AI Governance 13 min read

ISO 42001 Clause by Clause: What Each Requires and What You Can Reuse

J

September 13, 2026

ISO/IEC 42001:2023 has ten clauses, but only clauses 4 through 10 carry requirements an auditor can write a finding against. They follow the same Annex SL numbering as ISO 9001 and ISO 27001, so a company that already holds one of those certificates has most of clauses 4, 5, 7, 9 and 10 in place and needs to build three things it has never built before: an AI policy with named AI roles, an AI risk assessment and treatment process that ends in a Statement of Applicability, and an AI system impact assessment. Each clause below gets the same three answers: what it asks for, what evidence an auditor will want, and where the requirement already lives in ISO 9001 or ISO 27001.

How the standard is organized

Clauses 1 to 3 define scope, normative references and terms, and nothing in them is auditable on its own. Clauses 4 to 10 are the management system. Annex A lists the reference controls in nine areas, which you select from and justify in a Statement of Applicability, and Annex B gives implementation guidance for them.

Clause Already in ISO 9001? Already in ISO 27001? New in ISO 42001
4 Context Yes, 4.1 to 4.4 Yes, 4.1 to 4.4 Your AI roles; an inventory of AI systems in scope
5 Leadership Yes, 5.1 to 5.3 Yes, 5.1 to 5.3 An AI policy and named AI roles
6 Planning Partly (6.1 is light) Yes, 6.1 and 6.2 closely AI risk criteria, Annex A comparison, Statement of Applicability, impact assessment process
7 Support Yes, 7.1 to 7.5 Yes, 7.1 to 7.5 AI competence; AI documents under document control
8 Operation Different shape (8.1 to 8.7) Yes, 8.1 to 8.3 Performing impact assessments (8.4); lifecycle controls
9 Performance evaluation Yes, 9.1 to 9.3 Yes, 9.1 to 9.3 AI metrics; auditors who understand AI systems
10 Improvement Yes, 10.1 to 10.3 Yes, 10.1 and 10.2 AI incidents routed into corrective action

Clause 4: Context of the organization

What it requires. Clause 4.1 asks you to determine the internal and external issues that affect your AI management system and, specific to this standard, the roles you play with respect to AI systems: developing them, providing them, or using them. Clause 4.2 asks who the interested parties are and what they require of you, and for AI that list includes the people your systems make decisions about. Clause 4.3 asks you to set the scope of the AIMS as documented information, and 4.4 is the commitment to establish, maintain and continually improve it.

What an auditor expects to see. A record of the context analysis, a list of interested parties with their requirements, and a written scope statement naming which AI systems, products, sites and roles are inside. In our experience the scope conversation goes nowhere until there is an inventory of AI systems, including the tools that arrived inside a SaaS subscription, so expect the auditor to ask for one even though clause 4 never uses the word.

What you can reuse. All four sub-clauses exist with the same numbers in ISO 9001 and ISO 27001. Your context register and interested-party analysis take new rows for AI, and a 27001 scope statement is the right format. What is new is the role determination and the inventory, and in my experience those two pages of work drive every decision that follows.

Clause 5: Leadership

What it requires. Clause 5.1 asks top management to show commitment: setting the AI policy and objectives in line with the company's direction, integrating the AIMS into business processes, and providing resources. Clause 5.2 requires a documented AI policy that fits the organization, gives a framework for AI objectives, commits to applicable requirements and continual improvement, and is communicated internally and available to interested parties where appropriate. Clause 5.3 requires AI roles, responsibilities and authorities to be assigned and communicated, including who reports AIMS performance upward.

What an auditor expects to see. An approved AI policy with a revision history, evidence it was communicated (training records, a signed acknowledgment), and a responsibility matrix. At Stage 2 the auditor interviews top management directly and asks what the policy commits the company to and how they know the system is working. A policy the executive cannot describe is a finding waiting to happen.

What you can reuse. Clause 5 is nearly word for word the same as clause 5 of ISO 9001 and ISO 27001, with the quality or information security policy swapped for an AI policy, and integrated companies often fold both into one document. The standard names no job title, so a Chief AI Officer is optional; what you need is a named person with the authority to stop a deployment.

Clause 6: Planning

What it requires. This is where most of the new work lives. Clause 6.1.1 asks you to take the issues and interested parties from clause 4 and plan actions for risks and opportunities. Clause 6.1.2 requires a defined AI risk assessment process, with risk and acceptance criteria that produce consistent and comparable results, used to identify, analyze and evaluate AI risks against your AI objectives. Clause 6.1.3 covers treatment: choose options, determine the controls needed, compare them against Annex A so nothing necessary is missed, produce a Statement of Applicability justifying every inclusion and exclusion, and write a treatment plan. Clause 6.1.4 requires a documented process for assessing the potential consequences of your AI systems for individuals, groups and society. Clause 6.2 requires measurable AI objectives with plans to reach them, and 6.3 requires changes to the AIMS to be planned.

