Adding AI to an Annex SL system
If you already run an ISO 9001, ISO 13485 or ISO 27001 system, most of ISO 42001 is already in place. This page shows what carries over clause by clause, what is genuinely new, and how to add it as one system rather than two.
"Keep it Simple. Keep it Real."
What Carries Over
ISO 42001 uses the harmonized structure every modern ISO management standard uses. If you hold ISO 9001, 13485 or 27001, you already have clauses 4 through 10. The table shows what you reuse and what each clause adds for AI.
| Clause | What you already have | What ISO 42001 adds |
|---|---|---|
| 4. Context | Issues, interested parties, scope | Your role with AI (developer, provider, user) and the AI systems in scope |
| 5. Leadership | Policy, roles, commitment | An AI policy with objectives and a named owner for AI governance |
| 6. Planning | Risk-based thinking, objectives | AI risk assessment, AI risk treatment, AI system impact assessment (6.1.4), and the Statement of Applicability |
| 7. Support | Competence, awareness, document control | AI awareness for everyone who uses it, and records for AI systems and AI-generated content |
| 8. Operation | Process control, change control, suppliers | Running the impact assessments, controlling AI system changes, and the Annex A controls you selected |
| 9. Performance evaluation | Monitoring, internal audit, management review | Measures for AI systems, an internal audit that covers Annex A, and AI on the management review agenda |
| 10. Improvement | Nonconformity, corrective action | The same CAPA process, now fed by AI incidents and impact-assessment findings |
The clause-level detail, with the evidence an auditor asks for at each one, is in ISO 42001 clause by clause.
What Is New
This is the real size of the project for a company that already holds a certificate.
Every AI system you develop or use, with an owner, a purpose, the data it sees and the decisions it touches. Vendor features count. This is usually the first document an auditor asks for and the one nobody has.
A short policy leadership actually signed, with objectives that can be measured. Your quality policy does not cover this, and a paragraph about "responsible AI" on the website does not count.
For each system that affects people, products or decisions: who could be harmed, how, and what you do about it. Your risk register has the method; this is a new object in it.
Which Annex A controls apply, which do not, and why. ISO 27001 holders know this document; ISO 9001 holders will be writing their first one. See the SoA explained.
What your contracts say about AI a supplier runs on your data or inside your process. Your supplier qualification process already exists; the questions on the questionnaire do not.
Not a sentence in a procedure but a record: who reviews AI output before it becomes a decision or a document, and proof that they did. This is where most systems are thinnest.
Integrate, Do Not Duplicate
The most expensive mistake we see companies make with a second standard is building a second system: a separate manual, a separate document register, a separate internal audit calendar and a separate management review, each maintained by a different person. It doubles the upkeep and it makes the auditor's job harder, because the same requirement now has two answers.
The better way is to extend what you have. Add AI to the scope statement. Put the AI policy beside the quality policy. Add the AI system inventory and the impact assessments to the existing risk process. Extend the supplier questionnaire, the training matrix and the internal audit checklist. Put AI on the management review agenda. Then ask your certification body whether it is accredited for ISO 42001 under ISO/IEC 42006 and whether it can audit both standards in one visit. Many can; some cannot yet, and it is worth knowing before you plan the audit.
The one place we recommend a genuinely new process rather than an extension is human oversight of AI-generated content. Existing review and approval steps were designed for documents people wrote slowly. They need to be re-stated for documents a tool can produce instantly, or the review step quietly disappears. We wrote about why that matters most for regulated manufacturers in AI governance and quality management.
Most certified companies land at the short end of the four-to-twelve-month range.
Our gap assessment is a fixed $9,750 and tells you the rest of the number. Implementation support is scoped from the gap report. Certification body fees for an extension to an existing certificate are usually lower than for a new one, because the audit days are fewer; ask the body for a quote that covers both standards.
The line items and three worked budgets are in what ISO 42001 costs. If your base is ISO 27001 rather than ISO 9001, read from ISO 27001 to ISO 42001 as well.
Yes, and it should be. Both follow the Annex SL structure, so one manual, one document control process, one internal audit program and one management review can cover both. The AI-specific content sits inside the system you already have. Ask your certification body whether it is accredited for ISO 42001 and can audit both together; not every body is yet.
Typically at the short end of the four-to-twelve-month range. Clauses 4 through 10 mostly exist already; the work is the AI system inventory, AI risk and impact assessments, the Statement of Applicability, the Annex A controls that apply, and evidence of human oversight.
In some places. ISO 27001 already has a Statement of Applicability and a risk-treatment habit, which ISO 42001 borrows directly. ISO 9001 carries over more on process control, supplier management and records. Either is a strong base; ISO 13485 adds design controls and risk management that map well onto AI systems you build.
An inventory of AI systems, an AI policy with objectives, AI risk assessment and AI system impact assessments, the Statement of Applicability, controls on AI from suppliers, and documented human oversight of AI decisions. Everything else is an extension of a process you already run.
Book a free 30-minute call. Tell us which standard you hold and which AI tools you use, and we will tell you roughly how much of the work is already done and what the rest would take.
Or email us at [email protected]