ISO 42001 Requirements: Mandatory Clauses and Controls

What ISO/IEC 42001:2023 actually requires, the 7 mandatory clauses (4 through 10) that every AIMS must satisfy, and the 38 Annex A reference controls applied through the Statement of Applicability.

The shape of ISO 42001 requirements

ISO/IEC 42001:2023 follows the harmonised Annex SL structure used by every modern ISO management-system standard. Clauses 1–3 are introductory (scope, normative references, terms). Clauses 4 through 10 are the mandatory requirements. Annex A provides a reference set of 38 controls that are applied selectively based on a risk assessment, controls are not universally mandatory, but every applicable control listed in your Statement of Applicability becomes part of your obligations.

Clause 4, Context of the organisation

Understand your organisation and its context; identify interested parties and their needs; determine the AIMS scope; establish the AIMS itself and its processes.

Key outputs required: documented AIMS scope, list of interested parties, context analysis linking external and internal issues to AI activities.

In the toolkit: AIMS-02 AIMS Scope Statement.

Clause 5, Leadership

Top management must demonstrate leadership and commitment, establish an AI policy, and assign roles, responsibilities, and authorities.

Key outputs required: signed AI Policy, defined AIMS roles (AIMS owner, risk lead, system owners), board-level accountability evidence.

In the toolkit: AIMS-01 AI Policy, AIMS-11 Competence Matrix (RACI).

Clause 6, Planning

Address risks and opportunities; conduct AI risk assessment; establish AI risk treatment; conduct AI system impact assessments; set AI objectives and plan changes.

Key outputs required: risk methodology, AI risk register, Statement of Applicability, AI impact assessment procedure, AI impact assessment records, documented AI objectives, change-planning records.

In the toolkit: AIMS-03 through AIMS-09 (objectives, risk methodology, risk register, risk treatment, SoA, impact assessment procedure + records).

Clause 7, Support

Provide resources; ensure competence; manage awareness; run communication; manage documented information.

Key outputs required: competence records, awareness programme, communication plan, document-control procedure, retention/disposition rules.

In the toolkit: AIMS-10 Document Control, AIMS-11 Competence Matrix, AIMS-12 Communication Plan.

Clause 8, Operation

Plan, implement, and control the processes needed to meet AIMS requirements; implement the risk treatment and impact-assessment outcomes; manage the AI system lifecycle; govern data and third parties.

Key outputs required: operational procedures for AI system lifecycle, data management, supplier management, incident response.

In the toolkit: AIMS-19 Lifecycle, AIMS-20 Data, AIMS-21 Suppliers, AIMS-22 Incidents (includes EU AI Act Article 73 tiered 2/10/15-day reporting).

Clause 9, Performance evaluation

Monitor, measure, analyse, and evaluate AIMS performance; conduct internal audit; conduct management review.

Key outputs required: monitoring plan, internal audit programme and reports, management review minutes with inputs and outputs as specified by the standard.

In the toolkit: AIMS-13 Internal Audit Programme, AIMS-14 Audit Report Template, AIMS-15 Management Review Minutes Template.

Clause 10, Improvement

Continually improve the AIMS; manage nonconformity and corrective action.

Key outputs required: CAPA procedure, nonconformity register, evidence of improvements driven by audit/review outcomes.

In the toolkit: AIMS-16 CAPA Procedure, AIMS-17 Nonconformity Register.

Annex A, 38 reference controls in 9 groups

Annex A is applied selectively through the Statement of Applicability. Groups and control counts:

  • A.2 Policies for AI, 3 controls
  • A.3 Internal organisation, 2 controls
  • A.4 Resources for AI systems, 5 controls
  • A.5 Assessing impacts of AI systems, 4 controls
  • A.6 AI system lifecycle, 9 controls (the largest group)
  • A.7 Data for AI systems, 5 controls
  • A.8 Information for interested parties, 4 controls
  • A.9 Use of AI systems, 3 controls
  • A.10 Third-party and customer relationships, 3 controls

Each control is described in detail on the Annex A controls page.

What's not required by ISO 42001

  • A specific number of documents, different implementations use 18 to 25+ documents; the toolkit's Starter uses 23 core documents as the durable set.
  • A specific risk-methodology flavour, qualitative, quantitative, or hybrid are all acceptable if documented.
  • Specific tooling, the standard is technology-neutral. Spreadsheets, GRC platforms, or custom systems can all satisfy the requirements.
  • Specific certification, you can implement ISO 42001 without formal certification. Many organisations pursue certification for procurement (e.g., Microsoft SSPA), regulatory readiness, or signaling reasons.

How the toolkit maps to requirements

Every one of the 23 AIMS documents in the Starter tier addresses at least one clause requirement or Annex A control. Clause 6.1.3 is covered by three of them working together: the Risk Treatment Plan (AIMS-06) assigns an action to each risk, the Risk Treatment Action Catalogue (AIMS-06a) describes what each action is and how its completion is verified, and the Statement of Applicability (AIMS-07) maps those actions to Annex A controls. The Statement of Applicability (AIMS-07) explicitly lists all 38 Annex A controls with status and justification. The Professional tier's Four-Way Crosswalk shows, for every clause and control, how evidence from ISO 27001, NIST AI RMF, and the EU AI Act maps to ISO 42001, so you reuse evidence rather than duplicating.

Start your ISO 42001 implementation

The 22-document Starter pack gets you from purchase to signed AI Policy in 7 days. Professional adds Annex A deep-dives, a 64-formula Gap Analysis workbook, and industry variants. Audit-Ready prepares you for Stage 1.

Free FRIA starter

Article 27, EU AI Act. Six sections, ten fundamental rights, and the two things teams always miss.

Free. No sales call. Unsubscribe whenever.