Table of Contents

ISO 42001 Annex A Controls List Complete Guide (2026)

ISO/IEC 42001:2023 Annex A contains 38 AI-specific controls organized into 9 control objectives, from A.2 to A.10. These controls help organizations manage AI policies, responsibilities, resources, impact assessments, system development, data governance, transparency, responsible use, and third-party relationships.

The controls support organizations that develop, provide, deploy, or use artificial intelligence systems. They form part of an Artificial Intelligence Management System, also known as an AIMS.

Organizations do not need to implement every Annex A control in the same way. They identify their AI risks, select applicable controls, justify exclusions, and document their decisions in a Statement of Applicability.

Organizations that need a broader explanation of the standard can review the ISO/IEC 42001 Artificial Intelligence Management System guide.

This guide provides:

  • A complete list of all 38 Annex A controls.
  • A short explanation of each control.
  • Examples of implementation evidence.
  • Statement of Applicability guidance.
  • A practical implementation sequence.
  • A comparison with Annex B and ISO 27001.

The explanations below are practical summaries. Organizations should consult the official ISO/IEC 42001:2023 standard when preparing for certification or conducting a formal audit.

How Many Controls Are Included in ISO 42001 Annex A?

ISO 42001 Annex A includes 38 controls divided into 9 control objectives.

Each objective covers a defined area of AI governance. A.2 focuses on organizational policies, while A.10 focuses on suppliers, customers, and other external relationships.

ObjectiveControl areaNumber of controls
A.2Policies related to AI3
A.3Internal organization2
A.4Resources for AI systems5
A.5Assessing impacts of AI systems4
A.6AI system life cycle9
A.7Data for AI systems5
A.8Information for interested parties4
A.9Use of AI systems3
A.10Third-party and customer relationships3
Total9 control objectives38 controls

A.6 contains 9 controls, making it the largest control objective. It covers AI requirements, design, development, testing, deployment, operation, monitoring, documentation, and event logging.

What Are the 3 A.2 Policies Related to AI Controls?

A.2 establishes the policy foundation for the Artificial Intelligence Management System.

The organization should define how it develops, provides, acquires, and uses AI systems. The AI policy should also align with existing policies related to information security, privacy, risk management, procurement, ethics, and human resources.

ControlTitlePractical requirement
A.2.2AI policyEstablish and maintain an approved policy that defines the organization’s approach to responsible AI development and use.
A.2.3Alignment with other organizational policiesAlign the AI policy with related organizational policies, including privacy, security, procurement, risk, and HR policies.
A.2.4Review of the AI policyReview the AI policy at planned intervals and after significant technical, organizational, regulatory, or operational changes.

The AI policy should guide other Annex A controls.

For example, if the policy commits the organization to transparency and human oversight, its development, deployment, and responsible-use procedures should contain suitable transparency and oversight measures.

Evidence can include an approved AI policy, management authorization, policy review records, communication records, and version histories.

What Are the 2 A.3 Internal Organization Controls?

A.3 defines who is accountable for AI activities and how AI-related concerns can be reported.

AI governance normally involves several teams, including engineering, legal, compliance, privacy, information security, procurement, human resources, and business operations.

ControlTitlePractical requirement
A.3.2AI roles and responsibilitiesAssign authority, accountability, and operational responsibilities for AI activities throughout the AI system life cycle.
A.3.3Reporting of concernsEstablish a process through which employees, contractors, users, or external parties can report AI-related concerns.

Responsibilities can include:

  • AI risk assessment.
  • AI system impact assessment.
  • Data approval.
  • Model testing.
  • Deployment approval.
  • Human oversight.
  • Supplier management.
  • Incident response.
  • Performance monitoring.

The reporting process should explain how concerns are submitted, investigated, escalated, resolved, and documented.

Evidence can include responsibility matrices, job descriptions, committee terms of reference, reporting procedures, investigation records, and escalation criteria.

What Are the 5 A.4 Resources for AI Systems Controls?

A.4 requires organizations to identify and document the resources needed to develop, operate, monitor, and maintain AI systems.

