 'Use centralized log management tools', 'Regularly review logs to identify anomalies or system drift']}
  • {'finding': 'No Mechanism to Monitor and Mitigate Model Drift', 'what_is_missing': 'A process to detect model drift and automatically trigger review or retraining.', 'how_to_close': ['Set drift detection thresholds (e.g., accuracy, input distribution)', 'Use real-time monitoring and alerts for critical models', 'Define triggers for retraining or rollback procedures']}
  • {'finding': 'No Defined Criteria for AI Model Performance Evaluation', 'what_is_missing': 'Defined performance indicators and thresholds for success/failure.', 'how_to_close': ['Establish quantitative KPIs (e.g., precision, recall, latency, false positive', 'Include qualitative metrics (e.g., user satisfaction, ethical alignment)', 'Regularly assess performance and link findings to improvement plans']}
  • {'finding': 'AI Systems Operate Without User Feedback Loops', 'what_is_missing': 'Structured feedback mechanisms to gather user input and improve system performance.', 'how_to_close': ['Implement user feedback forms or in-app reporting features', 'Assign responsibility for reviewing and acting on feedback', 'Use feedback trends to refine models or retrain where needed']}
  • {'finding': 'AI Performance Not Benchmarked Against Alternatives', 'what_is_missing': 'Benchmarking to validate AI effectiveness versus traditional approaches.', 'how_to_close': ['Define benchmark scenarios and KPIs for comparison', 'Measure AI vs. manual process accuracy, cost, speed, and fairness', 'Use findings to support deployment decisions or revert when needed']}
  • {'finding': 'Lack of Monitoring for AI Hallucinations in Generative Systems', 'what_is_missing': 'A strategy to identify, log, and respond to generative hallucinations.', 'how_to_close': ['Flag high-risk outputs with uncertainty scoring or disclaimers', 'Monitor for hallucinations using prompt tracking and content reviews', 'Fine-tune or constrain models based on problem areas']}
9.2
Internal audit

Conduct internal audits at planned intervals to determine whether the AI management system conforms to the organisation's own requirements and to the requirements of this document, and whether it is effectively implemented and maintained. Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting. Define the criteria and scope of each audit, select auditors and conduct audits in a way that ensures objectivity and impartiality, report results to relevant management, and retain documented evidence of the programme and its results.

Artefacts an auditor will ask for
  • Internal audit programme covering frequency, methods and responsibilities
  • Audit plans with defined criteria and scope
  • Evidence of auditor objectivity and impartiality
  • Audit reports and nonconformities raised
  • Evidence results were reported to relevant management
Where this commonly fails
  • {'finding': 'Lack of Procedures for Auditing AI Ethics Compliance', 'what_is_missing': 'AI ethics checkpoints within the audit process.', 'how_to_close': ['Include ethical impact criteria in internal audit scope', 'Train auditors to review bias mitigation, transparency, and oversight', 'Use AI-specific audit templates and checklists']}
9.2.1
General

Conduct internal audits at planned intervals to establish whether the AI management system conforms to the organization's own requirements and to the requirements of the standard, and whether it is effectively implemented and maintained.

Artefacts an auditor will ask for
  • internal audit reports covering both conformity and effectiveness
  • audit calendar showing planned intervals
  • scope statement tying each audit to AIMS requirements
Where this commonly fails
  • audit checks conformity only and never effectiveness
  • intervals slip with no record
  • scope omits Annex A controls in use
9.2.2
Internal audit programme

Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, taking account of process importance and previous audit results, define objectives, criteria and scope per audit, select auditors that ensure objectivity and impartiality, report results to relevant managers, and retain evidence of the programme and its results.

Artefacts an auditor will ask for
  • documented audit programme with frequency and methods
  • auditor independence declarations
  • per-audit objectives, criteria and scope
  • distribution records showing results reached the relevant managers
Where this commonly fails
  • auditors auditing their own work
  • programme not adjusted for process importance or prior findings
  • results never formally reported to management
9.3
Management review

Top management must review the AI management system at planned intervals to confirm it remains suitable, adequate and effective. The review considers the status of actions from previous reviews, changes in the external and internal issues and in the requirements of interested parties, the system's performance including nonconformities, monitoring and measurement results and audit results, and opportunities for continual improvement. Its outputs include decisions on improvement opportunities and on any need to change the system. Retain documented information as evidence of the review and its outcomes.

