Knowledge base

ISO/IEC 42001:2023: documentation and compliance requirements

ISO/IEC 42001:2023 documentation requirements explained clause by clause, including the evidence and records an auditor may ask to review. Presented as clear requirements rather than a checklist.

Prem Kumar Dvivedi · 12 tháng 9, 2026

This guide explains, clause by clause, what ISO/IEC 42001:2023 expects an organisation to have and what an auditor may ask to see as evidence.

It covers 88 requirements across 14 key areas.

This is not designed as a simple checklist. A checklist only asks, “Do you have this?” This guide explains what is required, why it is required, and what evidence can demonstrate that you have implemented it.

The purpose is to help organisations build an effective Artificial Intelligence Management System (AIMS), rather than simply prepare documents for an audit.

________________________________________

4. Understanding Your Organisation and the AI You Use

Clauses 4.1, 4.2, 4.3 and 4.4


Understand external factors

You need to identify the external factors that can affect your use of AI, such as:

• Laws and regulations

• Customer expectations

• Technology changes

• Public concerns and expectations

Evidence: A documented list of these factors, with evidence that it is reviewed periodically.


Understand internal factors

You also need to identify internal factors that affect your AI activities, such as:

• Employee skills

• Data

• Technology and computing resources

• Budget

• Organisational structure

Evidence: A documented list of relevant internal issues.


Define your role for each AI system

For every AI system, you should clearly identify whether your organisation:

• Develops the AI

• Provides or sells it

• Deploys it

• Operates it

• Uses an AI system developed by someone else

Evidence: A documented role or responsibility for each AI system.

This is important because your responsibilities will depend on the role you play.


Identify interested parties

You need to identify everyone who may have an interest in or be affected by your AI systems.

This could include:

• Customers

• Employees

• AI users

• People affected by AI decisions

• Regulators

• Suppliers

• Data providers

• Technology providers

Evidence: A documented list of interested parties and their relevant requirements.

Remember to consider people who may be affected by an AI decision even if they are not your customers.


Identify applicable laws and regulations

You must know which laws and regulations apply to your AI activities in the countries where you operate.

These may include:

• AI regulations

• Data protection laws

• Industry-specific regulations

• Product safety requirements

Evidence: A legal and regulatory register that is regularly updated.


Define the scope of your AI Management System

You must clearly state which AI systems, activities, locations and business units are covered by your AIMS.

Evidence: A documented scope statement and an inventory of AI systems.

Your inventory should include:

• AI developed internally

• AI included in purchased software

• AI tools used by employees

• AI services provided by external suppliers

Understand your processes

You need to understand the main processes related to your AI Management System and how they work together.

Evidence: A process map or documented list of processes and their responsible owners.

________________________________________

5. Leadership

Clauses 5.1, 5.2 and 5.3


Management involvement

Top management must actively participate in AI-related decisions.

Evidence may include:

• Management review records

• Decisions made by management

• Resources provided

• Budgets

• Assigned responsibilities

An auditor may ask management to explain what AI-related decisions they have made recently.


Responsible AI decisions

Your organisation should be able to demonstrate that it has stopped, rejected or changed an AI activity when there was a valid responsibility, ethical or risk-related concern.

Evidence: A real example showing that responsible AI principles influenced a decision.


AI policy

You must have a documented AI policy.

The policy should:

• Be approved

• Be dated

• Support responsible AI use

• Commit to meeting applicable requirements

• Support continual improvement

Evidence: Approved and dated AI policy.

Communicating the policy

Employees and relevant people must know about the AI policy and their responsibilities.

Evidence: Internal communication, training or awareness records.


Responsibilities

It must be clear who is responsible for each AI system and each important AI activity.

Evidence:

• Organisation chart

• Responsibility matrix

• Named owner for each AI system

Authority and approval

You must define:

• Who can approve an AI system for deployment

• Who reviews AI outputs

• Who can require human intervention

• Who can stop or withdraw an AI system

Evidence: Clearly documented roles and authority.

________________________________________


6. Planning – AI Risks and Impacts

Clauses 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.2 and 6.3


Identify risks and opportunities

You must identify what could go wrong with your AI systems as well as opportunities for improvement.

