Many organisations align their AI Management Systems with the ISO High-Level Structure (Clauses 4-10), as it provides a clear and recognised basis for governance and control.
Organisational Context and AI Scope (Clause 4)
Clause 4 focuses on understanding the organisation’s context, identifying interested parties, defining the scope, and setting the boundaries of the management system.
For an AIMS, this might include:
- Understanding where AI affects products, services, or internal decision-making.
- Identifying stakeholders (customers, employees, regulators, partners, and procurement teams).
- Defining whether the AIMS covers all AI use or only certain functions, sites, products, or risk areas.
- Setting boundaries for what is in and out of scope, including third‑party tools.
The intention of this clause is clarity, highlighting that governance works best when the scope of the AI is explicit.
ISO 42001’s scope determination under 4.3 is explicitly tied to the organisation’s AI role(s) for each system or use case. This is a distinguishing feature of 42001 compared to other Annex SL management systems (e.g. 27001 or 9001), where scope is more about physical or organisational boundaries alone.
Leadership and Accountability (Clause 5)
Clause 5 focuses on leadership responsibility, policy direction, and the definition of roles and responsibilities.
In an AIMS context, this may involve clear leadership accountability for AI governance, policy statements that set expectations for responsible AI use, and building governance structures that define who approves, monitors, and escalates AI-related issues.
This is often where organisations link AI risk to broader organisational governance and risk management.
Risk Management and Planning (Clause 6)
Clause 6 covers planning, including risk and opportunity management, setting objectives, and planning for change.
For AI, this could include:
- Identifying AI-related risks such as bias, transparency, safety, reliability, and security.
- Evaluating risks based on use case impact (for example, decisions affecting people vs low-impact automation).
- Planning controls and monitoring appropriate to the risk level.
- Defining objectives for AI governance (for example, consistency, oversight, and documentation quality).
- Controlling change when AI systems, data sources, or integrations are modified.
- Conducting AI System Impact Assessments to evaluate potential effects on individuals, groups, and society.
Resources, Competence and Awareness (Clause 7)
Clause 7 covers the support needed to operate the management system, including resources, competence/training, awareness, communication, and documented information.
AIMS-related topics may include competence for teams using or overseeing AI (not just technical staff), awareness so staff understand where AI is used and what oversight is expected, and documented information (policies, procedures, records) that is controlled and maintained.
Resource allocation for monitoring, incident handling, and governance activities could also be involved.
A common practical issue is that AI adoption can outpace organisational capability. Clause 7 addresses skills and awareness.
Operational Control of AI Systems (Clause 8)
Clause 8 focuses on how the organisation runs and controls the activities within the scope of the management system.
For an AIMS, operational control may relate to:
- Data input management and quality controls.
- Development and testing controls (where AI is built in-house).
- Validation before deployment, including defining intended use and limitations.
- Monitoring in use.
- Change management for updates, configuration changes, or new use cases.
- Governance controls for third-party AI tools (supplier information, limitations, oversight responsibilities).
- Re-assessing AI system impact when significant changes occur in operation.
This clause is where governance becomes visible in day-to-day operations.
Performance Monitoring and Review (Clause 9)
Clause 9 covers monitoring and measurement, internal audit, and management review, with performance evaluations potentially including monitoring whether AI controls are working as intended, tracking incidents and recurring issues, conducting internal audits of AIMS controls, and management reviews to ensure leadership has visibility into AI risk and system performance.
These actions support evidence-based oversight rather than corrective decision-making based on assumptions.
Continual Improvement (Clause 10)
Clause 10 focuses on improvement, including nonconformity and corrective action, as well as continual improvement. For AI governance, this may involve:
- Identifying and recording AI-related issues (for example, unexpected outcomes or control failures).
- Corrective action to address root causes and prevent recurrence.
- Learning from monitoring and audit findings.
- Adapting controls as AI use changes, new risks emerge, or organisational context evolves.
In practice, continual improvement is often where AI governance matures, with initial controls changing into controls that keep pace with change.