AI Governance 13 min read

What Does ISO 42001 Clause 7.3 Require of Non-Technical Staff?

J

September 13, 2026

Clause 7.3 of ISO/IEC 42001 asks one thing of the people in your organization who do not build or manage AI: that they know the AI policy, understand how their own work affects the AI management system, and understand what happens when they ignore it. That is the whole clause. It does not ask for a training platform, a certification, or a separate program. If you already keep ISO 9001 or GMP training records, the practical answer is to add AI awareness to the training matrix you have, deliver it through the route you already use, record it on the form you already use, and make sure people can answer a few plain questions when the auditor pulls them aside.

What clause 7.3 actually says

ISO 42001 is an Annex SL standard, so clause 7.3 reads almost word for word like the awareness clause in ISO 27001 and ISO 9001. Persons doing work under the organization's control shall be aware of:

  1. the AI policy,
  2. their contribution to the effectiveness of the AI management system, including the benefits of improved performance, and
  3. the implications of not conforming with the AI management system requirements.

Three points. You will see longer lists on other sites, usually adding the AI objectives from clause 6.2 and the risks relevant to each role. Those are sensible things to teach, and in our experience they are how you make the second point concrete, but they are not extra requirements. The text is short on purpose. What the clause turns on is the phrase "persons doing work under the organization's control," which reaches past employees to contractors, temps, and anyone else whose work you direct.

Two things the clause does not say matter just as much. First, it does not say "competent." Competence is clause 7.2, and it applies to the people whose work affects AI performance: developers, the people who validate a model, the quality unit reviewing AI-generated records. Awareness is broader and shallower. An accounts payable clerk does not need to be competent in AI; she needs to know that the invoice-matching tool is an AI system, that the policy says a human approves exceptions, and where to raise a concern when the tool does something odd.

Second, clause 7.3 does not itself require documented information. The record-keeping language sits in 7.2, which asks you to retain evidence of competence. That is why auditors approach 7.3 by interviewing staff. Records help, and you should keep them, but the test is whether the person in front of the auditor can answer.

So what does "aware" look like for a non-technical role? A useful check is whether the person can answer these four questions in their own words.

Question What a good answer sounds like
What is our AI policy about? "We can use approved tools for drafting and summaries, we never put customer or batch data into a public tool, and a person signs off before anything AI-written goes out."
Which AI tools touch your job? Names the actual tools, including the ones built into email, the ERP, or the CRM.
What is your part in keeping it working? "I check the output before I use it, and I flag it if it looks wrong."
What happens if you do not follow the policy? Names a real consequence: a bad decision, a data leak, a regulatory finding, a disciplinary step.

If most people in a department can do that, you are conforming. If they can only confirm that a policy exists somewhere on the intranet, you are not.

Why non-technical staff are where the audit gets interesting

In a mid-sized company, the people who build or tune AI systems are a small minority. Everyone else is a user, and often does not think of themselves as one. The HR coordinator using a screening tool, the finance analyst summarizing a contract in a chatbot, the technical writer asking a model to draft a procedure, the customer service lead trusting an AI summary of a complaint. These are the people whose everyday choices create AI risk, and they are the ones an auditor will pick from a department list and interview.

The FDA gave the regulated world a concrete example in April 2026. A warning letter to Purolea cited "inappropriate use of artificial intelligence" under 21 CFR 211.22(c): specifications, procedures, and master records had been written with AI and released without qualified review. It is the first time AI-generated quality records drew an FDA citation, and at its root it is an awareness failure. Whoever used the tool either did not know what the rules were, or the rules did not exist. Nothing about that scenario involves a data scientist.

What the auditor will ask to see

Certification auditors verify 7.3 in two ways: they look at documents and they talk to people. Here is what the document side typically involves, and where it usually already lives if you run a quality system.