Evidence: Risk and opportunity register.

Define an AI risk assessment method

You need a documented method for assessing AI risks.

It should explain:

• How risks are identified

• How likelihood is measured

• How impact is measured

• What makes a risk acceptable

• How risks are prioritised

Include AI-specific risks

Your risk assessment should consider issues such as:

• Data quality

• Bias

• Model behaviour

• Transparency

• Security

• Reliability

• Robustness

• Excessive dependence on AI

Assess actual AI systems

The identified risks must actually be assessed for the AI systems within your scope.

Evidence: Risk register showing:

• Risk

• Likelihood

• Impact

• Risk level

• Responsible person


Treat identified risks

For significant risks, you must decide what action will be taken and which controls will be used.

Evidence: Risk treatment plan showing:

• Treatment approach

• Applicable controls

• Responsible person

• Target date


Approve residual risk

Risk owners should review and formally accept any remaining risk after controls have been applied.

Evidence: Documented approval or acceptance by the relevant risk owner.


Statement of Applicability

You must prepare a Statement of Applicability (SoA) covering the applicable Annex A controls.

It should explain:

• Which controls apply

• Which controls do not apply

• Why a control is included or excluded

• Whether the control has been implemented

Assess the impact of AI on people

This is one of the most important parts of ISO/IEC 42001.

You must separately consider how your AI system could affect:

• Individuals

• Groups

• Employees

• Customers

• Communities

• Society

• The environment

Areas may include:

• Fairness

• Discrimination

• Safety

• Health

• Privacy

• Human dignity

• Human autonomy

• Access to services

• Employment

• Environmental impact

Evidence: AI system impact assessments.

The assessment should include people who may be affected even if they are not customers.

Review impacts when things change

Impact assessments must be reviewed when there is a significant change to:

• The AI system

• Data

• Model

• Intended use

• Supplier

• Deployment environment

Evidence: Review triggers and updated assessments.

Set measurable AI objectives

You must establish AI-related objectives that can be measured.

Evidence: Objectives with clear targets and measurements.

For every objective, define:

• What needs to be done

• Who will do it

• When it must be completed

• What resources are needed

• How success will be measured

Plan changes

Changes such as adding a new AI use case, retraining a model, changing a data source or entering a new country should be planned before implementation.

Evidence: Change records showing that the impact was considered before the change.

________________________________________

7. Support

Clauses 7.1, 7.2, 7.3, 7.4 and 7.5


Provide resources

You must provide the resources needed to operate and control your AI systems.

This may include:

• People

• Data

• Technology

• Computing resources

• Software

• Budget

Evidence: Resource allocation or provision records.

Competence

You must identify the skills required for AI-related roles and demonstrate that people have those skills.

This can include knowledge of:

• AI and data science

• Engineering

• Business or industry requirements

• Risk management

• Legal requirements

• AI governance

• Human oversight

Evidence: Competence criteria, qualifications, experience and training records.

People responsible for impact assessments and human oversight should have suitable competence for those activities.


Awareness

People who use or are affected by AI should understand:

• The AI policy

• Their responsibilities

• The importance of following the requirements

• What may happen if requirements are not followed


Evidence: Awareness and training records.

Communication

You must decide:

• What AI information needs to be communicated

• Who needs to receive it

• When it should be communicated

• How it should be communicated

This includes internal and external communication.


Evidence: AI communication plan.

Documented information

You must maintain the documents and records required by the standard.

These may include:

• Risk assessments

• Impact assessments

• Risk treatment plans

• Statement of Applicability

• AI objectives

• Monitoring records

• Audit records

Documents must be reviewed and approved before use.

Record retention

You should keep important AI, data, model and decision records for an appropriate period so that an AI-related decision can be investigated later.

Evidence: Record retention schedule.

________________________________________

8. Operating the AI Management System

Clauses 8.1, 8.2, 8.3 and 8.4


You must establish and operate the processes needed to meet the requirements of ISO/IEC 42001.

Evidence: Documented processes and records showing that they are being followed.

