Chapter 21
21The Annex A Controls of ISO 42001
“Thirty-eight controls do not create responsible AI, but they stop it being responsible by accident.”
As in 27001, ISO 42001 offers a list of reference controls in its Annex A: 38 controls across nine domains. They are selected based on risks and impact assessment, and selection and exclusion are justified in the Statement of Applicability. Annex B provides implementation guidance for each control.


Text in this figure
AI policies · A.2 · 3 controls · Internal organisation · A.3 · 2 controls · Resources · A.4 · 5 controls · Impact assessment · A.5 · 4 controls · System life cycle · A.6 · 9 controls · Data · A.7 · 5 controls · Interested-party info · A.8 · 4 controls · Use of AI systems · A.9 · 3 controls · Third parties, customers · A.10 · 3 controls · Shaded: closest to creative work · controls are selected and justified in the SoA · Figure 27
| Domain | Content |
|---|---|
| A.2 Policies | The AI policy, its alignment with other policies, and its review. |
| A.3 Internal organisation | Roles and responsibilities, and reporting concerns. |
| A.4 Resources | Documenting data, tools, computing and human competence for each system. |
| A.5 Impact assessment | The assessment process, its documentation, and impact on individuals and society. |
| A.6 Life cycle | Objectives for responsible development, design, verification, deployment, operation and logs. |
| A.7 Data | Data quality, provenance, preparation and acquisition rights. |
| A.8 Information for interested parties | Documentation for users, incident reporting and communication. |
| A.9 Use of AI systems | Responsible use according to intended purpose and objectives. |
| A.10 Third-party relationships | Allocating responsibilities with suppliers and customers. |
Controls Worth Starting With
- An AI system register: An inventory of every system or tool: purpose, owner, role, data and impact level. There is no governance for what we do not know exists.
- Documenting system resources: Which model and version, which data, and which connected tools.
- Data quality and provenance: A record proving where the data came from and whether we have the right to use it.
- Information for users: Clear disclosure that the user is dealing with an AI system, and the limits of its capabilities.
- A reporting channel: A way for employees or clients to report a harmful output or concerns.
Relationship to 27001 Controls
The 42001 controls do not repeat security controls; they assume that access control, cryptography and supplier management are already in place through 27001, and add what is specific to AI. So an organisation certified to 27001 has already covered much of the way, and starts from the system register and impact assessment.
2026 Update
These controls intersect with the US AI Risk Management Framework (NIST AI RMF) and its four functions, Govern, Map, Measure and Manage, and with the EU AI Act’s requirements for high-risk systems. Implementing 42001 well goes a long way towards complying with them.
Start with the system register; every other control needs to know which system it is talking about.
Lessons Learned
- 138 controls in nine domains, from A.2 to A.10.
- 2Controls are selected by risk and impact assessment and justified in the SoA.
- 3The AI system register is the practical starting point.
- 442001 controls complement 27001 rather than repeating it.
Tip: use ← → to move between sections.