AI resources can include datasets, models, algorithms, software libraries, cloud platforms, development tools, computing infrastructure, domain experts, and system operators.

ControlTitlePractical requirement
A.4.2Resource documentationIdentify and document the resources required during relevant stages of the AI system life cycle.
A.4.3Data resourcesDocument the data used for AI development, testing, validation, deployment, operation, and improvement.
A.4.4Tooling resourcesDocument the models, algorithms, frameworks, libraries, tools, and platforms used by the AI system.
A.4.5System and computing resourcesDocument computing, storage, network, cloud, hosting, and physical infrastructure required by the system.
A.4.6Human resourcesIdentify the people, roles, skills, and competencies required for responsible AI activities.

A resource inventory helps organizations understand system dependencies.

For example, an AI application may depend on an external foundation model, a cloud platform, an internal customer database, a vector database, and a monitoring service. Each dependency can create different security, privacy, availability, quality, and supplier risks.

Evidence can include AI inventories, dataset registers, model registers, software dependency lists, architecture diagrams, infrastructure records, competency matrices, and training records.

Resource records should be updated when data, models, suppliers, infrastructure, software, or responsible personnel change.

What Are the 4 A.5 AI System Impact Assessment Controls?

A.5 requires organizations to assess how AI systems may affect individuals, groups, and society.

An AI system impact assessment is broader than a technical performance test. It may cover fairness, privacy, accessibility, safety, financial effects, employment effects, human rights, and human oversight.

ControlTitlePractical requirement
A.5.2AI system impact assessment processEstablish a repeatable process for identifying, analyzing, evaluating, and treating potential AI impacts.
A.5.3Documentation of AI system impact assessmentsDocument the assessment scope, affected parties, assumptions, identified impacts, treatment decisions, and review results.
A.5.4Assessing impacts on individuals or groupsEvaluate how the AI system may affect specific individuals or groups of individuals.
A.5.5Assessing societal impacts of AI systemsEvaluate broader environmental, economic, cultural, safety, democratic, and societal consequences.

The depth of the assessment should match the AI system’s purpose, complexity, level of autonomy, affected population, and potential severity of harm.

For example, an AI recruitment system may require detailed fairness, privacy, accessibility, and human-review assessments. An internal spelling tool may require a less extensive assessment because its outputs have fewer direct consequences.

Impact assessments should be reviewed after changes such as:

  • A new AI use case.
  • A major model update.
  • A new dataset.
  • A new affected population.
  • A serious AI incident.
  • A change in legal obligations.
  • A new supplier.

Evidence can include impact assessment methodologies, completed assessments, stakeholder analyses, fairness evaluations, mitigation plans, approval records, and reassessment schedules.

What Are the 9 A.6 AI System Life-Cycle Controls?

A.6 covers the responsible design, development, deployment, operation, and monitoring of AI systems.

These controls connect organizational AI principles with technical and operational processes.

ControlTitlePractical requirement
A.6.1.2Objectives for responsible development of AI systemsDefine measurable objectives for fairness, safety, privacy, transparency, robustness, security, and human oversight.
A.6.1.3Processes for responsible design and developmentEstablish documented processes for responsible AI design and development throughout the system life cycle.
A.6.2.2AI system requirements and specificationDefine functional, performance, safety, security, compliance, and responsible-AI requirements.
A.6.2.3Documentation of AI system design and developmentMaintain records of architecture, models, assumptions, components, interfaces, data dependencies, and design decisions.
A.6.2.4AI system verification and validationVerify that the system meets defined requirements and validate its suitability for the intended purpose.
A.6.2.5AI system deploymentControl production deployment through approvals, release criteria, environment checks, and rollback arrangements.
A.6.2.6AI system operation and monitoringMonitor performance, drift, failures, misuse, security threats, and changing operating conditions.
A.6.2.7AI system technical documentationMaintain suitable technical information for users, operators, customers, auditors, regulators, and other parties.
A.6.2.8AI system recording of event logsRecord events needed for traceability, monitoring, investigation, incident response, and auditing.