What an auditor expects to see. A written methodology and criteria, a risk register with entries that are actually about AI (bias in training data, model drift, hallucinated content in a controlled record, use of an unapproved tool), a treatment plan with owners and dates, the Statement of Applicability, an impact assessment procedure, and measurable objectives. "Use AI responsibly" will draw a question; "reduce unreviewed AI-drafted procedures to zero by Q2" will not.

What you can reuse. ISO 27001 companies will recognize every step in 6.1.2 and 6.1.3, because ISO 42001 borrowed the structure. The methodology, criteria, register, treatment plan and SoA format transfer almost intact; what changes is the list of risk sources, and Annex C is a useful starting list. ISO 9001 clause 6.1 asks for risk-based thinking without a formal method, so this is usually the biggest build for a 9001-only company, though device and pharma manufacturers can adapt the risk tools they already run under ISO 14971 or ICH Q9. The impact assessment in 6.1.4 has no equivalent in either standard; its closest cousin is a GDPR data protection impact assessment, and companies that do those can borrow the format.

Clause 7: Support

What it requires. Clause 7.1 asks for the resources the AIMS needs. Clause 7.2 asks you to define the competence required of people whose work affects AI performance, make sure they have it, and keep evidence. Clause 7.3 requires awareness of the AI policy, of each person's contribution, and of what happens when the system is not followed. Clause 7.4 asks what gets communicated about the AIMS, to whom, when and how. Clause 7.5 sets the rules for documented information: identification, review and approval, and control of distribution, change and retention.

What an auditor expects to see. A competence matrix with lines for everyone who builds, validates, approves or relies on AI outputs. The data scientists are the easy part; the approvers are usually missing. Awareness records, a communication plan, and a document master list that includes the AIMS documents, from which the auditor will sample a few for approval signatures and revision dates. A shared drive folder with no version control does not meet 7.5.

What you can reuse. Clause 7 is close to identical across the three standards, so your document control procedure and training matrix work as they are once AI documents and AI competence are added. For regulated manufacturers, 7.2 and 7.5 are where the FDA's April 2026 Purolea warning letter lands: AI-written specifications, procedures and master records were released without qualified review, and FDA cited it as inappropriate use of artificial intelligence under 21 CFR 211.22(c). Who may approve an AI-drafted record, and proof that they did, is exactly what our AI-in-the-quality-system review examines.

Clause 8: Operation

What it requires. Clause 8.1 asks you to plan, implement and control the processes that meet the AIMS requirements and carry out the actions from clause 6: process criteria, documented information showing the processes ran as planned, control of planned and unintended changes, and control of outsourced processes and suppliers that matter to the AIMS. Clauses 8.2 and 8.3 require the AI risk assessment to be performed at planned intervals and on significant change, and the treatment plan to be implemented, with results retained. Clause 8.4 requires the impact assessment from 6.1.4 to be performed on the same triggers.

What an auditor expects to see. Records with dates: risk assessments repeated on a schedule, a completed impact assessment for each AI system in scope, change records showing that a model update or a new use case triggered a reassessment, and supplier controls for AI vendors (contracts, evaluations, change notices). The lifecycle procedures asked about here, design through retirement, come from Annex A.6 and run under 8.1.

What you can reuse. ISO 27001 clauses 8.1 to 8.3 have the same shape, so a 27001 company adds 8.4 and the lifecycle procedures. ISO 9001 clause 8 is larger and differently shaped, but it maps well: design and development controls under 9001 clause 8.3 are a strong base for the AI lifecycle, external provider controls under 8.4 cover AI vendors, and nonconforming output handling under 8.7 is where a bad model output belongs. Pharma and device companies can reuse computer system validation and software assurance documentation for the verification and validation steps, which is one reason GMP manufacturers often reach clause 8 faster than software companies do.

Clause 9: Performance evaluation

What it requires. Clause 9.1 asks what you monitor and measure, by what method, when, and when the results are analyzed. Clause 9.2 requires an internal audit program with defined frequency, methods, responsibilities and reporting, objective and impartial auditors, and results reported to management. Clause 9.3 requires top management to review the AIMS at planned intervals against defined inputs (earlier actions, changes in context, performance, audit results, opportunities to improve) and to record decisions.

What an auditor expects to see. Metrics about the AI systems themselves: error rates, drift indicators, human override rates, incident counts, complaints. An audit program and at least one completed internal audit covering every clause and every applicable Annex A control. Management review minutes with decisions and assigned actions rather than a list of topics. Certification bodies generally expect a full internal audit and a management review before Stage 2, and a rescheduled Stage 2 hurts when some are already waiting six months or more.

