Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
23 / 34

Chapter 21

21The Annex A Controls of ISO 42001

2 min read23 of 34Read it in the book · page 123

“Thirty-eight controls do not create responsible AI, but they stop it being responsible by accident.”

As in 27001, ISO 42001 offers a list of reference controls in its Annex A: 38 controls across nine domains. They are selected based on risks and impact assessment, and selection and exclusion are justified in the Statement of Applicability. Annex B provides implementation guidance for each control.

Annex A of ISO 42001: nine domains and 38 controlsAnnex A of ISO 42001: nine domains and 38 controls
Annex A of ISO 42001: nine domains and 38 controls
Text in this figure

AI policies · A.2 · 3 controls · Internal organisation · A.3 · 2 controls · Resources · A.4 · 5 controls · Impact assessment · A.5 · 4 controls · System life cycle · A.6 · 9 controls · Data · A.7 · 5 controls · Interested-party info · A.8 · 4 controls · Use of AI systems · A.9 · 3 controls · Third parties, customers · A.10 · 3 controls · Shaded: closest to creative work · controls are selected and justified in the SoA · Figure 27

DomainContent
A.2 PoliciesThe AI policy, its alignment with other policies, and its review.
A.3 Internal organisationRoles and responsibilities, and reporting concerns.
A.4 ResourcesDocumenting data, tools, computing and human competence for each system.
A.5 Impact assessmentThe assessment process, its documentation, and impact on individuals and society.
A.6 Life cycleObjectives for responsible development, design, verification, deployment, operation and logs.
A.7 DataData quality, provenance, preparation and acquisition rights.
A.8 Information for interested partiesDocumentation for users, incident reporting and communication.
A.9 Use of AI systemsResponsible use according to intended purpose and objectives.
A.10 Third-party relationshipsAllocating responsibilities with suppliers and customers.

Controls Worth Starting With

  • An AI system register: An inventory of every system or tool: purpose, owner, role, data and impact level. There is no governance for what we do not know exists.
  • Documenting system resources: Which model and version, which data, and which connected tools.
  • Data quality and provenance: A record proving where the data came from and whether we have the right to use it.
  • Information for users: Clear disclosure that the user is dealing with an AI system, and the limits of its capabilities.
  • A reporting channel: A way for employees or clients to report a harmful output or concerns.

Relationship to 27001 Controls

The 42001 controls do not repeat security controls; they assume that access control, cryptography and supplier management are already in place through 27001, and add what is specific to AI. So an organisation certified to 27001 has already covered much of the way, and starts from the system register and impact assessment.

2026 Update

These controls intersect with the US AI Risk Management Framework (NIST AI RMF) and its four functions, Govern, Map, Measure and Manage, and with the EU AI Act’s requirements for high-risk systems. Implementing 42001 well goes a long way towards complying with them.

Start with the system register; every other control needs to know which system it is talking about.

Lessons Learned

  1. 138 controls in nine domains, from A.2 to A.10.
  2. 2Controls are selected by risk and impact assessment and justified in the SoA.
  3. 3The AI system register is the practical starting point.
  4. 442001 controls complement 27001 rather than repeating it.

Tip: use ← → to move between sections.