Create AIMS Policy for ISO42001 Compliance

Key Facts: AI Policy Under ISO/IEC 42001:2023 #

  • Clause 5.2 requires top management to establish an AI policy that is purpose-appropriate, provides a framework for objectives, commits to applicable requirements, and commits to continual improvement [Source 1]
  • The AI policy must be documented, communicated internally, and available to interested parties [Source 1]
  • Annex A domain A.2 requires operational AI policies beneath the strategic policy — covering development, use, bias mitigation, and change management [Source 1]
  • Annex C identifies ethical principles the policy should address: fairness, transparency, explainability, accountability, human oversight, safety, security, and privacy [Source 1]
  • The policy aligns with the OECD AI Principles (2019), the NIST AI Risk Management Framework, and the EU AI Act risk-based governance requirements [Source 2, 3, 4]
  • 76% of organizations plan to pursue AI compliance with a framework like ISO 42001 — A-LIGN 2025 Compliance Benchmark Report [Source 5]
  • The AI policy provides the foundational governance mandate from which all other AIMS processes, controls, and objectives flow [Source 1]

What Does ISO 42001 Clause 5.2 Require for an AI Policy? #

Before presenting the sample policy, it is worth understanding exactly what Clause 5.2 demands. The requirements are precise but deliberately allow organizations to shape the policy to their own context [Source 1].

Top management shall establish an AI policy that:

Requirement What It Means in Practice
(a) Is appropriate to the purpose of the organization The policy reflects the organization’s specific AI activities — whether it develops AI, deploys third-party AI, or both. A hospital using AI for clinical decision support needs a different policy emphasis than a company building large language models.
(b) Provides a framework for setting AI objectives The policy establishes the direction from which measurable AI objectives (Clause 6.2) are derived — objectives around fairness, performance, transparency, incident response, and compliance.
(c) Includes a commitment to meet applicable requirements The policy commits to legal, regulatory, contractual, and ethical requirements — including the EU AI Act, privacy legislation, sector-specific regulations, and international AI principles.
(d) Includes a commitment to continual improvement The policy is not static. It commits the organization to ongoing improvement of the AIMS through monitoring, audit, management review, and corrective action.

The policy must also:

  • Be available as documented information (Clause 7.5)
  • Refer to other organizational policies as relevant (information security, data protection, ethics, HR)
  • Be communicated within the organization
  • Be available to interested parties as appropriate

How Does the AI Policy Fit Into the Broader AIMS? #

The AI policy is the apex document. Every other element of the AI management system — risk assessments, impact assessments, control implementations, training programs, monitoring activities, and audit processes — should trace back to a commitment or principle established in the policy. It sets the tone. Everything else operationalizes it.


Sample AI Policy — Development and Use of AI Systems #

Policy Title: AI Policy — Development and Use of AI Systems

Policy Number: [Organization Policy Number]

Version: [Version Number]

Effective Date: [Date]

Last Reviewed: [Date]

Next Review Date: [Date — no later than 12 months from effective date]

Policy Owner: [Chief AI Officer / Chief Technology Officer / Chief Privacy Officer]

Approved By: [Board of Directors / Executive Leadership Team]

Classification: [Internal / Public — as determined by the organization]

What Is the Purpose of This Policy? #

This policy establishes [Organization Name]’s commitment to the responsible development, provision, and use of artificial intelligence (AI) systems. It provides the strategic framework for the AI Management System (AIMS) and sets the direction from which AI objectives, operational policies, and controls are derived [Source 1].

This policy applies to all AI systems developed, deployed, procured, or used by [Organization Name], across all business units, functions, and geographies. It applies to all employees, contractors, agents, and third parties who are involved in any stage of the AI system lifecycle — from design and development through deployment, monitoring, and decommissioning.

For the purposes of this policy, an AI system is a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments [Source 1, 4].

What Principles Guide Our Development and Use of AI? #

[Organization Name] commits to the following principles in all AI activities. These principles are aligned with the OECD AI Principles, the NIST AI Risk Management Framework, and the requirements of ISO/IEC 42001:2023 [Source 2, 3].

1. Fairness and Non-Discrimination #

AI systems developed or used by [Organization Name] must not produce outcomes that unfairly discriminate against individuals or groups based on protected characteristics — including race, gender, age, disability, religion, sexual orientation, or socioeconomic status. We commit to assessing AI systems for bias throughout their lifecycle and implementing mitigation measures where bias is identified.

2. Transparency #

Individuals who interact with or are affected by our AI systems have the right to know when AI is being used and how it influences decisions that affect them. [Organization Name] will clearly disclose the use of AI in customer-facing, employee-facing, and public-facing contexts, at a level of detail appropriate to the audience and the risk.