What you can reuse. The audit program and management review from 9001 or 27001 extend naturally: add the AIMS to the schedule and AI inputs to the review agenda; an integrated review is acceptable. What does not transfer is auditor competence. An internal auditor who has never seen a model card or a training data record will struggle with 8.4 and Annex A.6, so plan for training or bring someone in. Our internal audit checklist is written for that first cycle.

Clause 10: Improvement

What it requires. Clause 10.1 requires continual improvement of the suitability, adequacy and effectiveness of the AIMS. Clause 10.2 is the familiar corrective action cycle: react, evaluate whether the cause needs to be eliminated, act, review effectiveness, update the risk assessment if needed, and keep records of the nonconformity and the outcome.

What an auditor expects to see. A corrective action log with AI entries in it. A model producing wrong outputs, a team using a tool that was never approved, an AI-drafted procedure that reached the shop floor without review: each is a nonconformity under this standard and belongs in the log with a root cause and an effectiveness check. An empty AI section tells the auditor the incidents are happening and going uncaptured.

What you can reuse. Your corrective action process, whether a CAPA system under 21 CFR 820 or a nonconformity register under 27001, is the process. The new work is deciding what counts as an AI nonconformity and routing those events into it.

Annex A: nine control areas and the Statement of Applicability

Annex A is normative, and the auditor reaches it through the Statement of Applicability from clause 6.1.3. Every control you include needs evidence it is implemented, and every control you exclude needs a justification the auditor accepts. The controls fall into nine areas:

  1. Policies related to AI. The AI policy, its alignment with other policies, and its review.
  2. Internal organization. Roles, responsibilities and how AI concerns are reported.
  3. Resources for AI systems. Documenting the data, tooling, computing and people each system depends on.
  4. Assessing impacts of AI systems. The process and records behind clauses 6.1.4 and 8.4.
  5. AI system life cycle. Design, verification and validation, deployment, monitoring and technical documentation.
  6. Data for AI systems. Provenance, quality, acquisition and preparation of training and test data.
  7. Information for interested parties. What you tell users and affected people, and how they report concerns.
  8. Use of AI systems. Responsible and intended use for the people who operate AI rather than build it.
  9. Third-party and customer relationships. Allocating responsibility along the AI supply chain.

A 27001 company reuses its SoA format directly, and a 9001 company will find supplier controls, design controls and document control already covering much of areas 1, 5 and 9. We keep a separate guide on which Annex A controls apply.

Where to start if certification is on next quarter's plan

The clauses build on each other, so sequence matters more than speed. Inventory your AI systems and settle the scope (clause 4) before writing anything else. Write the risk methodology and the impact assessment process (clause 6) next, because clauses 8, 9 and 10 all consume their outputs. Get the policy signed and the roles assigned (clause 5) before the system starts operating, and run one internal audit and one management review (clause 9) before you book Stage 2.

Gap assessment to certificate commonly runs four to twelve months, with 27001 and 9001 companies at the short end. First-year cost for a 50 to 200 person company is commonly quoted at $85,000 to $150,000 including internal time, tooling and the certification body, so the reuse question is worth real money. Fewer than 100 organizations held a 42001 certificate in January 2026 and roughly 350 did by spring (there is no official register; the count is assembled from announcements), and certification bodies are reporting auditor backlogs, so book the audit early.

Our ISO 42001 gap assessment is a fixed-fee $9,750 engagement that walks every clause above and every Annex A area against what you have. If you already hold ISO 9001, start with what 42001 adds to a 9001 system. The standard is demanding in three places and familiar everywhere else, and knowing which is which is most of the work.

Frequently Asked Questions

Which ISO 42001 clauses are audited for certification?

Clauses 4 through 10 carry the auditable requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Clauses 1 to 3 cover scope, references and terms, and the Annex A controls are audited through your Statement of Applicability.

Can I reuse my ISO 27001 or ISO 9001 system for ISO 42001?

Yes, for most of clauses 4, 5, 7, 9 and 10, because all three standards share the same Annex SL structure. What you cannot reuse is the AI policy, the AI risk assessment and treatment that ends in a Statement of Applicability, and the AI system impact assessment, which has no equivalent in either standard.

Does ISO 42001 certification satisfy the EU AI Act?

No. EN ISO/IEC 42001:2026 was adopted as a European standard on 18 March 2026, but it has not been cited as a harmonised standard in the Official Journal, so certification gives no presumption of conformity. The standard being written for that purpose is prEN 18286.

What is the AI system impact assessment in ISO 42001?

It is a documented review of how an AI system could affect individuals, groups and society, required by clause 6.1.4 (the process) and clause 8.4 (performing it at planned intervals and on significant change). It is the one requirement most companies coming from ISO 9001 or ISO 27001 have never done before.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.