ISO 42001 Clauses 4–10 Explained in Plain English
A working walkthrough of every mandatory clause of ISO/IEC 42001:2023, what it demands, what evidence auditors look for, and which toolkit documents satisfy it.
Clause 4, Context of the organisation
4.1 Understanding the organisation and its context
Identify external and internal issues relevant to AI governance. External: regulation (EU AI Act, Colorado AI Act, Microsoft SSPA), competitive landscape, societal concerns about AI. Internal: organisational structure, AI maturity, risk appetite, existing management systems.
Evidence: documented context analysis, reviewed annually.
4.2 Understanding the needs and expectations of interested parties
Identify who is affected by your AI systems: customers, employees, regulators, investors, partners, affected individuals. Document their requirements and expectations.
Evidence: interested-parties register.
4.3 Determining the scope of the AIMS
Define which organisational boundaries and which AI systems are in scope. A narrow, risk-focused scope is usually better than a broad one.
Evidence: AIMS Scope Statement (AIMS-02).
4.4 AI management system
Establish, implement, maintain, and continually improve the AIMS, including its processes and their interactions.
Evidence: process map and interactions documentation.
Clause 5, Leadership
5.1 Leadership and commitment
Top management must own the AIMS, ensure it aligns with strategy, make resources available, and promote continual improvement.
Evidence: board resolutions, management-review participation records.
5.2 AI policy
Establish an AI policy approved at top-management level. It must be appropriate to the organisation, provide a framework for objectives, commit to meeting applicable requirements, and commit to continual improvement.
Evidence: signed AI Policy (AIMS-01).
5.3 Organisational roles, responsibilities, and authorities
Assign responsibility for the AIMS. Typical roles: AIMS Owner, AI Risk Lead, AI System Owners, Data Lead.
Evidence: RACI matrix, competence matrix (AIMS-11).
Clause 6, Planning
6.1 Actions to address risks and opportunities
Consider context, interested-party needs, and risks and opportunities that could affect AIMS outcomes. Plan actions to address them.
6.1.2 AI risk assessment
Define a risk-assessment methodology. Identify risks related to AI, covering individuals, groups, and society, not just the organisation.
Evidence: Risk Assessment Methodology (AIMS-04), AI Risk Register (AIMS-05). See risk assessment page.
6.1.3 AI risk treatment
Select risk-treatment options and necessary controls. Produce the Statement of Applicability.
Evidence: Risk Treatment Plan (AIMS-06), Risk Treatment Action Catalogue (AIMS-06a), Statement of Applicability (AIMS-07). See SoA page.
6.1.4 AI system impact assessment
Establish a process for assessing AI system impacts on individuals, groups, and society. Document results.
Evidence: Impact Assessment Procedure (AIMS-08), Impact Assessment Records (AIMS-09). See impact assessment page.
6.2 AI objectives and planning to achieve them
Set measurable AI objectives. Plan how they'll be achieved, with timelines and responsibilities.
Evidence: AI Objectives (AIMS-03).
6.3 Planning of changes
When changes are needed to the AIMS, plan them systematically, including purpose, consequences, integrity of the system, and resources.
Clause 7, Support
7.1 Resources
Determine and provide the resources needed for the AIMS.
7.2 Competence
Identify competence requirements for people doing work affecting AIMS performance. Ensure competence through education, training, or experience.
Evidence: Competence Matrix (AIMS-11).
7.3 Awareness
Make people aware of the AI policy, relevant objectives, their contribution, and implications of non-conformity.
7.4 Communication
Determine internal and external communications needs, what, when, with whom, how.
Evidence: Communication Plan (AIMS-12).
7.5 Documented information
Control documented information, creation, update, identification, format, review, approval. Control distribution, access, retrieval, use, storage, preservation, control of changes, retention, disposition.
Evidence: Document Control Procedure (AIMS-10). This is the strongest single mapping to the EU AI Act's Annex IV technical documentation requirements.
Clause 8, Operation
8.1 Operational planning and control
Plan, implement, and control the processes needed to meet AIMS requirements.
8.2 AI risk assessment (operational)
Perform AI risk assessments at planned intervals and when changes occur. This is the operational, ongoing cycle, distinct from the initial 6.1.2 methodology-setting.
8.3 AI risk treatment (operational)
Implement the risk treatment plan. Monitor effectiveness.
8.4 AI system impact assessment (operational)
Conduct impact assessments for each AI system in scope. Document results and use them to inform risk treatment.
Evidence: populated Impact Assessment Records (AIMS-09).
Clause 9, Performance evaluation
9.1 Monitoring, measurement, analysis, and evaluation
Determine what needs to be monitored and measured; methods; when; who. Evaluate performance and effectiveness of the AIMS.
9.2 Internal audit
Conduct internal audits at planned intervals. Plan, establish, implement, and maintain an audit programme.
Evidence: Internal Audit Programme (AIMS-13), Audit Reports (AIMS-14).
9.3 Management review
Top management reviews the AIMS at planned intervals. Inputs: audit results, feedback, performance, risks and opportunities, incident data. Outputs: improvements, changes, resource needs.
Evidence: Management Review Minutes (AIMS-15).
Clause 10, Improvement
10.1 Continual improvement
Continually improve the AIMS's suitability, adequacy, and effectiveness.
10.2 Nonconformity and corrective action
When a nonconformity occurs: react to it; evaluate need for action; implement; review effectiveness; update AIMS if necessary.
Evidence: CAPA Procedure (AIMS-16), Nonconformity Register (AIMS-17).
How auditors test each clause
Our Professional tier includes a Clause Playbook for each of clauses 4 through 10, describing exactly what auditors ask, what evidence to have ready, and common mistakes organisations make. The playbooks are one of the most-referenced parts of the toolkit during pre-audit preparation.