3. Explainability #

AI system outputs — particularly those that inform decisions with material consequences for individuals — must be interpretable and explainable at a level appropriate to the context. Where a fully interpretable explanation is not technically feasible, [Organization Name] will provide meaningful information about the factors that influenced the output and the limitations of the system.

4. Accountability #

Every AI system must have a clearly identified owner who is accountable for its performance, compliance, and outcomes. Accountability cannot be delegated to the AI system itself. Decisions informed by AI remain the responsibility of the people and the organization that deploy them.

5. Human Oversight #

[Organization Name] will implement human oversight mechanisms for AI systems proportionate to the risk they present. AI systems that inform high-stakes decisions — affecting health, safety, legal rights, financial standing, or access to essential services — require meaningful human review before action is taken. The level of human oversight (human-in-the-loop, human-on-the-loop, or human-in-command) will be determined through the AI risk assessment process.

6. Safety and Reliability #

AI systems must operate reliably within their intended use and reasonably foreseeable conditions. [Organization Name] will test AI systems rigorously before deployment, monitor their performance in production, and maintain the ability to intervene, correct, or shut down systems that behave unexpectedly or cause harm.

7. Security #

AI systems and the data they rely on must be protected against unauthorized access, manipulation, and adversarial attack. [Organization Name] will apply its information security controls (aligned with ISO/IEC 27001 where applicable) to AI systems and will address AI-specific security risks — including data poisoning, model theft, and prompt injection — through dedicated controls.

8. Privacy and Data Governance #

Personal data used in the development, training, testing, or operation of AI systems must be collected, used, and disclosed in compliance with applicable privacy legislation — including [applicable legislation, e.g., PHIPA, PIPEDA, GDPR, provincial privacy acts]. [Organization Name] will apply data minimization principles, ensure data quality and provenance, and maintain documented data governance processes for all AI-related data activities.

9. Societal and Environmental Responsibility #

[Organization Name] will consider the broader societal and environmental impacts of its AI systems, including energy consumption, environmental footprint, and effects on employment and communities. AI systems that present unacceptable societal risks will not be developed or deployed.

What AI Activities Does This Policy Govern? #

This policy governs the following activities across the AI system lifecycle:

Lifecycle Stage Activities Covered
Design and Planning Problem definition, feasibility assessment, AI system impact assessment, selection of AI approach, ethical review.
Data Management Data collection, labelling, quality assurance, bias assessment, provenance tracking, storage, retention, and disposal.
Development Model development, training, validation, testing (including fairness and robustness testing), and documentation.
Deployment Integration into production systems, user acceptance testing, deployment approval, and release management.
Monitoring and Operation Performance monitoring, drift detection, incident management, user feedback, and ongoing bias assessment.
Third-Party AI Procurement, evaluation, and governance of AI systems, components, models, or services obtained from third parties.
Decommissioning Retirement of AI systems, data disposal, model archival, and transition planning.

How Does [Organization Name] Manage AI Risk? #

[Organization Name] commits to a systematic, risk-based approach to AI governance, as required by ISO 42001 Clause 6.1 [Source 1].

AI Risk Assessment (Clause 6.1.2). All AI systems within the scope of the AIMS will undergo a formal AI risk assessment before deployment and at planned intervals during operation. The risk assessment identifies and evaluates risks specific to AI — including bias, lack of transparency, data quality degradation, security vulnerabilities, regulatory non-compliance, and unintended consequences — and determines appropriate risk treatment measures.

AI System Impact Assessment (Clause 6.1.4). AI systems that may affect individuals, groups, or society will undergo an impact assessment that evaluates potential consequences — positive and negative — across dimensions including fairness, privacy, safety, autonomy, and access to services. The depth and rigor of the impact assessment will be proportionate to the system’s risk classification.

Risk Appetite. [Organization Name] defines its AI risk appetite as [conservative / moderate / risk-accepting — to be determined by the organization]. AI systems that exceed the organization’s risk tolerance will not be deployed without explicit approval by [approving authority] and the implementation of additional controls.

Prohibited Uses. [Organization Name] will not develop or deploy AI systems for the following purposes:

  • Social scoring of individuals
  • Mass surveillance without lawful authority and appropriate oversight
  • Manipulation of human behaviour through subliminal techniques
  • Any use classified as “unacceptable risk” under the EU AI Act or equivalent regulation
  • [Organization to add any additional prohibited uses specific to its context]