Artefacts an auditor will ask for
  • Management review minutes covering every required input
  • Evidence of decisions on improvement opportunities and system changes
  • Actions with owners and dates arising from review
  • Evidence reviews occur at planned intervals
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
9.3.1
General

Top management reviews the AI management system at planned intervals to confirm its continuing suitability, adequacy and effectiveness.

Artefacts an auditor will ask for
  • management review minutes with attendance showing top management
  • schedule evidencing planned intervals
  • explicit conclusions on suitability, adequacy and effectiveness
Where this commonly fails
  • review chaired below top management
  • held ad hoc with no defined interval
  • no stated conclusion on the three criteria
9.3.2
Management review inputs

The management review considers the defined set of inputs including status of prior review actions, changes in external and internal issues relevant to the AI management system, and performance information covering nonconformities and corrective actions, monitoring and measurement results, and audit results.

Artefacts an auditor will ask for
  • review pack showing each required input present
  • trend data on nonconformities, monitoring results and audits
  • status tracking of actions from the previous review
Where this commonly fails
  • inputs presented selectively with gaps unexplained
  • no trend view, only a point in time
  • previous actions not tracked to closure
9.3.3
Management review results

The results of the management review include decisions on continual improvement opportunities and any need for changes to the AI management system, and documented information is retained as evidence of those results.

Artefacts an auditor will ask for
  • documented decisions with owners and due dates
  • recorded changes to the AIMS arising from the review
  • retained minutes as evidence of the results
Where this commonly fails
  • discussion recorded but no decisions
  • actions with no owner or date
  • results not retained as documented information

Planning – ISO/IEC 42001:2023

6.1
Actions to address risks and opportunities

Plan the actions the organisation will take to address the risks and opportunities that affect the AI management system, and determine how those actions will be integrated into its processes and how their effectiveness will be evaluated. The subclauses that follow set out the risk assessment, risk treatment and impact assessment processes this requires.

Artefacts an auditor will ask for
  • Register of risks and opportunities affecting the AIMS
  • Records linking planned actions into business processes
  • Evaluation of whether those actions were effective
Where this commonly fails
  • {'finding': 'No Formal AI Risk Assessment Framework', 'what_is_missing': 'A structured, repeatable AI risk management framework integrated into the development lifecycle.', 'how_to_close': ['Build an AI risk register', 'Conduct regular impact assessments (bias, misuse, performance)', 'Involve legal, ethics, and technical teams in evaluation', 'Update the risk framework with each major system change']}
  • {'finding': 'No Bias Testing Framework in Model Development', 'what_is_missing': 'A structured bias testing protocol during training and validation phases.', 'how_to_close': ['Mandate bias testing before deployment', 'Use tools to analyze representation and outcome fairness', 'Include bias test results in model documentation']}
  • {'finding': 'Absence of AI-Specific Threat Modeling in Development', 'what_is_missing': 'AI-tailored threat modeling as part of the secure development lifecycle.', 'how_to_close': ['Integrate threat modeling sessions into AI development planning', 'Include risks like inference attacks, training data leakage, model theft', 'Use frameworks like MITRE ATLAS for AI threat identification']}
  • {'finding': 'No Pre-Deployment Review of Legal and Ethical Risks', 'what_is_missing': 'A mandatory checkpoint for legal and ethical risks before go-live.', 'how_to_close': ['Include legal/ethics leads in AI go/no-go decisions', 'Maintain a pre-launch checklist of legal, regulatory, and ethical', 'Delay deployment until all risks are reviewed and documented']}
  • {'finding': 'AI System Not Reviewed Following Regulatory Updates', 'what_is_missing': 'Regulatory change tracking tied to AI system reviews.', 'how_to_close': ['Monitor global AI and data regulations continuously', 'Maintain a log of system reviews triggered by legal changes', 'Assign responsibility to legal/compliance teams for alerting relevant']}
  • {'finding': 'No Policy for Dual-Use or High-Risk AI Research', 'what_is_missing': 'Dual-use and misuse prevention protocols.', 'how_to_close': ['Identify dual-use risks in early research stages', 'Apply ethics review and usage restrictions', 'Restrict open deployment and model weights sharing when warranted']}
6.1.1
General

When planning the AI management system, consider the issues determined under 4.1 and the requirements determined under 4.2, and determine the risks and opportunities that need to be addressed in order to give assurance the system can achieve its intended outcomes, to prevent or reduce undesired effects, and to achieve continual improvement.