Control external AI services

You need to manage external:

• AI models

• Data

• APIs

• AI platforms

• AI services

• Technology providers


Evidence:

• Contracts

• Supplier requirements

• Supplier assessments

• Performance monitoring

• Reviews of supplier changes


Review AI risks

AI risks should be reviewed:

• At planned intervals

• When significant changes occur

• When incidents happen

• When new information becomes available


Evidence: Dated risk assessments and review records.

Implement risk treatments

The actions identified in the risk treatment plan must actually be implemented.

Evidence: Implementation records and status updates.

Implement impact assessments

AI impact assessments must be carried out in practice.


The results should influence actual decisions, such as:

• System design

• Controls

• Deployment

• Use of the AI system


Evidence: Completed assessments and records showing actions taken based on their findings.

________________________________________

9. Monitoring and Reviewing Performance

Clauses 9.1, 9.2 and 9.3


Decide what to measure

You must decide:

• What will be measured

• How it will be measured

• How often it will be measured

• Who will evaluate the results

Measurements may include:

• Accuracy

• Model drift

• Fairness

• Errors

• Overrides

• Incidents

• Complaints

• Management system performance


Analyse the results

Simply collecting data is not enough.

You must analyse the results and take action where necessary.

Evidence: Analysis, evaluation and action records.

Internal audit

You must conduct internal audits of the AI Management System and applicable Annex A controls.

Evidence:

• Audit programme

• Audit plans

• Audit reports

• Findings

• Corrective actions

Auditors should be competent and independent of the activities they audit.

Management review

Top management must review the AI Management System at planned intervals.

The review should consider:

• Previous actions

• Changes

• Performance

• Incidents

• Complaints

• Monitoring results

• Audit results

• Risk assessments

• Impact assessments

• Regulatory changes

• Resources

• Improvement opportunities

Evidence: Management review records.

The review should result in actual decisions and actions, not just meeting minutes.

________________________________________

10. Corrective Action and Continual Improvement

Clauses 10.1 and 10.2


When something goes wrong, you must:

1. Address the problem

2. Find out why it happened

3. Correct the problem

4. Prevent it from happening again

AI-related examples may include:

• Harmful AI output

• Biased results

• Incorrect AI-generated information being relied upon

• Model performance deterioration

• Unauthorised AI use


Check for similar problems

You should also check whether the same issue exists in other AI systems or use cases.

Evidence: Records showing that the issue was reviewed more broadly.

Check whether corrective action worked

After corrective action, you must check whether the solution was effective.


You may also need to update:

• Risk assessments

• Impact assessments

• Controls

• Procedures

Demonstrate improvement

You should be able to show that your AI Management System is improving over time.

Evidence may include trends in:

• Incidents

• Complaints

• AI performance

• Audit findings

• Corrective actions

________________________________________

Annex A.2 and A.3 – Policies and Responsibilities

Clauses A.2.2, A.2.3, A.2.4, A.3.2 and A.3.3


You must have an approved AI policy that is reviewed regularly.

Your AI policy should also be consistent with other organisational policies, such as:

• Information security

• Privacy

• Quality

• Ethics

Evidence: Approved policies and review records.

Responsibilities should be clearly defined throughout the AI lifecycle, including:

• Design

• Development

• Deployment

• Operation

• Maintenance

• Retirement

Employees should also have a safe way to report concerns about AI without fear of punishment.

Evidence: Reporting process and records showing how concerns are handled.

________________________________________

Annex A.4 – Resources Used by AI Systems

Clauses A.4.2 to A.4.6


For each AI system, you should know what resources it depends on.

This includes:

Data

Where does the data come from?

Evidence: Data source and provenance records.

Tools

Which software, libraries and frameworks are used?

Evidence: Tool and technology inventory.

Computing and infrastructure

What servers, cloud platforms or other infrastructure does the system use?

Evidence: Infrastructure records.

People

What people and skills are required to operate the system?

Evidence: Resource and competence records.

________________________________________

Annex A.5 – Assessing the Impact of AI on People

Clauses A.5.2 to A.5.5


You must have a process for assessing how AI affects people.

The assessment should consider:

• Individuals

• Groups

• Wider society

• Environmental effects

Evidence: Documented and completed AI impact assessments.

The assessment should consider real groups and people who could be affected rather than using only general categories.

Environmental considerations may include the resources and energy required to train and operate AI models.

