Information for Interested Parties of AI Systems - ISO 42001 Annex A Controls
ISO 42001 Annex A.8
Information for interested parties is what makes AI use accountable. Without it, the management system cannot demonstrate transparency or responsiveness to those affected.
ISO 42001 Annex A.8 - Information for Interested Parties of AI Systems Explained
Annex A.8 recognises that AI systems often affect interested parties beyond the immediate organisation. The four controls together require the organisation to make sure relevant interested parties have the necessary information to understand and assess the AI system, can report adverse impacts, are notified of incidents, and receive appropriate information about the AI system's role.
Control A.8.2 - System documentation and information for users
The organisation must determine and provide the necessary information to users of the AI system. The implementation guidance under Annex B.8.2 lists the information typically provided - the purpose of the system, that the user is interacting with an AI system, how to interact with the system, how and when to override it, technical requirements and limitations, needs for human oversight, information about accuracy and performance, relevant impact assessment information, system updates and contact information.
Control A.8.3 - External reporting
The organisation must provide capabilities for interested parties to report adverse impacts of the AI system. The reporting capability is for external interested parties - users, affected individuals and others outside the organisation - and complements the internal reporting mechanism under A.3.3. The aim is to make sure adverse impacts can be raised, investigated and addressed.
Control A.8.4 - Communication of incidents
The organisation must determine and document a plan for communicating incidents to users of the AI system. The plan typically covers the types of incidents that must be communicated, the timeline for notification, whether and which authorities must be notified, and the details required to be communicated. AI-specific incidents include AI system failures, model drift causing significant performance degradation, and adversarial attacks. Information security incidents under ISO 27001 and personal data breaches under the UK GDPR may also apply.
Control A.8.5 - Information for interested parties
The organisation must determine and document its obligations to report information about the AI system to interested parties. Information that may be reported includes technical system documentation, risks related to the system, results of impact assessments, and logs and other system records. Reporting may be required to regulators, contractual customers, or other interested parties depending on the jurisdiction and the nature of the AI system.
The transparency expectation under A.8.2 is the control that customer-facing organisations need to engage with most carefully. The implementation guidance specifically lists notification that the user is interacting with an AI system as one of the items typically provided. UK GDPR Article 22 imposes specific obligations where automated decisions have significant effects on individuals. The EU AI Act introduces further transparency duties for organisations selling into European markets. The standard helps organisations build the foundation that meets all these obligations together.
The external reporting mechanism under A.8.3 is sometimes overlooked. It is not enough to have an internal channel for staff to raise concerns. Affected individuals outside the organisation also need a route to report adverse impacts. A simple email address or web form is usually sufficient, with clear governance for who reviews submissions and how responses are handled.
When auditing Annex A.8, I look for the user-facing documentation, the external reporting channel, the incident communications plan and the regulatory reporting commitments. For each, I check that the obligation has been determined, the response has been documented, and the response has been delivered or tested.
The external reporting channel needs to be accessible. A reporting capability buried at the bottom of a long terms-of-service document is unlikely to be effective. The standard expects affected individuals to be able to find and use the channel.
For the inspection AI, the users are line operators and the QA team. They get the supplier's manual plus our standard operating procedure, both of which now flag that AI is involved and what to do if a result looks wrong. For the generative tool, the users are office staff and they get the AI usage guide. External reporting goes through the customer service email with a flag for AI-related concerns.
Practical Compliance Guidance
The IMS1 Manual Section 3.3 Management System Communication/IMS1-3-3 Communication establishes the framework for communications, with the AI-specific arrangements under Annex A.8 integrated into the wider communications matrix. The P-17 Communications Policy sets out the policy framework that the AI-specific arrangements operate within.
The following alphaZ documents support compliance with ISO 42001 Annex A.8.
| alphaZ document | How to use it |
|---|---|
| ISO 42001 AI Management System Toolkit | The full toolkit containing the AI management system documentation including the AI policy, communications policy and IMS1. |
| P-17 Communications Policy | The communications policy that establishes the framework for internal and external communication, extended to cover AI-specific communications. |
| PP-8-100 AI Content Procedure | Sets out the procedure for the use of AI in content generation including transparency to recipients of AI-assisted content, supporting A.8.2. |
| F-IMS70 Annex A Controls | Records the Statement of Applicability including the A.8 controls with the implementation status and supporting evidence. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
The following UK legislation is directly relevant to information for interested parties of AI systems. Organisations outside the UK should identify the equivalent legislation applicable in their jurisdiction.