Artefacts an auditor will ask for
  • Documented determination of risks and opportunities
  • Traceability from the issues in 4.1 and the requirements in 4.2
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
6.1.2
Risk assessment

Define and apply an AI risk assessment process. The process must establish and maintain risk criteria, including the criteria for accepting risk, and must produce consistent, valid and comparable results when repeated. It must identify the risks to achieving the organisation's AI objectives and the risks that AI systems present to individuals, to groups and to society, analyse their likelihood and consequences, evaluate them against the criteria, and prioritise them for treatment. Retain documented information about the process and its results.

Artefacts an auditor will ask for
  • Documented AI risk assessment procedure
  • Risk criteria including risk acceptance criteria
  • Risk register with likelihood, consequence and evaluation against criteria
  • Evidence of risks to individuals, groups and society, not only to the organisation
  • Evidence the process gives consistent results when repeated
Where this commonly fails
  • {'finding': 'No Periodic Review of AI Risk Assessments', 'what_is_missing': 'A cadence for reviewing and updating AI risk assessments.', 'how_to_close': ['Schedule quarterly or biannual risk assessment reviews', 'Update the register after model updates, incidents, or policy changes', 'Link risk changes to controls and mitigation plans']}
6.1.3
Risk treatment

Define and apply an AI risk treatment process that selects treatment options in light of the assessment results, determines the controls necessary to implement them, and compares those controls against the reference controls in Annex A to verify none has been overlooked. Produce a Statement of Applicability recording the controls that apply, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control. Formulate a treatment plan, obtain the risk owners' approval of that plan, and obtain their acceptance of the residual AI risks. Retain documented information about the process and its results.

Artefacts an auditor will ask for
  • Risk treatment plan with owners and dates
  • Statement of Applicability with justification for inclusions and exclusions of Annex A controls
  • Risk owner approval of the treatment plan
  • Documented acceptance of residual AI risk by risk owners
Where this commonly fails
  • {'finding': 'Weak Documentation of Risk Treatment', 'what_is_missing': 'A documented Risk Treatment Plan (RTP) linked to the AI risk register.', 'how_to_close': ['Create an RTP outlining risks, mitigation steps, owners, and deadlines', 'Track progress with version-controlled documentation', 'Use tools to monitor and report on mitigation progress']}
6.1.4
AI system impact assessment

Define a process for assessing the potential consequences an AI system may have for individuals, for groups of individuals and for society, and apply it across the system's life cycle. The assessment considers the intended purpose recorded under 4.1 and the context in which the system will operate, and its results are retained as documented information and used as an input to risk assessment and treatment.

Artefacts an auditor will ask for
  • Documented AI system impact assessment procedure
  • Completed impact assessments per AI system in scope
  • Evidence the assessment covers consequences for individuals, groups and society
  • Evidence it is applied across the life cycle, not once at design
  • Traceability from impact assessment results into risk assessment and treatment
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
6.2
Objectives and planning to achieve them

Establish AI objectives at the relevant functions and levels. Objectives must be consistent with the AI policy, measurable or at least capable of being evaluated, take account of applicable requirements and the results of risk assessment and risk treatment, be monitored, communicated and updated as necessary, and be maintained as documented information. For each objective, plan what will be done, what resources are required, who is responsible, when it will be completed, and how the results will be evaluated.