________________________________________

Annex A.6 – AI System Lifecycle

Clauses A.6.2.2 to A.6.2.8


Define objectives before development

Before building an AI system, define what it is supposed to achieve.

Objectives should include appropriate performance and fairness requirements.

Record design decisions

Document important design decisions and explain why a particular model, method or approach was selected.

Test the system

The AI system should be verified and validated against defined requirements.

Evidence: Testing and validation records.

Control deployment

Before an AI system goes live, it should meet defined acceptance criteria.

Evidence: Deployment approval and acceptance records.

Monitor after deployment

Once the system is live, monitor it for:

• Performance changes

• Model drift

• Errors

• Degradation

• Unexpected behaviour

Maintain logs

You should keep enough information to understand how a particular AI output or decision was produced.

Maintain technical documentation

Each AI system should have current technical documentation with appropriate revision history.

________________________________________

Annex A.7 – Data Used by AI

Clauses A.7.2 to A.7.6


You need a process for managing data used by AI systems.

Know where data comes from

You should know:

• The source of each dataset

• Whether you are legally allowed to use it

• What the permitted use is

Evidence: Data provenance and licence records.

Check data quality

Define appropriate data quality criteria and check the data against them.

Document data preparation

Record activities such as:

• Data cleaning

• Labelling

• Data augmentation

• Data splitting

• Other preparation activities

Check representativeness

You should assess whether your data properly represents the people and situations that the AI system will affect.

This should include consideration of potential bias.

________________________________________

Annex A.8 – Providing Information to People

Clauses A.8.2 to A.8.6


You should document what each AI system does, including:

• Purpose

• Capabilities

• Limitations

• Assumptions

• Situations where it may not work properly

Tell users when AI is being used

Where users may not otherwise know that AI is being used, appropriate disclosure should be provided.

Allow people to raise concerns

People should have a way to:

• Raise concerns

• Request a review

• Challenge an AI-assisted outcome

Evidence: A documented process and records of how concerns are handled.

Inform affected people

People affected by AI-assisted decisions should receive appropriate information in language they can understand.

AI incidents

You should have arrangements for communicating with external parties when an AI incident requires notification.

________________________________________

Annex A.9 and A.10 – Responsible AI Use and External Parties

Clauses A.9.2 to A.9.5 and A.10.2 to A.10.4


Define acceptable AI use

You should clearly define:

• What AI may be used for

• What AI must not be used for

Evidence: Responsible AI use policy.

Human oversight

Every relevant AI system should have clearly defined human oversight.

This should specify:

• Who reviews the output

• When review is required

• What decisions require human intervention

• Who can override the AI

Evidence: Oversight procedures and actual records of human intervention or overrides.

Monitor actual use

You should monitor whether AI is being used as intended.

Control employee use of external AI tools

Employees may use public AI tools or chatbots that are not included in the organisation's AI inventory.

Organisations should have rules for such use and appropriate controls.

Define supplier responsibilities

You must clearly establish which responsibilities belong to your organisation and which belong to:

• AI suppliers

• Technology providers

• Partners

• Service providers

Assess AI suppliers

Supplier assessment should consider areas such as:

• AI governance

• Data practices

• Model origin

• Security

• Incident management

• Compliance

Evidence: Supplier due diligence and contractual requirements.

When providing AI to customers

If you provide an AI system or service to customers, you should clearly communicate what customers need to do to use it responsibly and safely.

________________________________________

How to Use This Guide

ISO/IEC 42001:2023 does not simply require you to create a large number of manuals and templates.

The main requirement is that your organisation has made the necessary decisions, implemented appropriate controls and can demonstrate that those decisions and controls are actually working.

More documents do not automatically mean better compliance.

A procedure that exists on paper but is never followed can create a bigger problem during an audit because the auditor may find a gap between the documented process and actual practice.


The real test is simple:


Can the people responsible for the work recognise their actual activities, responsibilities and decisions in your AI Management System?

If the answer is yes, your documentation is supporting the system rather than simply creating paperwork.

The goal of ISO/IEC 42001:2023 is therefore not to create documents for the sake of documentation. It is to establish a practical, controlled and continually improving approach to responsible AI management.


What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 42001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles