ISO 42001 Clauses 4–10 Explained in Plain English

A working walkthrough of every mandatory clause of ISO/IEC 42001:2023, what it demands, what evidence auditors look for, and which toolkit documents satisfy it.

Clause 4, Context of the organisation

4.1 Understanding the organisation and its context

Identify external and internal issues relevant to AI governance. External: regulation (EU AI Act, Colorado AI Act, Microsoft SSPA), competitive landscape, societal concerns about AI. Internal: organisational structure, AI maturity, risk appetite, existing management systems.

Evidence: documented context analysis, reviewed annually.

4.2 Understanding the needs and expectations of interested parties

Identify who is affected by your AI systems: customers, employees, regulators, investors, partners, affected individuals. Document their requirements and expectations.

Evidence: interested-parties register.

4.3 Determining the scope of the AIMS

Define which organisational boundaries and which AI systems are in scope. A narrow, risk-focused scope is usually better than a broad one.

Evidence: AIMS Scope Statement (AIMS-02).

4.4 AI management system

Establish, implement, maintain, and continually improve the AIMS, including its processes and their interactions.

Evidence: process map and interactions documentation.

Clause 5, Leadership

5.1 Leadership and commitment

Top management must own the AIMS, ensure it aligns with strategy, make resources available, and promote continual improvement.

Evidence: board resolutions, management-review participation records.

5.2 AI policy

Establish an AI policy approved at top-management level. It must be appropriate to the organisation, provide a framework for objectives, commit to meeting applicable requirements, and commit to continual improvement.

Evidence: signed AI Policy (AIMS-01).

5.3 Organisational roles, responsibilities, and authorities

Assign responsibility for the AIMS. Typical roles: AIMS Owner, AI Risk Lead, AI System Owners, Data Lead.

Evidence: RACI matrix, competence matrix (AIMS-11).

Clause 6, Planning

6.1 Actions to address risks and opportunities

Consider context, interested-party needs, and risks and opportunities that could affect AIMS outcomes. Plan actions to address them.

6.1.2 AI risk assessment

Define a risk-assessment methodology. Identify risks related to AI, covering individuals, groups, and society, not just the organisation.

Evidence: Risk Assessment Methodology (AIMS-04), AI Risk Register (AIMS-05). See risk assessment page.

6.1.3 AI risk treatment

Select risk-treatment options and necessary controls. Produce the Statement of Applicability.

Evidence: Risk Treatment Plan (AIMS-06), Risk Treatment Action Catalogue (AIMS-06a), Statement of Applicability (AIMS-07). See SoA page.

6.1.4 AI system impact assessment

Establish a process for assessing AI system impacts on individuals, groups, and society. Document results.

Evidence: Impact Assessment Procedure (AIMS-08), Impact Assessment Records (AIMS-09). See impact assessment page.

6.2 AI objectives and planning to achieve them

Set measurable AI objectives. Plan how they'll be achieved, with timelines and responsibilities.

Evidence: AI Objectives (AIMS-03).

6.3 Planning of changes

When changes are needed to the AIMS, plan them systematically, including purpose, consequences, integrity of the system, and resources.

Clause 7, Support

7.1 Resources

Determine and provide the resources needed for the AIMS.

7.2 Competence

Identify competence requirements for people doing work affecting AIMS performance. Ensure competence through education, training, or experience.

Evidence: Competence Matrix (AIMS-11).

7.3 Awareness

Make people aware of the AI policy, relevant objectives, their contribution, and implications of non-conformity.

7.4 Communication

Determine internal and external communications needs, what, when, with whom, how.

Evidence: Communication Plan (AIMS-12).

7.5 Documented information

Control documented information, creation, update, identification, format, review, approval. Control distribution, access, retrieval, use, storage, preservation, control of changes, retention, disposition.

Evidence: Document Control Procedure (AIMS-10). This is the strongest single mapping to the EU AI Act's Annex IV technical documentation requirements.

Clause 8, Operation

8.1 Operational planning and control

Plan, implement, and control the processes needed to meet AIMS requirements.

8.2 AI risk assessment (operational)

Perform AI risk assessments at planned intervals and when changes occur. This is the operational, ongoing cycle, distinct from the initial 6.1.2 methodology-setting.

8.3 AI risk treatment (operational)

Implement the risk treatment plan. Monitor effectiveness.

8.4 AI system impact assessment (operational)

Conduct impact assessments for each AI system in scope. Document results and use them to inform risk treatment.

Evidence: populated Impact Assessment Records (AIMS-09).

Clause 9, Performance evaluation

9.1 Monitoring, measurement, analysis, and evaluation

Determine what needs to be monitored and measured; methods; when; who. Evaluate performance and effectiveness of the AIMS.

9.2 Internal audit

Conduct internal audits at planned intervals. Plan, establish, implement, and maintain an audit programme.

Evidence: Internal Audit Programme (AIMS-13), Audit Reports (AIMS-14).

9.3 Management review

Top management reviews the AIMS at planned intervals. Inputs: audit results, feedback, performance, risks and opportunities, incident data. Outputs: improvements, changes, resource needs.

Evidence: Management Review Minutes (AIMS-15).

Clause 10, Improvement

10.1 Continual improvement

Continually improve the AIMS's suitability, adequacy, and effectiveness.

10.2 Nonconformity and corrective action

When a nonconformity occurs: react to it; evaluate need for action; implement; review effectiveness; update AIMS if necessary.

Evidence: CAPA Procedure (AIMS-16), Nonconformity Register (AIMS-17).

How auditors test each clause

Our Professional tier includes a Clause Playbook for each of clauses 4 through 10, describing exactly what auditors ask, what evidence to have ready, and common mistakes organisations make. The playbooks are one of the most-referenced parts of the toolkit during pre-audit preparation.

Start your ISO 42001 implementation

The 22-document Starter pack gets you from purchase to signed AI Policy in 7 days. Professional adds Annex A deep-dives, a 64-formula Gap Analysis workbook, and industry variants. Audit-Ready prepares you for Stage 1.