Artefacts an auditor will ask for
  • AI objectives register showing consistency with the AI policy
  • How each objective is measured or evaluated
  • Plan per objective: resources, owner, completion date, evaluation method
  • Evidence of communication and update
Where this commonly fails
  • {'finding': 'AI System Lifecycle Not Linked to Business Objectives', 'what_is_missing': 'Business-aligned objectives driving AI development and use.', 'how_to_close': ['Link AI outcomes (e.g., automation, accuracy, fairness) to business KPIs', 'Include strategic objectives in model documentation', 'Involve business leaders in the AI design and review phases']}
6.3
Planning of changes

Where the organization determines a need to change the AI management system, carry the change out in a planned manner.

Artefacts an auditor will ask for
  • change requests covering AIMS scope, policy, roles or processes
  • record of the planning step before the change was made
  • post-change review confirming the system still meets requirements
Where this commonly fails
  • AIMS scope or roles changed without any record
  • changes applied first and documented afterwards
  • no assessment of what else the change affects

Support – ISO/IEC 42001:2023

7.1
Resources

Determine and provide the resources needed to establish, implement, maintain and continually improve the AI management system, including the data, tooling, computing and human resources the organisation's AI systems depend on.

Artefacts an auditor will ask for
  • Resource plan for the AIMS
  • Budget approvals
  • Inventory of compute, data and tooling the AI systems depend on
  • Staffing plan for AI roles
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
7.2
Competence

Determine the competence necessary for the people whose work affects the performance of the AI management system, ensure they are competent on the basis of appropriate education, training or experience, take action where a competence gap exists, evaluate whether that action worked, and retain documented evidence of competence.

Artefacts an auditor will ask for
  • Competence matrix for roles affecting AIMS performance
  • Training records, qualifications or experience evidence
  • Actions taken where a competence gap was identified
  • Evaluation of whether those actions worked
Where this commonly fails
  • {'finding': 'No AI-Specific Training for Employees', 'what_is_missing': 'Targeted training on responsible AI, regulatory obligations, and organizational AI governance.', 'how_to_close': ['Conduct mandatory AI governance training', 'Include topics like transparency, fairness, privacy, and accountability', 'Track participation and issue refresher courses annually']}
  • {'finding': 'No Internal Training on ISO 42001 or AIMS Requirements', 'what_is_missing': 'Awareness and education on ISO 42001 principles and internal policies.', 'how_to_close': ['Run training sessions for relevant teams (AI, risk, compliance, execs)', 'Include ISO 42001 basics, governance roles, and non-conformity risks', 'Refresh annually and track participation']}
7.3
Awareness

Ensure that people doing work under the organisation's control are aware of the AI policy, of how they contribute to the effectiveness of the AI management system and to the benefits of improved AI performance, and of the implications of not conforming to the system's requirements.

Artefacts an auditor will ask for
  • Awareness materials covering the AI policy
  • Attendance or completion records
  • Evidence people understand the implications of not conforming
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
7.4
Communication

Determine the internal and external communications relevant to the AI management system: what will be communicated, when, to whom, and by what process. This includes how the organisation communicates about its AI systems to the parties affected by them.

Artefacts an auditor will ask for
  • Communication plan stating what, when, with whom and how
  • Records of external communication about AI systems
  • User-facing notices or disclosures where AI is in use
Where this commonly fails
  • {'finding': 'Lack of Explainability for End-Users', 'what_is_missing': 'Clear, accessible communication of how AI systems make decisions— especially for external stakeholders.', 'how_to_close': ['Generate user-friendly summaries of decision logic', 'Provide justification or rationale for decisions where legally or ethically', 'Offer recourse or appeal mechanisms when needed']}
  • {'finding': 'No Communication Strategy for AI System Failures', 'what_is_missing': 'A defined process for internal and external communication during AI outages or incidents.', 'how_to_close': ['Draft communication templates for AI failure scenarios', 'Define who communicates what, when, and through which channel', 'Include escalation steps and status update timelines']}
  • {'finding': 'No External Disclosure of AI System Usage to Users', 'what_is_missing': 'Transparency about AI involvement in decision-making, as required by ethical and legal standards.', 'how_to_close': ['Clearly disclose when users are interacting with or being influenced by', 'Include disclaimers or AI usage statements on digital interfaces', 'Provide contact info or appeal options for automated decisions']}
  • {'finding': 'No Mechanism for Users to Challenge or Appeal AI Decisions', 'what_is_missing': 'Appeal mechanisms for decisions made (or influenced) by AI.', 'how_to_close': ['Create a documented process for users to challenge outcomes', 'Assign human reviewers to evaluate appeals', 'Communicate the option to appeal in user-facing interfaces']}
  • {'finding': 'Lack of User Education on AI Limitations and Risks', 'what_is_missing': 'User awareness of system boundaries and potential risks.', 'how_to_close': ['Provide clear disclaimers or explanations with AI outputs', 'Offer user guides or tutorials for interacting with AI responsibly', 'Communicate fallback options or when to consult a human']}
7.5
Documented information