A.6 normally requires coordination between product managers, engineers, data scientists, quality teams, information security professionals, risk managers, and system operators.

Responsible-development objectives should be measurable where possible.

Examples include:

  • Maximum error rates.
  • Fairness thresholds.
  • Human-review requirements.
  • Safety tolerances.
  • Privacy requirements.
  • Performance targets.
  • Response-time limits.

Requirements should be documented before development or acquisition. They should include both functional and non-functional requirements.

Verification checks whether the system was built according to its specification. Validation checks whether the system remains suitable for its intended use.

Deployment controls should define release criteria, required approvals, monitoring readiness, rollback conditions, and incident contacts.

Operational monitoring may cover model drift, data drift, harmful outputs, accuracy, latency, security events, misuse, and unexpected behavior.

Evidence can include requirements specifications, architecture diagrams, model cards, test reports, validation results, deployment approvals, monitoring dashboards, technical manuals, and system logs.

What Are the 5 A.7 Data for AI Systems Controls?

A.7 governs the data used to develop, test, validate, improve, and operate AI systems.

Poor, outdated, incomplete, inaccurate, or unrepresentative data can produce unreliable or unfair AI outputs.

ControlTitlePractical requirement
A.7.2Data for development and enhancement of AI systemsEstablish processes for managing data used to develop, test, validate, or improve AI systems.
A.7.3Acquisition of dataDefine how data is selected, generated, purchased, licensed, shared, or obtained from internal and external sources.
A.7.4Quality of data for AI systemsDefine and evaluate data-quality requirements suitable for the intended AI use.
A.7.5Data provenanceMaintain traceability of data origin, ownership, collection, transformations, transfers, updates, and use.
A.7.6Data preparationDocument how data is cleaned, labelled, filtered, transformed, normalized, encoded, or augmented.

Relevant data-quality criteria can include:

  • Accuracy.
  • Completeness.
  • Consistency.
  • Timeliness.
  • Relevance.
  • Validity.
  • Representativeness.
  • Uniqueness.

The required criteria depend on the AI use case.

For example, geographic representation may be important for a healthcare model used across several regions. Current data may be especially important for fraud detection, financial analysis, cybersecurity, and market forecasting.

Data acquisition processes should address ownership, licences, consent, privacy, security, prior use, and known limitations.

Evidence can include dataset registers, source agreements, licences, consent records, quality rules, profiling reports, bias analyses, data-lineage records, preparation scripts, and transformation logs.

What Are the 4 A.8 Information for Interested Parties Controls?

A.8 addresses information provided to people and organizations that use, depend on, regulate, or may be affected by an AI system.

Interested parties can include customers, users, employees, data subjects, suppliers, regulators, partners, and members of the public.

ControlTitlePractical requirement
A.8.2System documentation and information for usersProvide understandable information about the AI system’s purpose, capabilities, limitations, inputs, outputs, and proper use.
A.8.3External reportingProvide a method for external parties to report complaints, errors, adverse impacts, misuse, or unexpected behavior.
A.8.4Communication of incidentsDefine how and when affected parties will be informed about AI-related incidents.
A.8.5Information for interested partiesDetermine which additional AI information should be shared, with whom, when, and through which channels.

Information should match the intended audience.

A technical auditor may require model documentation, test records, and architecture information. A customer may require a plain-language explanation of the system’s purpose, limitations, expected inputs, and human-review options.

External reporting processes should define reporting channels, investigation responsibilities, escalation criteria, response timeframes, and closure records.

Evidence can include user guides, limitation notices, disclosure statements, reporting forms, complaint records, incident communication plans, transparency reports, and regulatory submissions.

What Are the 3 A.9 Use of AI Systems Controls?

A.9 governs how an organization uses AI systems after development, acquisition, or deployment.

These controls establish responsible operating rules and help prevent systems from being used outside their approved purpose.

