Knowledge base
ISO/IEC 42001:2023: documentation and compliance requirements
ISO/IEC 42001:2023 documentation requirements explained clause by clause, including the evidence and records an auditor may ask to review. Presented as clear requirements rather than a checklist.
Prem Kumar Dvivedi · 12. September 2026
This guide explains, clause by clause, what ISO/IEC 42001:2023 expects an organisation to have and what an auditor may ask to see as evidence.
It covers 88 requirements across 14 key areas.
This is not designed as a simple checklist. A checklist only asks, “Do you have this?” This guide explains what is required, why it is required, and what evidence can demonstrate that you have implemented it.
The purpose is to help organisations build an effective Artificial Intelligence Management System (AIMS), rather than simply prepare documents for an audit.
________________________________________
4. Understanding Your Organisation and the AI You Use
Clauses 4.1, 4.2, 4.3 and 4.4
Understand external factors
You need to identify the external factors that can affect your use of AI, such as:
• Laws and regulations
• Customer expectations
• Technology changes
• Public concerns and expectations
Evidence: A documented list of these factors, with evidence that it is reviewed periodically.
Understand internal factors
You also need to identify internal factors that affect your AI activities, such as:
• Employee skills
• Data
• Technology and computing resources
• Budget
• Organisational structure
Evidence: A documented list of relevant internal issues.
Define your role for each AI system
For every AI system, you should clearly identify whether your organisation:
• Develops the AI
• Provides or sells it
• Deploys it
• Operates it
• Uses an AI system developed by someone else
Evidence: A documented role or responsibility for each AI system.
This is important because your responsibilities will depend on the role you play.
Identify interested parties
You need to identify everyone who may have an interest in or be affected by your AI systems.
This could include:
• Customers
• Employees
• AI users
• People affected by AI decisions
• Regulators
• Suppliers
• Data providers
• Technology providers
Evidence: A documented list of interested parties and their relevant requirements.
Remember to consider people who may be affected by an AI decision even if they are not your customers.
Identify applicable laws and regulations
You must know which laws and regulations apply to your AI activities in the countries where you operate.
These may include:
• AI regulations
• Data protection laws
• Industry-specific regulations
• Product safety requirements
Evidence: A legal and regulatory register that is regularly updated.
Define the scope of your AI Management System
You must clearly state which AI systems, activities, locations and business units are covered by your AIMS.
Evidence: A documented scope statement and an inventory of AI systems.
Your inventory should include:
• AI developed internally
• AI included in purchased software
• AI tools used by employees
• AI services provided by external suppliers
Understand your processes
You need to understand the main processes related to your AI Management System and how they work together.
Evidence: A process map or documented list of processes and their responsible owners.
________________________________________
5. Leadership
Clauses 5.1, 5.2 and 5.3
Management involvement
Top management must actively participate in AI-related decisions.
Evidence may include:
• Management review records
• Decisions made by management
• Resources provided
• Budgets
• Assigned responsibilities
An auditor may ask management to explain what AI-related decisions they have made recently.
Responsible AI decisions
Your organisation should be able to demonstrate that it has stopped, rejected or changed an AI activity when there was a valid responsibility, ethical or risk-related concern.
Evidence: A real example showing that responsible AI principles influenced a decision.
AI policy
You must have a documented AI policy.
The policy should:
• Be approved
• Be dated
• Support responsible AI use
• Commit to meeting applicable requirements
• Support continual improvement
Evidence: Approved and dated AI policy.
Communicating the policy
Employees and relevant people must know about the AI policy and their responsibilities.
Evidence: Internal communication, training or awareness records.
Responsibilities
It must be clear who is responsible for each AI system and each important AI activity.
Evidence:
• Organisation chart
• Responsibility matrix
• Named owner for each AI system
Authority and approval
You must define:
• Who can approve an AI system for deployment
• Who reviews AI outputs
• Who can require human intervention
• Who can stop or withdraw an AI system
Evidence: Clearly documented roles and authority.
________________________________________
6. Planning – AI Risks and Impacts
Clauses 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.2 and 6.3
Identify risks and opportunities
You must identify what could go wrong with your AI systems as well as opportunities for improvement.
Evidence: Risk and opportunity register.
