Policies Related to AI - ISO 42001 Annex A Controls

ISO 42001 Annex A.2

The AI policy is the document that signals top management's intent and direction for AI. Without it, every other Annex A control loses its anchor.

ISO 42001 Annex A.2 - Policies Related to AI Explained

Annex A.2 is the first control area in ISO 42001 Annex A, which is the appropriate starting point given that the AI policy underpins everything that follows. The objective stated by the standard is to provide management direction and support for AI systems according to business requirements. The three controls in this section work together to make sure that policy is documented, that it is consistent with the organisation's other policies, and that it is kept current.

Control A.2.2 - AI policy

The organisation must document a policy for the development or use of AI systems. The AI policy is the formal statement of top management's intentions with respect to AI, and serves the same function in the AI management system as the quality policy does in ISO 9001 or the information security policy does in ISO 27001.

The standard's implementation guidance under Annex B.2.2 sets out what the AI policy should be informed by - business strategy, organisational values, the level of risk posed by the AI systems, legal requirements, the organisation's risk environment, and the impact on relevant interested parties. The policy should also include the principles that guide AI activities and the processes for handling deviations and exceptions.

For organisations that already have an integrated management system, the AI policy can be a separate document or a clearly identified section within a wider policy document, provided it meets the content requirements of Clause 5.2 and the implementation guidance.

Control A.2.3 - Alignment with other organisational policies

The organisation must determine where other policies can be affected by, or apply to, the organisation's objectives with respect to AI systems. AI intersects with many other policy areas - data protection, information security, equality and diversity, procurement, communications, intellectual property, and quality. The control requires a deliberate review of these intersections rather than letting policies drift apart over time.

In practice, this control is satisfied by mapping the AI policy against the existing policy framework, identifying any conflicts or gaps, and either updating the existing policies or including the AI-specific provisions in the AI policy. The decision should be documented so that an auditor can see the work has been done.

Control A.2.4 - Review of the AI policy

The AI policy must be reviewed at planned intervals or when needed to make sure it remains suitable, adequate and effective. AI is a fast-moving area both technically and in terms of regulation, and a policy written eighteen months ago may already be out of date. The standard expects the review to consider changes in the organisational environment, business circumstances, legal conditions and the technical environment.

The review of the AI policy is most efficiently combined with the management review under Clause 9.3, where the inputs and outputs of the wider review naturally inform the policy review. A separate, ad-hoc review can be triggered by significant events such as a major regulatory change, a new AI system being adopted, or an incident affecting an existing AI system.

The AI policy is where many organisations stumble. It is tempting to copy a generic template and call it done, but a generic AI policy is almost worse than no policy at all because it gives the impression of governance without the substance. The policy needs to reflect what the organisation actually does with AI, the risks it is willing to accept, and the principles it expects its people to follow.

Aligning the AI policy with existing policies is also more involved than people expect. Data protection, information security, procurement and communications policies all touch AI, and a small change to any of them can have implications for the AI management system. Mapping the policy framework once and then keeping it under review is the most effective approach.

We have one AI policy, two pages, signed by the MD. It says what we use AI for, what we will not use AI for, who decides, and what staff need to do if something looks off. That is enough. Anyone who needs the detail goes to the management system documents. Anyone who just needs to know the rules can read the policy in five minutes.

When auditing Annex A.2, I look for the AI policy as documented information, signed or formally approved by top management, dated and version controlled. I check that it covers the elements required by Clause 5.2 and the implementation guidance in Annex B.2.2, and that it has been communicated within the organisation.

For alignment with other policies, I expect to see evidence of the mapping exercise, whether that is a written analysis or simply a record of the review. The Statement of Applicability should also reference how the AI policy connects to other organisational policies. For policy review, I look at the date of the last review, the inputs considered, and the conclusions reached.

Practical Compliance Guidance

The IMS1 Manual Section 2.1 Company Policies/IMS1-1-2-1 Company Objectives/Policies is the place where the AI policy is set out alongside the other top-level policies of the management system, with responsibility statements and approval recorded against each policy.

The following alphaZ documents support compliance with ISO 42001 Annex A.2.

alphaZ document How to use it
ISO 42001 AI Management System Toolkit The full toolkit containing the AI management system documentation including the P-120 AI Policy and the AI-specific registers, assessments and forms. 
P-120 Artificial Intelligence Policy The standalone AI policy document covering the requirements of Clause 5.2 and the elements set out in the Annex B.2.2 implementation guidance.
F-IMS70 Annex A Controls Records the Statement of Applicability including the Annex A.2 controls and the justification for their inclusion or exclusion.
F-Q3 Management Review Provides the standing input format for the management review where the AI policy is reviewed at planned intervals.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

The AI policy can be a standalone document or a clearly identified section within an integrated policy document, provided it meets the content requirements of Clause 5.2 and the implementation guidance under Annex B.2.2. Many organisations with an existing integrated management system find a standalone P-120 AI Policy easier to maintain and present to auditors than a buried section in a longer document.
The standard requires review at planned intervals or as needed. Most organisations align the policy review with the annual management review cycle, which is sufficient for stable AI environments. A more frequent review is appropriate where the organisation is rapidly adopting new AI systems, where the regulatory landscape is changing, or where an AI-related incident has occurred.
Alignment means that the AI policy and the organisation's other policies do not contradict each other and that AI-specific concerns are covered somewhere appropriate. The data protection policy should account for AI processing of personal data, the information security policy should cover AI-specific threats such as model poisoning and prompt injection, and the procurement policy should cover the assessment of AI suppliers. The mapping exercise identifies where existing policies need to extend to cover AI and where the AI policy can reference other policies rather than duplicate their content.
Annex A controls are reference controls. The organisation determines which controls apply through its Statement of Applicability based on the results of the AI risk assessment. In practice, all three Annex A.2 controls are difficult to exclude because the AI policy itself is also required by Clause 5.2, alignment with other policies is implicit in any integrated management system, and review at planned intervals is implicit in the management review requirements at Clause 9.3. Excluding any of them would need a clear and documented justification.

Further Resources

payment logos