ISO 42001 Documentation: Complete Document List
What documents does an ISO/IEC 42001:2023 implementation typically need? ISO doesn't prescribe a fixed count. This list is the durable 23-document set covering every clause requirement and every Annex A group.
Why there's no "official" document count
ISO/IEC 42001:2023 uses the phrase "documented information" rather than listing specific documents. The standard tells you what must be documented (policies, objectives, risk methodology, risk register, Statement of Applicability, operational procedures, audit records, etc.) but not how those are split into files. Some consultancies publish a list of 19 mandatory documents; others publish 25+. They're all defensible because the standard is outcome-based, not document-count-based.
The 23 documents below are the durable set: one document for each clause requirement that typically deserves its own artefact, plus the operational procedures that cover Annex A controls. These correspond to the Starter tier of our toolkit.
Foundation, Clauses 4 and 5 (3 documents)
- AIMS-01 AI Policy, Clause 5.2. Top-management approved AI policy including purpose, commitments, framework for objectives. Signed and dated.
- AIMS-02 AIMS Scope Statement, Clause 4.3. Which AI systems and which organisational boundaries are in scope; exclusions and justifications.
- AIMS-03 AI Objectives, Clause 6.2. Measurable AI objectives with timelines, owners, and review cadence.
Risk and impact, Clause 6 (7 documents)
- AIMS-04 Risk Assessment Methodology, Clause 6.1.2. How risks are identified, analysed, evaluated, treated. Defines scoring scales and risk appetite.
- AIMS-05 AI Risk Register, Clause 6.1.2. All identified AI risks with ratings, owners, treatments. 20 pre-seeded example risks in the Starter.
- AIMS-06 Risk Treatment Plan, Clause 6.1.3. For each unacceptable risk: treatment, timeline, owner, residual rating.
- AIMS-06a Risk Treatment Action Catalogue, Clause 6.1.3. Full description of every treatment action: what it is, how completion is verified, who verifies it independently, the evidence retained, and the inherent→residual→target risk movement. Added in v2.3 after a customer found AIMS-06 referenced actions by ID without describing them. The account is here.
- AIMS-07 Statement of Applicability, Clause 6.1.3. All 38 Annex A controls with status and justification. See the SoA page.
- AIMS-08 AI Impact Assessment Procedure, Clause 6.1.4 and A.5.2. How impact assessments are performed.
- AIMS-09 AI Impact Assessment Record Template, A.5.3. Completed record per AI system.
Support, Clause 7 (3 documents)
- AIMS-10 Document Control Procedure, Clause 7.5. Version control, approval, retention, disposition.
- AIMS-11 Competence Matrix, Clause 7.2, 5.3. RACI + competence tracking for AIMS roles.
- AIMS-12 Communication Plan, Clause 7.4. Internal and external communications.
Evaluation and improvement, Clauses 9, 10 (5 documents)
- AIMS-13 Internal Audit Programme, Clause 9.2.
- AIMS-14 Internal Audit Report Template, Clause 9.2.
- AIMS-15 Management Review Minutes Template, Clause 9.3. Includes the mandatory input and output agenda items.
- AIMS-16 Nonconformity and CAPA Procedure, Clause 10.2.
- AIMS-17 Nonconformity Register, Clause 10.2.
Annex A operational documents (5 documents)
- AIMS-18 AI System Inventory, A.4.2. Every AI system you use, build, or ship.
- AIMS-19 AI System Lifecycle Procedure, A.6 (9 controls).
- AIMS-20 Data Management Procedure, A.7 (5 controls).
- AIMS-21 Supplier Management Procedure, A.10 (3 controls).
- AIMS-22 Incident Response Procedure, A.8.4. Implements EU AI Act Article 73 tiered 2/10/15-day reporting from 2 December 2027.
Beyond the 22
The Professional tier adds 24 more artefacts: 9 Annex A deep-dives, 7 Clause playbooks, a Four-Way Crosswalk document, a Gap Analysis workbook with 64 formulas, a 90-Day Roadmap workbook, 3 industry Impact Assessment variants (SaaS, FinTech, HealthTech), and the Microsoft SSPA Section K mapping. The Audit-Ready tier adds 5 certification-launch artefacts (Pre-Audit Self-Assessment, Stage 1 and Stage 2 Evidence Binders, Auditor Briefing Pack, Marketing Kit).
Some organisations add further documents, a Master Policy Manual, a standalone AI Ethics Policy, a Board-reporting Pack, a customer-facing Trust Centre. These are optional for certification but can be useful organisationally.