Demystifying ISO42001

ISO 42001 · CLAUSES AND ANNEX A

ISO/IEC 42001 has 10 clauses and an Annex A of 38 controls, and several guides get the theme count wrong. This piece walks through the ISO 42001 clauses in order and unpacks the ISO 42001 Annex A controls theme by theme. Then it shows how the pieces feed into an ISO 42001 statement of applicability that holds up in audit.

TL;DR

ISO/IEC 42001 runs 10 clauses, and an auditor checks clauses 4 through 10. Annex A adds 38 controls, grouped into 9 themes numbered A.2 through A.10, not 6. A Statement of Applicability records which of the 38 apply to your AI systems and why you excluded the rest.

What trips people up

A number of compliance guides describe Annex A as 6 themes starting at A.5, plus a separate “A.11: AI literacy” control. Neither claim matches the published standard. Annex A runs A.2 through A.10, nine themes, and literacy sits in the main clauses (competence and awareness), not in Annex A.

38Annex A controls
9Annex A themes, A.2 to A.10
10clauses, 4 to 10 audited
Dec 2027EU AI Act high-risk deadline, after the 2026 deferral

Sources: ISO/IEC 42001:2023 · European Parliament, Digital Omnibus on AI

The 10-clause structure, and what an audit checks #

ISO/IEC 42001 follows the same pattern as ISO 27001 and other management system standards. Clauses 1 through 3 set the scope, list normative references, and define terms. An auditor does not test them. Clauses 4 through 10 hold the requirements, and those are what a certification audit reviews.

ClauseTitleWhat it covers
4Context of the organizationInternal and external issues, interested parties, and the scope of your AI management system.
5LeadershipTop management commitment, the AI policy (5.2), and defined roles and responsibilities (5.3).
6PlanningRisks and opportunities, AI objectives, the AI risk assessment (6.1.2), risk treatment (6.1.3), and the AI System Impact Assessment (6.1.4).
7SupportResources, competence, awareness, internal and external communication, documented information.
8OperationRunning the risk assessment and impact assessment in practice, and controlling AI systems across their life cycle.
9Performance evaluationMonitoring, measurement, internal audit, and management review.
10ImprovementNonconformity, corrective action, and continual improvement.

Two required assessments, not one #

Clause 6.1.2 asks you to assess AI risk to your organization, the standard risk management exercise. Clause 6.1.4 asks a different question: how does a specific AI system affect the people and groups it touches. Teams that treat these as the same exercise often miss one of them. See the full breakdown of AI risk assessment against the AI System Impact Assessment for the worked difference between the two.

Clause 5.2 also asks for something the other ISO management standards skip. Your AI policy has to address the effect of your AI systems on individuals and society. That goes beyond the usual commitments to resources and continual improvement.

ThemeNameWhat it covers
A.2Policies related to AISetting, aligning, and reviewing the AI policy. Three controls: A.2.2, A.2.3, A.2.4.
A.3Internal organizationRoles, responsibilities, and reporting of AI concerns.
A.4Resources for AI systemsDocumenting the data, tooling, compute, and people behind each AI system.
A.5Assessing impacts of AI systemsThe impact assessment process on individuals and society, before and during use.
A.6AI system life cycleObjectives, design, development, verification, and deployment.
A.7Data for AI systemsData quality, provenance, and preparation.
A.8Information for interested parties of AI systemsTransparency and documentation for users and other affected parties.
A.9Use of AI systemsResponsible, intended use, including monitoring once a system runs in production.
A.10Third-party and customer relationshipsAllocating responsibility across suppliers, partners, and customers in the AI supply chain.

Annex A.2: three controls, not seven policies #

A common practitioner pattern lists seven AI policies as the Annex A.2 requirement. That list names development standards, acceptable use, bias mitigation, data management, incident response, third-party governance, and change management. It is a convention some consultancies teach. It is not what A.2 says.

ControlWhat it requires
A.2.2An AI policy that top management sets, approves, and communicates.
A.2.3Alignment between the AI policy and your other organizational policies.
A.2.4A scheduled review of the AI policy at planned intervals or after significant change.

You can still write seven separate policy documents if that suits how your team organizes its documents. Label them as your own structure for meeting A.2.2 through A.2.4, not as a fourth ISO requirement. Do that and an auditor has nothing to question.

Building the Statement of Applicability #

The Statement of Applicability, or SoA, is the document that connects your risk work to Annex A. It lists every one of the 38 controls, states whether each one applies to your AI systems, and gives the reason.