What Are the Roles and Responsibilities for AI Governance? #

Role Responsibilities
Executive Leadership / Board Approve the AI policy. Allocate resources for the AIMS. Review AIMS performance through management review (Clause 9.3). Set the organization’s AI risk appetite.
AI Governance Committee Oversee implementation of the AI policy. Review AI risk assessments and impact assessments. Approve high-risk AI deployments. Monitor regulatory developments. Report to executive leadership.
Policy Owner (CAIO / CTO / CPO) Maintain and update this policy. Ensure alignment with organizational strategy, regulatory requirements, and the AIMS. Lead the management review process.
AI System Owners Accountable for individual AI systems throughout their lifecycle. Ensure risk assessments, impact assessments, and controls are implemented and maintained. Report incidents and performance issues.
Development and Engineering Teams Develop AI systems in accordance with this policy and operational policies. Implement technical controls for fairness, security, and reliability. Document design decisions and testing results.
Data Governance Team Ensure data used in AI systems meets quality, provenance, and compliance requirements. Conduct bias assessments on training and operational data. Manage data lifecycle.
All Personnel Comply with this policy and associated operational policies. Report AI incidents, concerns, or suspected policy violations. Complete required AI governance training.

How Does This Policy Relate to Other Organizational Policies? #

As required by Clause 5.2, this policy is aligned with and should be read alongside the following organizational policies [Source 1]:

  • Information Security Policy (ISO/IEC 27001, where applicable)
  • Data Protection / Privacy Policy (aligned with applicable privacy legislation)
  • Data Governance Policy
  • Ethics and Code of Conduct
  • Risk Management Policy
  • Acceptable Use Policy
  • Procurement and Vendor Management Policy
  • Incident Management Policy
  • Human Resources Policy (for disciplinary and training obligations)

Where a conflict exists between this policy and another organizational policy, the more restrictive requirement applies. Conflicts should be escalated to the Policy Owner for resolution.

What Operational AI Policies Support This Policy? #

This strategic AI policy is supported by operational policies that provide detailed guidance for specific aspects of AI governance, as required by Annex A control domain A.2 [Source 1]:

Operational Policy Scope
AI Development and Use Standards Technical standards for model development, testing, validation, documentation, and deployment approval.
AI Acceptable Use Policy Rules for appropriate and inappropriate use of AI tools and systems by staff — including generative AI.
AI Bias Detection and Mitigation Policy Procedures for assessing, monitoring, and mitigating bias in AI training data, models, and outputs.
AI Data Management Policy Data quality, provenance, labelling, retention, and disposal requirements specific to AI systems.
AI Incident Response Policy Procedures for detecting, reporting, investigating, and remediating AI system incidents — including unintended outputs, safety events, and security breaches.
AI Third-Party Governance Policy Due diligence, contractual, and monitoring requirements for AI systems, components, or services obtained from or provided to third parties.
AI Change Management Policy Controls for changes to AI models, training data, and production systems — including retraining, fine-tuning, and version management.

How Is Compliance With This Policy Monitored and Enforced? #

Monitoring. Compliance with this policy is monitored through the internal audit program (Clause 9.2), management review (Clause 9.3), AI system performance monitoring (Clause 9.1), and incident reporting.

Non-compliance. Violations of this policy may result in disciplinary action, up to and including termination of employment or contract. Non-compliance that results in harm to individuals, regulatory enforcement, or legal liability will be escalated to executive leadership and, where required, reported to relevant regulators.

Reporting concerns. Any employee, contractor, or stakeholder who becomes aware of a potential violation of this policy — or who has concerns about the ethical, safety, or fairness implications of an AI system — should report the concern to the AI Governance Committee or the Policy Owner. [Organization Name] prohibits retaliation against individuals who raise concerns in good faith.

How Often Is This Policy Reviewed? #

This policy is reviewed at least annually as part of the AIMS management review process (Clause 9.3), and updated whenever [Source 1]:

  • The organization’s AI activities, risk profile, or strategic direction change materially.
  • New or amended legislation or regulation takes effect (including the EU AI Act phased requirements).
  • Audit findings, incident investigations, or stakeholder feedback identify gaps.
  • New AI technologies, methods, or use cases are adopted that are not addressed by the current policy.
  • The organization’s broader policy framework (information security, privacy, ethics) is updated.

All changes to this policy must be approved by [approving authority] and communicated to all personnel within [timeframe, e.g., 30 days].

What Commitments Does [Organization Name] Make Through This Policy? #

In summary, [Organization Name] commits to:

  1. Developing and using AI systems responsibly — guided by the principles of fairness, transparency, explainability, accountability, human oversight, safety, security, privacy, and societal responsibility.
  2. Meeting all applicable requirements — legal, regulatory, contractual, ethical, and organizational — governing the development and use of AI.
  3. Managing AI risk systematically — through formal risk assessments, impact assessments, and proportionate controls across the AI system lifecycle.
  4. Maintaining human oversight — ensuring that humans remain accountable for decisions informed by AI, with oversight mechanisms proportionate to risk.
  5. Continually improving the AI management system — through monitoring, audit, management review, and corrective action, so that our governance keeps pace with the technology it governs.
  6. Communicating openly — making this policy available to interested parties and providing transparency about our AI practices.

Frequently Asked Questions About AI Policies Under ISO 42001 #

What does ISO 42001 Clause 5.2 require for an AI policy? #

ISO/IEC 42001:2023 Clause 5.2 requires top management to establish an AI policy that: (a) is appropriate to the purpose of the organization; (b) provides a framework for setting AI objectives; (c) includes a commitment to meet applicable requirements; and (d) includes a commitment to continual improvement of the AI management system. The policy must be available as documented information, refer to other relevant organizational policies, be communicated within the organization, and be available to interested parties as appropriate.

What topics should an ISO 42001 AI policy cover? #

A compliant AI policy should address: the organization’s commitment to responsible AI development and use; ethical principles including fairness, transparency, explainability, and accountability; AI risk management and impact assessment processes; data governance for AI systems including data quality, provenance, and bias mitigation; human oversight requirements calibrated to the risk level of each AI system; privacy and security obligations; third-party AI governance; regulatory compliance including alignment with the EU AI Act and other applicable legislation; roles, responsibilities, and authorities for AI governance; and continual improvement of the AI management system.

How does the AI policy relate to Annex A controls in ISO 42001? #

The AI policy required by Clause 5.2 is the strategic, top-level policy that establishes direction and commitment. Annex A control domain A.2 (Policies related to AI) requires additional operational policies that sit beneath the strategic policy — such as AI development and use policies, acceptable use policies, bias detection and mitigation policies, and AI change management policies. Control A.2.3 requires alignment with other organizational policies (information security, data protection, ethics, HR), and A.2.4 requires periodic review and update. The strategic AI policy should reference and provide the framework for these operational policies.

What ethical principles should an AI policy include? #

ISO 42001’s Annex C identifies AI system objectives that the policy should address, aligned with international frameworks including the OECD AI Principles and NIST AI RMF. Key ethical principles include: fairness and bias mitigation — AI systems must not produce discriminatory outcomes; transparency — stakeholders must understand when AI is being used and how it influences decisions; explainability — AI outputs must be interpretable at a level appropriate to the context; accountability — clear ownership of AI system decisions and outcomes; human oversight — appropriate human involvement in AI decision-making based on risk level; safety and security — AI systems must operate reliably and be protected against threats; and privacy — personal data used in AI systems must be governed in compliance with applicable privacy legislation.

Who is responsible for the AI policy under ISO 42001? #

Under Clause 5.1, top management is responsible for establishing, approving, and demonstrating commitment to the AI policy. Clause 5.3 requires that roles, responsibilities, and authorities for the AI management system be assigned and communicated. In practice, the AI policy is typically owned by a senior executive such as the Chief AI Officer, Chief Technology Officer, or Chief Privacy Officer, with approval by the board or executive leadership. An AI Governance Committee or equivalent body is often established to oversee policy implementation, and all personnel involved in AI development, deployment, or use are responsible for complying with the policy.

How often should the AI policy be reviewed and updated? #

Annex A control A.2.4 requires that AI policies be reviewed and updated at planned intervals or when significant changes occur. In practice, the AI policy should be reviewed at least annually as part of the management review process required by Clause 9.3. It should also be updated when there are material changes to the organization’s AI systems, risk profile, regulatory environment (such as new requirements under the EU AI Act), organizational structure, or strategic direction. Changes resulting from incident investigations, audit findings, or stakeholder feedback should also trigger policy review.


Sources and References #

  1. ISO, ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. Published December 18, 2023. Clauses 4–10, Annexes A–D. Available at: iso.org
  2. OECD, Recommendation of the Council on Artificial Intelligence (OECD AI Principles), 2019. Available at: oecd.ai
  3. National Institute of Standards and Technology (NIST), AI Risk Management Framework (AI RMF 1.0), January 2023. Available at: nist.gov
  4. European Parliament and Council, Regulation (EU) 2024/1689 — Artificial Intelligence Act. Entered into force August 1, 2024. Available at: eur-lex.europa.eu
  5. A-LIGN, 2025 Compliance Benchmark Report — AI Governance and ISO 42001 Adoption. Available at: a-lign.com
  6. Infocomm Media Development Authority of Singapore, Model Artificial Intelligence Governance Framework, Second Edition, 2020. Available at: imda.gov.sg

This sample policy is provided for informational and educational purposes only and does not constitute legal, regulatory, or certification advice. Organizations should adapt this template to their specific context and consult qualified professionals. For the official text of ISO/IEC 42001:2023, refer to iso.org.

What are your feelings
Updated on June 19, 2026
Scroll to Top