Maintain the documented information the AI management system requires, both the information this document requires and the information the organisation determines is necessary for the system to be effective. The subclauses that follow set out how that information is created and controlled.

Artefacts an auditor will ask for
  • Register or index of AIMS documented information
  • Retention schedule
Where this commonly fails
  • {'finding': 'Poor Documentation of AI Model Purpose and Limitations', 'what_is_missing': 'Formal documentation of model objectives, intended audience, assumptions, and risks.', 'how_to_close': ['Document every model’s purpose, limitations, and expected behavior', 'Include transparency statements for internal and external stakeholders', 'Keep documentation updated after retraining or changes']}
  • {'finding': 'Inconsistent Version Control for AI Models', 'what_is_missing': 'Robust version control to track models, datasets, and configuration settings.', 'how_to_close': ['Use MLOps tools to manage and version models', 'Tag and store metadata (e.g., training data, code version,', 'Archive deprecated versions and prevent accidental redeployment']}
  • {'finding': 'No Structured Method for Documenting AI Model Assumptions', 'what_is_missing': 'Documentation of underlying assumptions, use limitations, and design trade-offs.', 'how_to_close': ['Require a “Model Card” or equivalent artifact for each system', 'Include assumptions, known limitations, data bias concerns, and', 'Review and update documentation with every major model change']}
  • {'finding': 'AI Documentation Lacks Version History and Change Logs', 'what_is_missing': 'Version control and change history for critical AI documentation.', 'how_to_close': ['Use version control systems (e.g., Git) for model documentation', 'Maintain changelogs for key documents (model cards, risk registers, SoA)', 'Require approval and sign-off for major document revisions']}
  • {'finding': 'No Audit Trail for AI Model Retraining Activities', 'what_is_missing': 'Retraining documentation and traceability of when and how models evolve.', 'how_to_close': ['Document every retraining instance with dates, data used, reasons, and', 'Store logs in a centralized, secure location', 'Include retraining audits in your AIMS review process']}
7.5.1
General

The AI management system must include the documented information required by this document, together with any documented information the organisation determines is necessary for the system's effectiveness. What is necessary varies with the size of the organisation, the complexity of its processes and the competence of its people.

Artefacts an auditor will ask for
  • List of documented information required by the standard
  • Justification for additional documentation deemed necessary
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
7.5.2
Creating and updating

When creating and updating documented information, ensure it is appropriately identified and described, in a suitable format and on suitable media, and reviewed and approved for suitability and adequacy before use.

Artefacts an auditor will ask for
  • Document control procedure covering identification, format and media
  • Review and approval records prior to use
  • Template or format standards
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
7.5.3
Control of documented information

Control the documented information the AI management system requires so that it is available and fit for use where and when it is needed, and adequately protected against loss of confidentiality, improper use or loss of integrity. Address distribution, access, retrieval and use; storage and preservation, including legibility; version control; and retention and disposition. Documented information of external origin that the organisation relies on must be identified and controlled in the same way.

Artefacts an auditor will ask for
  • Access control records for AIMS documentation
  • Version history and distribution records
  • Retention and disposal records
  • Register of controlled documents of external origin
Where this commonly fails
  • AI policy adopted but no inventory of AI systems in use, so scope is theoretical.
  • Model cards exist but datasets undocumented or untraceable to training pipelines.
  • Risk dimensions limited to security and accuracy; fairness and contestability omitted.
  • Third-party AI (foundation models, APIs) not assessed for their training data or alignment.
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO/IEC 42001:2023 framework page.