ISO 42001 Annex A: All 38 Controls Explained
A plain-English breakdown of every Annex A control in ISO/IEC 42001:2023, organised by the 9 control groups (A.2 through A.10), with the intent and evidence requirement for each.
How Annex A works
ISO/IEC 42001:2023 Annex A is a reference list of 38 controls organised in 9 control groups (A.2 through A.10). Unlike the main clauses (which are mandatory requirements), Annex A controls are applied selectively based on your risk assessment. Your Statement of Applicability (SoA) lists which controls apply to your AIMS scope, which you've chosen to exclude, and the justification for each decision.
Each control listed below maps to a control clause in Annex A. The Professional tier of our toolkit includes a 9-part Annex A deep-dive set, one document per control group, covering intent, implementation sequence, evidence requirements, common failure modes, and auditor Q&A for every control.
A.2, Policies related to AI (3 controls)
- A.2.2 AI policy, establish an overarching AI policy. Top management signs it.
- A.2.3 Alignment with other organisational policies, ensure the AI policy is consistent with privacy, security, ethics, and legal policies.
- A.2.4 Review of the AI policy, review and update the policy periodically and after material changes.
A.3, Internal organisation (2 controls)
- A.3.2 AI roles and responsibilities, define and assign AI roles at every level: AIMS owner, risk lead, data owners, system owners.
- A.3.3 Reporting of concerns, provide a channel for staff and third parties to raise AI-related concerns (bias, safety, ethics).
A.4, Resources for AI systems (5 controls)
- A.4.2 Resource documentation, document the computing, data, tooling, and human resources used to develop and operate AI systems.
- A.4.3 Data resources, document data sources, quality, provenance, and lifecycle.
- A.4.4 Tooling resources, document the tools, platforms, and services used for AI development and operation.
- A.4.5 System and computing resources, document the infrastructure supporting AI systems.
- A.4.6 Human resources, document the roles, competencies, and training for AI-involved personnel.
A.5, Assessing impacts of AI systems (4 controls)
- A.5.2 AI system impact assessment process, establish a formal process for assessing AI system impacts on individuals, groups, and society.
- A.5.3 Documentation of AI system impact assessments, record the results of every impact assessment.
- A.5.4 Assessing AI system impacts on individuals or groups, specifically evaluate impacts on people (bias, fairness, autonomy, privacy).
- A.5.5 Assessing societal impacts of AI systems, evaluate broader societal effects (environment, economy, information ecosystem).
Colorado AI Act note: A.5 controls (AI impact assessment) align closely with impact-assessment expectations under the EU AI Act and broader AI governance frameworks.
A.6, AI system life cycle (9 controls, the largest group)
- A.6.1.2 Objectives for responsible development of AI systems, define responsible-development objectives aligned with the AI policy.
- A.6.1.3 Processes for responsible design and development, establish processes for design, architecture, and development.
- A.6.2.2 AI system requirements and specification, document requirements (functional, non-functional, ethical).
- A.6.2.3 Documentation of AI system design and development, record design decisions and technical documentation.
- A.6.2.4 AI system verification and validation, verify and validate AI systems before deployment.
- A.6.2.5 AI system deployment, deploy AI systems under controlled conditions.
- A.6.2.6 AI system operation and monitoring, operate and monitor AI systems in production.
- A.6.2.7 AI system technical documentation, maintain technical documentation throughout the lifecycle.
- A.6.2.8 AI system event logs, log significant events for traceability.
EU AI Act note: A.6 operationalises the EU AI Act Article 9 risk-management system and Article 15 accuracy/robustness obligations.
A.7, Data for AI systems (5 controls)
- A.7.2 Data for development and enhancement of AI systems, govern data used for model development.
- A.7.3 Acquisition of data, acquire data lawfully, with provenance.
- A.7.4 Quality of data for AI systems, ensure data quality, representativeness, and relevance.
- A.7.5 Data provenance, record data origin and lineage.
- A.7.6 Data preparation, govern data preparation, transformation, and labelling.
EU AI Act note: A.7 operationalises the EU AI Act Article 10 data-governance requirements for high-risk AI systems.
A.8, Information for interested parties (4 controls)
- A.8.2 System documentation and information for users, provide clear documentation for users.
- A.8.3 External reporting, establish external reporting channels (regulators, partners).
- A.8.4 Communication of incidents, communicate significant incidents to affected parties.
- A.8.5 Information for interested parties, keep stakeholders informed throughout the lifecycle.
EU AI Act note: A.8.4 aligns with Article 73 serious-incident reporting obligations (tiered 2/10/15-day deadlines; applies from 2 December 2027 under the Digital Omnibus, Regulation (EU) 2026/1744, in force 27 July 2026).
A.9, Use of AI systems (3 controls)
- A.9.2 Processes for responsible use of AI systems, define responsible-use processes for deployers.
- A.9.3 Objectives for responsible use of AI systems, establish objectives for responsible use.
- A.9.4 Intended use of the AI system, document intended use and foreseeable misuse.
A.10, Third-party and customer relationships (3 controls)
- A.10.2 Allocation of responsibilities, allocate AI responsibilities across the value chain.
- A.10.3 Suppliers, govern supplier AI systems through procurement controls.
- A.10.4 Customers, clarify customer responsibilities and obligations.
Procurement note: A.10 is the primary channel through which Microsoft SSPA, enterprise vendor questionnaires, and EU AI Act Article 25 supply-chain obligations are satisfied.
Where Annex A controls come from in the toolkit
In our Starter tier, the AIMS-07 Statement of Applicability pre-populates all 38 Annex A controls with status, justification, and implementation guidance fields. Each other AIMS document addresses one or more Annex A controls:
- AIMS-01 AI Policy → A.2.2, A.2.3
- AIMS-18 AI System Inventory → A.4.2
- AIMS-19 AI System Lifecycle Procedure → A.6 (9 controls)
- AIMS-20 Data Management Procedure → A.7 (5 controls)
- AIMS-21 Supplier Management Procedure → A.10 (3 controls)
- AIMS-22 Incident Response Procedure → A.8.4
The Professional tier's 9 Annex A deep-dive documents then cover each control in detail: auditor expectations, implementation sequence, evidence requirements, common failure modes, and interview Q&A patterns.