ControlTitlePractical requirement
A.9.2Processes for responsible use of AI systemsEstablish documented requirements for acceptable use, human oversight, operator training, escalation, and suspension.
A.9.3Objectives for responsible use of AI systemsDefine measurable objectives that guide the responsible operation of AI systems.
A.9.4Intended use of the AI systemEnsure that the AI system remains within its approved purpose, user group, operating conditions, and decision context.

Responsible-use procedures can cover:

  • Acceptable-use rules.
  • User access restrictions.
  • Human-review requirements.
  • Operator training.
  • Output verification.
  • Escalation procedures.
  • Conditions for suspending use.

A.9.4 helps prevent function creep.

Function creep occurs when an AI system designed for one purpose is used for another purpose without a suitable risk and impact assessment.

For example, a system designed to recommend employee training should not automatically be used for promotion or termination decisions. These uses have different risks and oversight requirements.

Evidence can include responsible-use procedures, intended-use statements, access controls, training records, use-case approvals, human-review records, and exception reports.

What Are the 3 A.10 Third-Party and Customer Relationship Controls?

A.10 addresses responsibilities shared with AI providers, cloud platforms, data suppliers, software vendors, consultants, customers, and other external parties.

Third-party dependencies can affect security, data quality, availability, transparency, monitoring, and incident response.

ControlTitlePractical requirement
A.10.2Allocation of responsibilitiesDefine how AI responsibilities are divided between the organization, suppliers, customers, partners, and other parties.
A.10.3SuppliersAssess and manage suppliers whose data, models, tools, platforms, or services affect AI development or use.
A.10.4CustomersConsider customer requirements, contractual obligations, expectations, and potential impacts in responsible AI decisions.

Responsibility allocation should be clear before an incident occurs.

Contracts and service agreements can define:

  • Data responsibilities.
  • Model-update notifications.
  • Performance requirements.
  • Security responsibilities.
  • Monitoring obligations.
  • Incident reporting.
  • Audit rights.
  • Exit support.

Supplier management should continue after contract approval.

Ongoing activities can include supplier reviews, model-change assessments, performance monitoring, assurance reporting, incident notifications, and exit planning.

Evidence can include supplier due diligence, contracts, responsibility matrices, service reviews, assurance reports, performance records, and supplier exit plans.

Are All ISO 42001 Annex A Controls Mandatory?

Organizations do not automatically need to implement all 38 controls in the same way.

ISO 42001 uses a risk-based approach. Organizations identify their AI risks, select suitable controls, and compare those controls with Annex A.

A practical control-selection process includes 6 steps:

  1. Define the AIMS scope.
  2. Identify AI systems and affected parties.
  3. Conduct AI risk and impact assessments.
  4. Select suitable controls.
  5. Justify included and excluded controls.
  6. Maintain implementation evidence.

A control should not be excluded only because it is difficult, expensive, or inconvenient.

The justification should be based on the organization’s scope, AI role, risks, legal obligations, contractual requirements, and existing controls.

Organizations may also implement controls that are not listed in Annex A when additional risk treatments are necessary.

What Is the Difference Between ISO 42001 Annex A and Annex B?

Annex A and Annex B support different activities.

Annex A provides the control framework. Annex B provides guidance for applying the controls.

FeatureAnnex AAnnex B
PurposeProvides control objectives and controls.Provides implementation guidance.
Main questionWhich controls may be required?How can the controls be implemented?
Risk treatment roleSupports control selection.Supports control design and application.
Statement of ApplicabilityControls are evaluated and recorded.Guidance supports implementation decisions.

Annex B does not require one universal implementation method. Organizations can use different technologies, processes, responsibilities, and documents when those measures effectively address their risks.

More information is available in the ISO/IEC 42001 Annex B Controls guide.

How Does ISO 42001 Annex A Compare With ISO 27001 Annex A?

ISO 42001 and ISO 27001 are both management system standards, but they address different risk areas.

ISO 27001 focuses on information security. ISO 42001 focuses on AI governance and responsible AI management.