Define an AI risk assessment method
You need a documented method for assessing AI risks.
It should explain:
• How risks are identified
• How likelihood is measured
• How impact is measured
• What makes a risk acceptable
• How risks are prioritised
Include AI-specific risks
Your risk assessment should consider issues such as:
• Data quality
• Bias
• Model behaviour
• Transparency
• Security
• Reliability
• Robustness
• Excessive dependence on AI
Assess actual AI systems
The identified risks must actually be assessed for the AI systems within your scope.
Evidence: Risk register showing:
• Risk
• Likelihood
• Impact
• Risk level
• Responsible person
Treat identified risks
For significant risks, you must decide what action will be taken and which controls will be used.
Evidence: Risk treatment plan showing:
• Treatment approach
• Applicable controls
• Responsible person
• Target date
Approve residual risk
Risk owners should review and formally accept any remaining risk after controls have been applied.
Evidence: Documented approval or acceptance by the relevant risk owner.
Statement of Applicability
You must prepare a Statement of Applicability (SoA) covering the applicable Annex A controls.
It should explain:
• Which controls apply
• Which controls do not apply
• Why a control is included or excluded
• Whether the control has been implemented
Assess the impact of AI on people
This is one of the most important parts of ISO/IEC 42001.
You must separately consider how your AI system could affect:
• Individuals
• Groups
• Employees
• Customers
• Communities
• Society
• The environment
Areas may include:
• Fairness
• Discrimination
• Safety
• Health
• Privacy
• Human dignity
• Human autonomy
• Access to services
• Employment
• Environmental impact
Evidence: AI system impact assessments.
The assessment should include people who may be affected even if they are not customers.
Review impacts when things change
Impact assessments must be reviewed when there is a significant change to:
• The AI system
• Data
• Model
• Intended use
• Supplier
• Deployment environment
Evidence: Review triggers and updated assessments.
Set measurable AI objectives
You must establish AI-related objectives that can be measured.
Evidence: Objectives with clear targets and measurements.
For every objective, define:
• What needs to be done
• Who will do it
• When it must be completed
• What resources are needed
• How success will be measured
Plan changes
Changes such as adding a new AI use case, retraining a model, changing a data source or entering a new country should be planned before implementation.
Evidence: Change records showing that the impact was considered before the change.
________________________________________
7. Support
Clauses 7.1, 7.2, 7.3, 7.4 and 7.5
Provide resources
You must provide the resources needed to operate and control your AI systems.
This may include:
• People
• Data
• Technology
• Computing resources
• Software
• Budget
Evidence: Resource allocation or provision records.
Competence
You must identify the skills required for AI-related roles and demonstrate that people have those skills.
This can include knowledge of:
• AI and data science
• Engineering
• Business or industry requirements
• Risk management
• Legal requirements
• AI governance
• Human oversight
Evidence: Competence criteria, qualifications, experience and training records.
People responsible for impact assessments and human oversight should have suitable competence for those activities.
Awareness
People who use or are affected by AI should understand:
• The AI policy
• Their responsibilities
• The importance of following the requirements
• What may happen if requirements are not followed
Evidence: Awareness and training records.
Communication
You must decide:
• What AI information needs to be communicated
• Who needs to receive it
• When it should be communicated
• How it should be communicated
This includes internal and external communication.
Evidence: AI communication plan.
Documented information
You must maintain the documents and records required by the standard.
These may include:
• Risk assessments
• Impact assessments
• Risk treatment plans
• Statement of Applicability
• AI objectives
• Monitoring records
• Audit records
Documents must be reviewed and approved before use.
Record retention
You should keep important AI, data, model and decision records for an appropriate period so that an AI-related decision can be investigated later.
Evidence: Record retention schedule.
________________________________________
8. Operating the AI Management System
Clauses 8.1, 8.2, 8.3 and 8.4
You must establish and operate the processes needed to meet the requirements of ISO/IEC 42001.
Evidence: Documented processes and records showing that they are being followed.