Evidence Where it usually already lives What the auditor is checking
The AI policy and proof it was communicated Document control, the same place your quality policy sits Clause 5.2 says the policy must be communicated. They want to see how, and to whom.
A training needs analysis or matrix by role Your training procedure and matrix That you decided who needs what depth, rather than sending one deck to everyone.
The awareness content itself, under version control Document control That it references your policy and your actual tools, and that they can see which version each person received.
Individual training records Your training record form or LMS Name, date, content version, trainer, and some kind of sign-off.
An effectiveness check Whatever you already use: a short quiz, a supervisor attestation, a read-and-understand signature That awareness was confirmed, and not only delivered.
Onboarding and contractor induction New hire checklist, contractor orientation That people are trained before they use an AI-enabled system, and that contractors are covered.
Retraining after a change Change control, document change notices That a policy revision or a new AI tool triggered retraining, and that it happened.
A route to report concerns Your deviation, complaint, or nonconformance procedure Annex A control A.3.3 asks for a process to report concerns about AI systems. Staff should know it exists and how to use it.

None of those rows requires a new system. If you hold ISO 9001 or operate under GMP, every one is a record you already keep; what you add is the AI content inside it.

Then comes the interview. Auditors pick people who are not on the implementation team, and the questions are simple:

  • "Can you describe the AI policy in your own words?"
  • "Which AI tools do you use, and what have you been told about using them?"
  • "What would you do if a tool gave you a result that looked biased or wrong?"
  • "Has your training been updated since you started?"

What they are listening for is consistency. If the HR manager describes the policy one way and the finance analyst describes it another, an experienced auditor will keep pulling on that thread. In our experience, inconsistent interview answers are one of the most common sources of a minor nonconformance in a first 42001 audit, and they usually trace back to one generic deck that never told anyone what the policy meant for their own desk.

If you already run ISO 9001 training

ISO 9001 clause 7.3 asks that people be aware of the quality policy, the relevant quality objectives, their contribution, and the implications of nonconformance. The structure is the same, and so is the system you built to satisfy it: a training procedure, a training needs analysis, a matrix that maps roles to required training, individual records, and some method of evaluating effectiveness. You reuse all of it. Here is the sequence we use with 9001-certified clients.

  1. Add AI to the training needs analysis. Go department by department and list which AI tools each role touches, including the ones embedded in software people already use. This list doubles as the AI inventory your clause 4 context work needs anyway.
  2. Tier roles by exposure. Three tiers is enough for most organizations (see the table below). The tier decides how deep the training goes; everyone gets some.
  3. Write one awareness module, then a short role-specific supplement for the high-exposure tier. The core module covers the AI policy, the approved-tool list, what may never go into a public tool, who reviews AI-generated output, and how to report a concern. The supplements cover the risks that matter to that role: bias in screening for HR, data leakage for finance, unreviewed procedure text for quality and technical writing.
  4. Deliver through your existing route and record on your existing training form, with the content version number on the record.
  5. Use your existing effectiveness method. A five-question quiz or a supervisor sign-off is fine. The requirement is that some check exists, and the one you already use will do.
  6. Add triggers to change control. A revision to the AI policy, the introduction of a new AI tool, an AI-related incident, or a role change should each trigger retraining for the affected group, the same way a revised SOP does today.
  7. Add 7.3 to your internal audit checklist and management review inputs. The internal auditor should interview a few non-technical staff before the certification body does. Our ISO 42001 internal audit checklist has the questions.
Tier Who Depth
High exposure Roles whose decisions are shaped by AI output: HR, finance, legal, customer service, quality, technical writing Core module plus a role supplement with scenarios; roughly 60 to 90 minutes in our experience
Moderate exposure Roles that use AI-assisted tools occasionally: operations, procurement, marketing, sales Core module with function-specific examples; roughly 30 to 45 minutes
Minimal exposure Roles with little or no direct AI tool use: facilities, warehouse, reception Policy, prohibited uses, and how to report; roughly 15 to 20 minutes

What actually changes is the content. The training procedure, the matrix, the record form, and the effectiveness check are the same documents with a new row. For a fuller view of how the rest of 42001 sits on top of a 9001 system, see what ISO 42001 adds to an ISO 9001 system.

