Anyone working with ISO/IEC 42001 quickly encounters two levels: clauses 4 to 10, which describe what an AI management system must achieve — and Annex A, which provides the concrete controls with which that succeeds. Whoever builds the AIMS in practice works on Annex A. This article gives the overview.
What Annex A is
Annex A is the normative set of controls of ISO 42001: 38 controls, grouped into nine control areas (A.2 to A.10). They are the AI counterpart to what Annex A of ISO 27001 is for information security — only tailored to the responsible use of AI.
Important: you do not blindly implement all 38. As with 27001, you select the applicable controls and justify the selection — matching your actual AI use and risk.
The nine control areas
A.2 — AI policy. The guardrails from the very top: a management-level AI policy that everything else aligns to.
A.3 — Internal organisation. Roles and responsibilities: who decides on AI, who approves, who reports incidents?
A.4 — Resources for AI systems. What an AI system needs and what must be documented: data, tools, compute resources, human know-how.
A.5 — Assessing impacts. The AI impact assessment — the consequences of a system for the people affected (employees, customers, third parties). The genuine novelty compared to older management standards.
A.6 — AI system life cycle. Requirements for development, testing, release, operation and retirement — including data quality and traceability. Engineers will recognise it: life-cycle thinking, applied to AI.
A.7 — Data for AI systems. Origin, quality, preparation and governance of the data the AI works on — the foundation of any reliable AI.
A.8 — Information for interested parties. Transparency: whoever deals with the AI’s results must know where they stand — users, customers, supervisors.
A.9 — Responsible use. Rules for intended use: what the AI is for, what it is explicitly not for, and where the human keeps control.
A.10 — Third parties and customers. Whoever sources AI from third parties or delivers it to customers must assess their roles and risks — cloud provider, foundation model, purchased tool.
The further annexes B, C and D
Annex A does not stand alone. Annex B provides the normative implementation guidance for the controls — the “how” behind the “what”. Annex C (informative) names potential AI risk sources and objectives as an aid for risk assessment. Annex D (informative) frames the use of the AIMS across industries and domains.
From catalogue to operation
The most common mistake is to treat Annex A as a tick-box list. An AIMS that consists only of ticked controls falls apart at the first real incident. Value emerges when the controls describe and steer the actual AI processes — then operations become measurably calmer, and the certificate is a by-product.
Two bridges matter here: many A-controls reach into information security (ISO/IEC 27001) — data, access, suppliers. And they create the framework in which the obligations of the EU AI Act — risk register, human oversight, documentation — can be organised cleanly, rather than patched together one by one.
We build AIMS by exactly this logic and work by it ourselves — as a TÜV Süd certified AI Officer; the ISO/IEC 42001 certification is in preparation. The first step is always a gap analysis: which controls are already in place and which are missing.