Control external AI services
You need to manage external:
• AI models
• Data
• APIs
• AI platforms
• AI services
• Technology providers
Evidence:
• Contracts
• Supplier requirements
• Supplier assessments
• Performance monitoring
• Reviews of supplier changes
Review AI risks
AI risks should be reviewed:
• At planned intervals
• When significant changes occur
• When incidents happen
• When new information becomes available
Evidence: Dated risk assessments and review records.
Implement risk treatments
The actions identified in the risk treatment plan must actually be implemented.
Evidence: Implementation records and status updates.
Implement impact assessments
AI impact assessments must be carried out in practice.
The results should influence actual decisions, such as:
• System design
• Controls
• Deployment
• Use of the AI system
Evidence: Completed assessments and records showing actions taken based on their findings.
________________________________________
9. Monitoring and Reviewing Performance
Clauses 9.1, 9.2 and 9.3
Decide what to measure
You must decide:
• What will be measured
• How it will be measured
• How often it will be measured
• Who will evaluate the results
Measurements may include:
• Accuracy
• Model drift
• Fairness
• Errors
• Overrides
• Incidents
• Complaints
• Management system performance
Analyse the results
Simply collecting data is not enough.
You must analyse the results and take action where necessary.
Evidence: Analysis, evaluation and action records.
Internal audit
You must conduct internal audits of the AI Management System and applicable Annex A controls.
Evidence:
• Audit programme
• Audit plans
• Audit reports
• Findings
• Corrective actions
Auditors should be competent and independent of the activities they audit.
Management review
Top management must review the AI Management System at planned intervals.
The review should consider:
• Previous actions
• Changes
• Performance
• Incidents
• Complaints
• Monitoring results
• Audit results
• Risk assessments
• Impact assessments
• Regulatory changes
• Resources
• Improvement opportunities
Evidence: Management review records.
The review should result in actual decisions and actions, not just meeting minutes.
________________________________________
10. Corrective Action and Continual Improvement
Clauses 10.1 and 10.2
When something goes wrong, you must:
1. Address the problem
2. Find out why it happened
3. Correct the problem
4. Prevent it from happening again
AI-related examples may include:
• Harmful AI output
• Biased results
• Incorrect AI-generated information being relied upon
• Model performance deterioration
• Unauthorised AI use
Check for similar problems
You should also check whether the same issue exists in other AI systems or use cases.
Evidence: Records showing that the issue was reviewed more broadly.
Check whether corrective action worked
After corrective action, you must check whether the solution was effective.
You may also need to update:
• Risk assessments
• Impact assessments
• Controls
• Procedures
Demonstrate improvement
You should be able to show that your AI Management System is improving over time.
Evidence may include trends in:
• Incidents
• Complaints
• AI performance
• Audit findings
• Corrective actions
________________________________________
Annex A.2 and A.3 – Policies and Responsibilities
Clauses A.2.2, A.2.3, A.2.4, A.3.2 and A.3.3
You must have an approved AI policy that is reviewed regularly.
Your AI policy should also be consistent with other organisational policies, such as:
• Information security
• Privacy
• Quality
• Ethics
Evidence: Approved policies and review records.
Responsibilities should be clearly defined throughout the AI lifecycle, including:
• Design
• Development
• Deployment
• Operation
• Maintenance
• Retirement
Employees should also have a safe way to report concerns about AI without fear of punishment.
Evidence: Reporting process and records showing how concerns are handled.
________________________________________
Annex A.4 – Resources Used by AI Systems
Clauses A.4.2 to A.4.6
For each AI system, you should know what resources it depends on.
This includes:
Data
Where does the data come from?
Evidence: Data source and provenance records.
Tools
Which software, libraries and frameworks are used?
Evidence: Tool and technology inventory.
Computing and infrastructure
What servers, cloud platforms or other infrastructure does the system use?
Evidence: Infrastructure records.
People
What people and skills are required to operate the system?
Evidence: Resource and competence records.
________________________________________
Annex A.5 – Assessing the Impact of AI on People
Clauses A.5.2 to A.5.5
You must have a process for assessing how AI affects people.
The assessment should consider:
• Individuals
• Groups
• Wider society
• Environmental effects
Evidence: Documented and completed AI impact assessments.
The assessment should consider real groups and people who could be affected rather than using only general categories.
Environmental considerations may include the resources and energy required to train and operate AI models.
________________________________________
Annex A.6 – AI System Lifecycle
Clauses A.6.2.2 to A.6.2.8
Define objectives before development
Before building an AI system, define what it is supposed to achieve.
Objectives should include appropriate performance and fairness requirements.
Record design decisions
Document important design decisions and explain why a particular model, method or approach was selected.
Test the system
The AI system should be verified and validated against defined requirements.
Evidence: Testing and validation records.
Control deployment
Before an AI system goes live, it should meet defined acceptance criteria.
Evidence: Deployment approval and acceptance records.
Monitor after deployment
Once the system is live, monitor it for:
• Performance changes
• Model drift
• Errors
• Degradation
• Unexpected behaviour
Maintain logs
You should keep enough information to understand how a particular AI output or decision was produced.
Maintain technical documentation
Each AI system should have current technical documentation with appropriate revision history.
________________________________________
Annex A.7 – Data Used by AI
Clauses A.7.2 to A.7.6
You need a process for managing data used by AI systems.
Know where data comes from
You should know:
• The source of each dataset
• Whether you are legally allowed to use it
• What the permitted use is
Evidence: Data provenance and licence records.
Check data quality
Define appropriate data quality criteria and check the data against them.
Document data preparation
Record activities such as:
• Data cleaning
• Labelling
• Data augmentation
• Data splitting
• Other preparation activities
Check representativeness
You should assess whether your data properly represents the people and situations that the AI system will affect.
This should include consideration of potential bias.
________________________________________
Annex A.8 – Providing Information to People
Clauses A.8.2 to A.8.6
You should document what each AI system does, including:
• Purpose
• Capabilities
• Limitations
• Assumptions
• Situations where it may not work properly
Tell users when AI is being used
Where users may not otherwise know that AI is being used, appropriate disclosure should be provided.
Allow people to raise concerns
People should have a way to:
• Raise concerns
• Request a review
• Challenge an AI-assisted outcome
Evidence: A documented process and records of how concerns are handled.
Inform affected people
People affected by AI-assisted decisions should receive appropriate information in language they can understand.
AI incidents
You should have arrangements for communicating with external parties when an AI incident requires notification.
________________________________________
Annex A.9 and A.10 – Responsible AI Use and External Parties
Clauses A.9.2 to A.9.5 and A.10.2 to A.10.4
Define acceptable AI use
You should clearly define:
• What AI may be used for
• What AI must not be used for
Evidence: Responsible AI use policy.
Human oversight
Every relevant AI system should have clearly defined human oversight.
This should specify:
• Who reviews the output
• When review is required
• What decisions require human intervention
• Who can override the AI
Evidence: Oversight procedures and actual records of human intervention or overrides.
Monitor actual use
You should monitor whether AI is being used as intended.
Control employee use of external AI tools
Employees may use public AI tools or chatbots that are not included in the organisation's AI inventory.
Organisations should have rules for such use and appropriate controls.
Define supplier responsibilities
You must clearly establish which responsibilities belong to your organisation and which belong to:
• AI suppliers
• Technology providers
• Partners
• Service providers
Assess AI suppliers
Supplier assessment should consider areas such as:
• AI governance
• Data practices
• Model origin
• Security
• Incident management
• Compliance
Evidence: Supplier due diligence and contractual requirements.
When providing AI to customers
If you provide an AI system or service to customers, you should clearly communicate what customers need to do to use it responsibly and safely.
________________________________________
How to Use This Guide
ISO/IEC 42001:2023 does not simply require you to create a large number of manuals and templates.
The main requirement is that your organisation has made the necessary decisions, implemented appropriate controls and can demonstrate that those decisions and controls are actually working.
More documents do not automatically mean better compliance.
A procedure that exists on paper but is never followed can create a bigger problem during an audit because the auditor may find a gap between the documented process and actual practice.
The real test is simple:
Can the people responsible for the work recognise their actual activities, responsibilities and decisions in your AI Management System?
If the answer is yes, your documentation is supporting the system rather than simply creating paperwork.
The goal of ISO/IEC 42001:2023 is therefore not to create documents for the sake of documentation. It is to establish a practical, controlled and continually improving approach to responsible AI management.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 42001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13. September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13. September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13. September 2026