Comparison areaISO 42001 Annex AISO 27001 Annex A
Primary focusAI governance and responsible AI.Information security management.
Number of controls38 controls.93 controls.
Structure9 control objectives.4 control themes.
Main risksAI impacts, data, transparency, oversight, and responsible use.Confidentiality, integrity, and availability.
Implementation guidanceISO 42001 Annex B.ISO/IEC 27002.

The standards can share processes such as document control, internal audits, management reviews, supplier management, corrective actions, risk management, and incident response.

However, ISO 27001 certification does not automatically satisfy ISO 42001.

Organizations still need AI-specific processes for impact assessments, responsible use, data provenance, AI system monitoring, human oversight, and interested-party information.

How Should Organizations Implement ISO 42001 Annex A Controls?

ISO 42001 does not require one universal implementation order.

A practical sequence contains 5 stages.

What Should Organizations Implement During Stage 1?

Start with A.2 and A.3.

These controls establish the AI policy, define responsibilities, align existing policies, and provide a process for reporting concerns.

What Should Organizations Implement During Stage 2?

Establish the A.5 impact assessment process.

Impact assessments help identify affected parties, potential harms, broader societal effects, and suitable risk treatments.

What Should Organizations Implement During Stage 3?

Document A.4 resources.

The organization should identify its data, models, tools, infrastructure, people, and external providers.

What Should Organizations Implement During Stage 4?

Implement A.6 and A.7.

These controls normally require the most operational effort because they cover development, testing, deployment, monitoring, data quality, data provenance, documentation, and logging.

What Should Organizations Implement During Stage 5?

Implement A.8, A.9, and A.10.

These controls address users, responsible use, suppliers, customers, external reporting, and incident communication.

Professionals responsible for establishing an AIMS can develop implementation skills through the ISO 42001 Lead Implementer course.

The complete range of learning options is available on the ISO 42001 Artificial Intelligence training page.

What Evidence Is Required for ISO 42001 Annex A Controls?

Auditors evaluate whether selected controls are implemented and operating effectively.

Policies can demonstrate management intent. Operational records demonstrate whether the controls work in practice.

Evidence areaExamples
GovernanceAI policy, approvals, committee minutes, responsibility records.
Risk managementRisk registers, impact assessments, treatment plans.
ResourcesAI inventories, dataset registers, model registers.
DevelopmentRequirements, architecture, design records, change records.
TestingTest plans, validation reports, fairness results.
DeploymentRelease approvals, deployment checklists, rollback plans.
OperationsMonitoring reports, drift alerts, incidents, maintenance records.
DataQuality reports, lineage records, preparation logs.
TransparencyUser instructions, disclosures, limitation statements.
Third partiesSupplier assessments, contracts, service reviews.
ImprovementAudit findings, corrective actions, management reviews.

Evidence should be current, traceable, approved where necessary, and connected to the relevant control.

For example, a monitoring policy can support A.6.2.6, but stronger evidence may include dashboards, alert records, drift reports, incident tickets, and completed performance reviews.

Professionals responsible for assessing implementation evidence can develop audit skills through the ISO 42001 Lead Auditor course.

How Should the Statement of Applicability Record Annex A Controls?

The Statement of Applicability explains which controls apply, why they were selected, and how they are implemented.

SoA fieldWhat should be recorded?
Control referenceAnnex A control code.
Control titleOfficial control title.
ApplicabilityApplicable, excluded, or partially applicable.
JustificationReason for inclusion or exclusion.
Related risksRisks addressed by the control.
StatusPlanned, in progress, partial, or implemented.
OwnerAccountable organizational role.
EvidenceSupporting policies, procedures, systems, and records.
Review dateNext reassessment date.

A weak justification may state that a control is not relevant.

A stronger justification explains the organization’s scope, AI role, operating model, risks, and external responsibilities.

The Statement of Applicability should be reviewed when AI systems, models, datasets, intended uses, suppliers, or legal obligations change.

What Are the Best Practices for Implementing Annex A Controls?

There are 7 practical implementation practices:

  1. Define the AIMS scope before selecting controls.
  2. Maintain an accurate inventory of AI systems.
  3. Connect each control to an identified risk or requirement.
  4. Assign an accountable owner to each control.
  5. Define measurable criteria where possible.
  6. Collect evidence during normal operations.
  7. Review controls after material changes.