  1. Pull findings from both assessments. Your AI risk assessment (6.1.2) and your AI System Impact Assessment (6.1.4) tell you which risks are live in your environment.
  2. Work through all 38 controls. Skipping a theme because it looks irrelevant is the fastest way to fail an audit. Go through A.2 to A.10 in order.
  3. Mark each control applicable or not applicable. Most organizations exclude a handful, seldom all of a theme.
  4. Write a specific reason for every exclusion. A generic label does not survive an auditor’s questions.
  5. Route the finished SoA through management review. Clause 5 makes leadership accountable for what the AIMS covers, so sign-off belongs there.
  6. Update it when your AI systems change. A new model, a new vendor, or a new use case can move a control from not applicable to applicable.

What good looks like

A strong exclusion names the actual reason, for example no AI system in this scope processes biometric data, so A.7.4 does not apply. A weak one says not applicable, nothing more. Auditors accept the first kind and query the second.

JurisdictionStatus as of September 2026
European UnionThe Digital Omnibus moved the deadline for high-risk stand-alone AI systems from August 2026 to 2 December 2027. The deadline for high-risk systems embedded in already-regulated products stays 2 August 2028.
CanadaBill C-27, which carried the Artificial Intelligence and Data Act, died on prorogation on 6 January 2025. Parliament has not reintroduced it, so Canada has no binding federal AI-specific statute.
United States (Colorado)A federal court blocked Colorado’s SB 24-205 in April 2026. Colorado replaced it with SB 26-189, a narrower notice-based law. The governor signed it 14 May 2026, effective 1 January 2027.

Where ISO 42001 sits next to AI law right now #

ISO published ISO/IEC 42001 in December 2023, and the text has not changed since. Every government watching this space has moved its own AI law in the meantime. The EU pushed its main deadline back over a year. Canada’s federal bill died without a replacement. Colorado rewrote its state law after a court blocked the original version. A certification built on ISO 42001 stays put while the law around it keeps shifting.

Certification is not automatic legal compliance

The Cloud Security Alliance’s 2026 research note found five categories of AI Act requirements that ISO/IEC 42001 does not address. European standards bodies are now drafting a companion standard, prEN 18286, to close the gap. Treat ISO 42001 as strong governance groundwork, not a substitute for reading the specific law that applies to your AI system.

Regular use of AI inside a business is now the default rather than the exception. McKinsey’s 2026 global survey found close to nine in ten respondents report regular AI use in at least one business function. That is the population ISO 42001 governs, and it grew past the point where an informal approach to AI risk still holds up.

Frequently asked questions #

How many controls are in ISO 42001 Annex A?

38 controls, organized into 9 themes numbered A.2 through A.10. A.2 covers AI policy, A.10 covers third-party and customer relationships.

What does Annex A.2 require?

Three controls: an AI policy (A.2.2), alignment between that policy and your other policies (A.2.3), and a scheduled review of it (A.2.4). A seven-policy list circulating in some guides is a practitioner habit, not part of the standard.

Do you have to implement all 38 Annex A controls?

No. Annex A is a reference set. Your Statement of Applicability determines which controls apply to your AI systems, based on your risk assessment and impact assessment. It also documents why the rest do not apply.

What is the difference between an AI risk assessment and an AI System Impact Assessment?

Clause 6.1.2 assesses risk to your organization. Clause 6.1.4 assesses how a specific AI system affects the people and groups it touches. ISO 42001 requires both, and they answer different questions.

Is ISO 42001 certification the same as EU AI Act compliance?

No. Independent research has identified gaps between the two, and a companion standard is in development to close them. ISO 42001 certification supports AI Act compliance work without replacing it.

Is there a federal AI law in Canada or the United States like the EU AI Act?

Not yet. Canada’s federal AI bill died on prorogation in January 2025 and has not returned. The United States has no federal AI statute, only state laws such as Colorado’s. Colorado itself rewrote its law in 2026 after a court blocked the first version.

Key takeaways #

  • ISO/IEC 42001 has 10 clauses. An audit checks clauses 4 through 10.
  • Annex A has 38 controls across 9 themes, A.2 through A.10, not 6 themes starting at A.5.
  • A.2 requires 3 controls: an AI policy, its alignment with other policies, and its review.
  • Clause 6.1.2 and Clause 6.1.4 are two separate assessments, risk to the organization and impact on people.
  • The Statement of Applicability documents every control, applicable or not, with a specific reason for each exclusion.
  • ISO 42001 has not changed since December 2023. The EU, Canadian, and US AI law it sits next to has not stood still.
  • Certification is not a substitute for checking the specific AI law that applies to your system.
HZ

Hunter Zhu Founder of Nank.ai, a Toronto firm that takes companies in Canada and the United States to SOC 2, ISO 27001, and ISO 42001. Connect on LinkedIn

Build the AIMS once, keep it current after #

Nank.ai runs ISO 42001 readiness for companies in Canada and the United States. That covers everything from the first risk assessment to a Statement of Applicability an auditor accepts.

What are your feelings
Updated on September 10, 2026
Scroll to Top