Skip to main content
← All resources
Guide

ISO/IEC 42001 Implementation Guide: from Annex A controls to audit-ready evidence

Sentrify Team9 min read
On this page

ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It describes how an organisation should govern the AI it builds, buys and uses. This guide turns the standard into ten practical steps, shows what evidence each part of Annex A typically needs, and gives you a 90-day plan to get started.

This guide is general information. It is not legal advice, and following it does not by itself make an organisation certified. Certification against ISO/IEC 42001 is carried out by an accredited certification body.

Who this guide is for

Risk, compliance and governance leads, and the AI and product teams who work with them, in organisations that are starting to implement ISO 42001 or that have been asked to show alignment with it by a board, a customer or a regulator.

What ISO 42001 requires

ISO 42001 asks you to establish an AI management system (AIMS): the policies, roles, processes and records that show your AI is governed. It has two parts.

  • Clauses 4 to 10 describe the management system itself: context, leadership, planning, support, operation, performance evaluation and improvement. These follow the same structure as other ISO management system standards.
  • Annex A lists 38 controls in nine groups that you consider and, where relevant, apply to your AI systems. Annex A is where most of the day-to-day evidence comes from.

You decide which Annex A controls apply, and you record that decision, with reasons, in a document called the Statement of Applicability.

The ten steps

Step 1. Define your scope and context (clause 4). Decide which AI systems, teams and locations are inside your AIMS. List the internal and external issues that affect your AI, and the interested parties who care about it, such as customers, regulators and staff. Evidence: a scope statement and a register of interested parties and their requirements.

Step 2. Set leadership and accountability (clause 5). Name an executive sponsor, and assign clear roles for who owns each AI system, who assesses its risk, and who approves it. Evidence: a roles and responsibilities document and a record of leadership approval.

Step 3. Build an AI inventory. You cannot govern what you cannot see. List every AI system, model and agent, including those bought from vendors and those embedded in other software. For each, record its purpose, owner, users, data and lifecycle status. Evidence: the inventory, with a review date.

Step 4. Assess risk and impact (clauses 6.1.2 and 6.1.4, 8.2 and 8.4). Define how you assess AI risk and how you assess an AI system's impact on people and society. Then do it for each system in your inventory. Evidence: a documented risk method, completed risk assessments and completed impact assessments.

Step 5. Treat risk and write your Statement of Applicability (clause 6.1.3). Decide how you will treat each risk, compare your chosen controls against Annex A, and record which controls apply and why, and which do not and why. Evidence: a risk treatment plan and a Statement of Applicability.

Cover of the AI Governance Checklist: 50 checkpoints for responsible AI deployment
Free download

AI Governance Checklist

50 checkpoints for responsible AI deployment: governance documentation, evidence requirements, control mapping and regulator-ready reporting. Built for Australian compliance contexts (ISO 42001, APRA CPS 230, TEQSA).

We'll email you the file and may follow up about Sentrify. You can unsubscribe at any time. See our Privacy Policy.

Step 6. Set your AI policy and objectives (clauses 5.2 and 6.2). Publish an AI policy that leadership has approved, and set measurable objectives, such as the percentage of AI systems with a completed impact assessment. Evidence: the approved policy, the objectives, and a plan for how each will be measured.

Step 7. Provide resources, competence and awareness (clause 7). Make sure the people running the AIMS have the skills, budget and tools they need, and that everyone who works with AI understands the policy. Evidence: training records, competence records and communication records.

Step 8. Operate your controls across the AI lifecycle (clause 8 and Annex A). Put the controls you selected into practice, from design and testing through deployment, monitoring and retirement. Manage changes deliberately, and control any AI you buy from third parties. Evidence: design records, test results, change logs, monitoring reports and supplier records.

Step 9. Monitor, audit and review (clause 9). Measure how the AIMS is performing, run an internal audit, and hold a management review where leadership looks at the results. Evidence: monitoring data, internal audit reports and management review minutes.

Step 10. Improve (clause 10). When something fails or a finding is raised, record it, fix the cause and check that the fix worked. Evidence: a log of nonconformities and corrective actions.

What evidence each Annex A group typically needs

Annex A groupWhat it coversTypical evidence
A.2 Policies related to AIYour AI policy and how it fits with other policiesApproved AI policy, review records, a mapping to related policies
A.3 Internal organisationRoles, responsibilities and reporting of concernsRole descriptions, an escalation and concern-reporting procedure
A.4 Resources for AI systemsThe data, tools, computing and people an AI system needsResource documentation for each system
A.5 Assessing impacts of AI systemsHow you assess effects on people and societyImpact assessment process and completed assessments
A.6 AI system life cycleDesign, testing, deployment, operation and monitoringDesign objectives, verification and validation results, deployment plans, monitoring records, event logs, technical documentation
A.7 Data for AI systemsData quality, provenance and preparationData management procedures, provenance records, data quality checks
A.8 Information for interested partiesWhat you tell users and others about your AIUser documentation, disclosure notices, incident communication procedure
A.9 Use of AI systemsHow AI is used responsibly inside your organisationResponsible use procedures, defined intended uses
A.10 Third-party and customer relationshipsResponsibilities shared with suppliers and customersSupplier assessments, contract terms, customer information

Common pitfalls

  1. Treating it as a document exercise. A policy on a shared drive is not a management system. Auditors look for evidence that the policy is followed.
  2. An incomplete inventory. Shadow AI and AI embedded in vendor software are the systems most often missed.
  3. A Statement of Applicability with no reasons. Every excluded control needs a documented justification.
  4. Point-in-time evidence. A risk assessment done once and never revisited goes stale as models, data and regulations change.
  5. No proof that evidence is unaltered. If a document can be edited after the fact, its value as evidence drops. Keep versions and record when each item was added.

A 90-day plan

Days 1 to 30: foundation. Confirm the executive sponsor and name the AIMS lead. Set the scope. Build the first version of the AI inventory. Agree the risk and impact assessment method.

Days 31 to 60: assessment and treatment. Assess the highest-risk systems first. Draft the risk treatment plan and the Statement of Applicability. Approve the AI policy and set the first objectives.

Days 61 to 90: operate and evidence. Put the selected controls into practice for your first systems. Collect evidence against each control. Run a small internal review to find gaps before anyone external does.

How Sentrify helps

Sentrify's 94 governance controls map to the 38 requirements of Annex A, and to the other frameworks in its crosswalk. You register your AI systems, upload evidence that is versioned and integrity-hashed, run an automated evaluation, and receive a TrustScore™ and an assurance report with the full evidence chain. Approvals stay with your people: Sentrify routes the review and records the decision. All data stays in AWS Sydney.

Sentrify's controls are aligned to ISO 42001. Alignment does not constitute certification.

Next steps

  • Download the AI Governance Checklist for 50 practical checkpoints.
  • See what the output looks like in the sample assurance report.
  • Book a demo, or apply for the 8-week pilot.
Cover of the AI Governance Checklist: 50 checkpoints for responsible AI deployment
Free download

AI Governance Checklist

50 checkpoints for responsible AI deployment: governance documentation, evidence requirements, control mapping and regulator-ready reporting. Built for Australian compliance contexts (ISO 42001, APRA CPS 230, TEQSA).

We'll email you the file and may follow up about Sentrify. You can unsubscribe at any time. See our Privacy Policy.

Turn this guide into evidence.

Related reading: ISO 42001 Explained: What Your AI Team Actually Needs to Do

← All resources