If you run GMP training records

GMP manufacturers have an even shorter distance to cover. 21 CFR 211.25 already requires training in the particular operations each employee performs and in current good manufacturing practice as it relates to their functions, delivered by qualified people on a continuing basis and with enough frequency that staff stay familiar with the requirements. Part 111 for dietary supplements carries the same expectation, and the device QMSR incorporates ISO 13485, whose clause 6.2 reads much like 9001.

If an operation now involves an AI tool, the training on that operation has to cover the tool. 211.25 has said that all along, before ISO 42001 existed. The clean way to do it is the way you handle any new expectation on the floor: write or revise an SOP, then train it.

In practice the SOP covers a short list. Which AI tools are permitted, and for what. What may never go into an external tool: batch records, deviations, complaint files, anything with patient or customer data. Who reviews and approves AI-drafted text before it becomes a controlled document, and how that review is recorded. How the use of AI in a record is disclosed. How to report a concern about an AI output. Then you train the SOP the way you train every SOP, with a read-and-understand signature or a classroom session, recorded on your existing training form.

The Purolea letter tells you what an FDA investigator will ask when they see AI in the quality system. Who wrote this procedure? Did the quality unit know AI was used? Who reviewed it, and against what? Your awareness training is the answer to the question underneath those: did the people who used the tool know the rules? If you want a second pair of eyes on the records themselves before an investigator sees them, our AI-in-the-quality-system review does exactly that, and ISO 42001 for GMP manufacturers covers how the wider standard fits under Parts 211 and 111.

The mistakes we see most often

Using a vendor's AI ethics course as the only evidence. A course from a software supplier can supplement your training, but it cannot describe your policy, your tool list, or your reporting route. Auditors will ask how a generic course told the AP clerk which tool she may use, and there is no good answer.

Recording awareness as competence. If your training record says an HR coordinator is "competent" in AI after a 30-minute awareness session, an auditor will ask what competence was assessed. Keep the two words apart on the form. Awareness is for everyone; competence is for the people whose work affects AI performance.

No trigger when a new tool arrives. The IT team turns on an AI feature in the CRM, nobody updates the tool list, and six months later the interview reveals that half the sales team is using it with no idea whether it is approved. Adding "new AI tool" to your change control triggers fixes this.

No known route to report a concern. People will say "I guess I'd tell my manager." An auditor will not accept that as a process, and Annex A asks for one. Point your existing deviation or nonconformance route at AI concerns and tell people so.

What this takes in time

In our experience, an organization with a working 9001 or GMP training system can have the awareness piece of clause 7.3 in place in a few weeks of part-time effort: a day or two to build the tool inventory by role, a few days to write the core module and the high-exposure supplements, and then whatever your normal training cycle takes to get everyone through it. The slow part is usually the AI policy itself, because you cannot teach a policy that is still in draft.

If you are working toward certification and want to know how far your existing training records already carry you, that is one of the questions a fixed-fee ISO 42001 gap assessment answers in writing. For the clause-level view of the whole standard, start with the clause-by-clause breakdown, and for what has to exist on paper, see the documentation requirements.

Frequently Asked Questions

Does ISO 42001 clause 7.3 apply to employees who never use AI?

Yes. The clause covers every person doing work under the organization's control, including contractors and temporary staff, but the depth of awareness should match how much AI touches their work. Someone with no AI exposure needs to know the policy exists, what it forbids, and where to report a concern.

Does clause 7.3 require training records?

The clause itself does not name a record; the documented-information requirement sits in clause 7.2 on competence. In practice, auditors verify 7.3 through staff interviews plus whatever training records you keep, so a record on your existing training form is the simplest way to show it.

Can we satisfy ISO 42001 awareness with our ISO 9001 training procedure?

Usually yes. ISO 9001 clause 7.3 has the same structure, so you add AI awareness to your training needs analysis and matrix, deliver it through the same route, and record it on the same forms. The content is new; the system is not.

How often does AI awareness training need to be repeated?

ISO 42001 does not set an interval. Most organizations refresh annually and retrain when the AI policy changes, a new AI tool is introduced, or an AI-related incident occurs, which mirrors how they already handle revised procedures.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.