ISO 42001 Documentation: Complete Document List

What documents does an ISO/IEC 42001:2023 implementation typically need? ISO doesn't prescribe a fixed count. This list is the durable 23-document set covering every clause requirement and every Annex A group.

Why there's no "official" document count

ISO/IEC 42001:2023 uses the phrase "documented information" rather than listing specific documents. The standard tells you what must be documented (policies, objectives, risk methodology, risk register, Statement of Applicability, operational procedures, audit records, etc.) but not how those are split into files. Some consultancies publish a list of 19 mandatory documents; others publish 25+. They're all defensible because the standard is outcome-based, not document-count-based.

The 23 documents below are the durable set: one document for each clause requirement that typically deserves its own artefact, plus the operational procedures that cover Annex A controls. These correspond to the Starter tier of our toolkit.

Foundation, Clauses 4 and 5 (3 documents)

  • AIMS-01 AI Policy, Clause 5.2. Top-management approved AI policy including purpose, commitments, framework for objectives. Signed and dated.
  • AIMS-02 AIMS Scope Statement, Clause 4.3. Which AI systems and which organisational boundaries are in scope; exclusions and justifications.
  • AIMS-03 AI Objectives, Clause 6.2. Measurable AI objectives with timelines, owners, and review cadence.

Risk and impact, Clause 6 (7 documents)

  • AIMS-04 Risk Assessment Methodology, Clause 6.1.2. How risks are identified, analysed, evaluated, treated. Defines scoring scales and risk appetite.
  • AIMS-05 AI Risk Register, Clause 6.1.2. All identified AI risks with ratings, owners, treatments. 20 pre-seeded example risks in the Starter.
  • AIMS-06 Risk Treatment Plan, Clause 6.1.3. For each unacceptable risk: treatment, timeline, owner, residual rating.
  • AIMS-06a Risk Treatment Action Catalogue, Clause 6.1.3. Full description of every treatment action: what it is, how completion is verified, who verifies it independently, the evidence retained, and the inherent→residual→target risk movement. Added in v2.3 after a customer found AIMS-06 referenced actions by ID without describing them. The account is here.
  • AIMS-07 Statement of Applicability, Clause 6.1.3. All 38 Annex A controls with status and justification. See the SoA page.
  • AIMS-08 AI Impact Assessment Procedure, Clause 6.1.4 and A.5.2. How impact assessments are performed.
  • AIMS-09 AI Impact Assessment Record Template, A.5.3. Completed record per AI system.

Support, Clause 7 (3 documents)

  • AIMS-10 Document Control Procedure, Clause 7.5. Version control, approval, retention, disposition.
  • AIMS-11 Competence Matrix, Clause 7.2, 5.3. RACI + competence tracking for AIMS roles.
  • AIMS-12 Communication Plan, Clause 7.4. Internal and external communications.

Evaluation and improvement, Clauses 9, 10 (5 documents)

  • AIMS-13 Internal Audit Programme, Clause 9.2.
  • AIMS-14 Internal Audit Report Template, Clause 9.2.
  • AIMS-15 Management Review Minutes Template, Clause 9.3. Includes the mandatory input and output agenda items.
  • AIMS-16 Nonconformity and CAPA Procedure, Clause 10.2.
  • AIMS-17 Nonconformity Register, Clause 10.2.

Annex A operational documents (5 documents)

  • AIMS-18 AI System Inventory, A.4.2. Every AI system you use, build, or ship.
  • AIMS-19 AI System Lifecycle Procedure, A.6 (9 controls).
  • AIMS-20 Data Management Procedure, A.7 (5 controls).
  • AIMS-21 Supplier Management Procedure, A.10 (3 controls).
  • AIMS-22 Incident Response Procedure, A.8.4. Implements EU AI Act Article 73 tiered 2/10/15-day reporting from 2 December 2027.

Beyond the 22

The Professional tier adds 24 more artefacts: 9 Annex A deep-dives, 7 Clause playbooks, a Four-Way Crosswalk document, a Gap Analysis workbook with 64 formulas, a 90-Day Roadmap workbook, 3 industry Impact Assessment variants (SaaS, FinTech, HealthTech), and the Microsoft SSPA Section K mapping. The Audit-Ready tier adds 5 certification-launch artefacts (Pre-Audit Self-Assessment, Stage 1 and Stage 2 Evidence Binders, Auditor Briefing Pack, Marketing Kit).

Some organisations add further documents, a Master Policy Manual, a standalone AI Ethics Policy, a Board-reporting Pack, a customer-facing Trust Centre. These are optional for certification but can be useful organisationally.

Start your ISO 42001 implementation

The 23-document Starter pack gets you from purchase to signed AI Policy in 7 days. Professional adds Annex A deep-dives, a 64-formula Gap Analysis workbook, and industry variants. Audit-Ready prepares you for Stage 1.

Version 2.5 · 30 July 2026

A customer found a defect in our toolkit. Here's what we did about it.

He was reading AIMS-06 and noticed it referenced treatment actions by identifier, TRT-001 through TRT-016, without ever describing what any of them were. He was right.

So we audited the whole set and found two more defects he hadn't spotted. Four risks with no treatment action at all, one of them marked "in treatment" with nothing treating it. And two control back-links in the Statement of Applicability that didn't reconcile with the treatment plan. An auditor tracing controls would have found both, as a finding against his AI management system, not against our toolkit.

We rebuilt the documents, wrote a new one — AIMS-06a, the Risk Treatment Action Catalogue — and shipped v2.3 free to every existing customer with a written explanation of exactly what had been wrong.

In v2.5 we found a second defect of the same class that our own v2.3 audit had missed: nine risk scores in AIMS-06a did not match the register they cited. That audit traced every identifier in both directions; it did not trace the values carried alongside them. Both accounts are public, and so is the automated check that now runs before every release.

Read the full account, with the control IDs →

Building this list yourself?

Start with the hardest one. Our free FRIA starter covers Article 27 of the EU AI Act, six sections, ten fundamental rights, and the two things teams always miss.

Free. No sales call. Unsubscribe whenever.