Organizations should also integrate AI controls with existing security, privacy, quality, procurement, risk, and compliance processes.

For example, an existing supplier-management process can be extended to cover AI models, datasets, cloud platforms, and model-change notifications.

What Are the Common ISO 42001 Annex A Implementation Mistakes?

There are 5 common implementation mistakes.

Why Is Treating Annex A as a Checklist a Mistake?

Controls should address actual AI risks.

Implementing every control superficially can create documents without improving governance.

Why Is Generic Documentation Insufficient?

Generic policies may not describe the organization’s actual models, datasets, suppliers, users, or responsibilities.

Documentation should reflect real processes and operating conditions.

Why Is Technical Testing Alone Insufficient?

AI governance covers more than technical accuracy.

Organizations may also need to assess fairness, privacy, safety, accessibility, security, transparency, and human oversight.

Why Do Unclear Responsibilities Create Control Gaps?

AI systems involve multiple departments.

Controls can fail when engineering, compliance, security, legal, and business teams assume another team owns the activity.

Why Must Third-Party AI Services Be Assessed?

Using an external AI provider does not remove the organization’s responsibility for its own use of the service.

Organizations should assess supplier data handling, limitations, model updates, monitoring, incidents, and contractual responsibilities.

How Can Risk Professionals Support ISO 42001 Implementation?

Risk Professionals provides ISO 42001 training and implementation resources for professionals and organizations developing, operating, or auditing an Artificial Intelligence Management System.

Available learning pathways include:

  • ISO 42001 Foundation training.
  • ISO 42001 Lead Implementer training.
  • ISO 42001 Lead Auditor training.

The PECB ISO 42001 Training guide explains available certification pathways, course formats, benefits, and learning options.

Training can improve implementation and audit competence. However, organizations must still conduct their own risk assessments, select suitable controls, assign responsibilities, and maintain operational evidence.

Risk Professionals is a PECB Authorised Platinum Partner providing ISO 42001 training, documentation, implementation support, and AI governance expertise.

FAQs Organizations Ask About ISO 42001 Annex A?

How many controls are in ISO 42001 Annex A?

ISO 42001 Annex A contains 38 controls divided into 9 control objectives, from A.2 to A.10.

Are all 38 Annex A controls mandatory?

No. Organizations select applicable controls based on their AIMS scope, AI risks, impact assessments, legal obligations, and operating environment.

What is the Statement of Applicability?

The Statement of Applicability records applicable controls, exclusions, justifications, implementation status, owners, and supporting evidence.

What is the difference between Annex A and Annex B?

Annex A provides the control framework. Annex B provides implementation guidance for applying those controls.

Can ISO 27001 controls replace ISO 42001 controls?

No. ISO 27001 supports information security, but it does not replace AI-specific controls related to impacts, data, transparency, human oversight, and responsible use.

When should Annex A controls be reviewed?

Controls should be reviewed after model updates, data changes, new use cases, supplier changes, incidents, regulatory changes, or changes in intended use.

What Should Organizations Remember About the ISO 42001 Annex A Controls List?

ISO 42001 Annex A contains 38 controls covering AI policies, responsibilities, resources, impact assessments, system development, data governance, transparency, responsible use, and third-party relationships.

Effective implementation does not mean applying all 38 controls identically.

It means selecting proportionate controls, connecting them to identified risks, assigning accountable owners, maintaining evidence, and recording decisions in the Statement of Applicability.

This risk-based approach helps organizations establish an Artificial Intelligence Management System that supports responsible AI development, controlled AI use, transparency, accountability, and continual improvement.

Picture of Wasim Malik

Wasim Malik

CEO and Founder of Risk Professionals with over 26 years of experience in Risk Management, Business Resilience, AI, Cyber Resilience, GRC, and ESG. Skilled in designing impactful technical projects, mentoring teams, and driving strategic initiatives to achieve measurable results.