KI FÜR MÜNCHEN AI adoption. Done right.

GOVERNANCE · 7 July 2026 · 7 min READ

ISO 42001 Annex A: the 38 controls that make AI management work

The clauses of ISO 42001 say WHAT an AI management system must achieve. Annex A says with WHICH concrete controls. An overview of the 38 controls across nine areas — and how to select the right ones.

Anyone working with ISO/IEC 42001 quickly encounters two levels: clauses 4 to 10, which describe what an AI management system must achieve — and Annex A, which provides the concrete controls with which that succeeds. Whoever builds the AIMS in practice works on Annex A. This article gives the overview.

What Annex A is

Annex A is the normative set of controls of ISO 42001: 38 controls, grouped into nine control areas (A.2 to A.10). They are the AI counterpart to what Annex A of ISO 27001 is for information security — only tailored to the responsible use of AI.

Important: you do not blindly implement all 38. As with 27001, you select the applicable controls and justify the selection — matching your actual AI use and risk.

The nine control areas

A.2 — AI policy. The guardrails from the very top: a management-level AI policy that everything else aligns to.

A.3 — Internal organisation. Roles and responsibilities: who decides on AI, who approves, who reports incidents?

A.4 — Resources for AI systems. What an AI system needs and what must be documented: data, tools, compute resources, human know-how.

A.5 — Assessing impacts. The AI impact assessment — the consequences of a system for the people affected (employees, customers, third parties). The genuine novelty compared to older management standards.

A.6 — AI system life cycle. Requirements for development, testing, release, operation and retirement — including data quality and traceability. Engineers will recognise it: life-cycle thinking, applied to AI.

A.7 — Data for AI systems. Origin, quality, preparation and governance of the data the AI works on — the foundation of any reliable AI.

A.8 — Information for interested parties. Transparency: whoever deals with the AI’s results must know where they stand — users, customers, supervisors.

A.9 — Responsible use. Rules for intended use: what the AI is for, what it is explicitly not for, and where the human keeps control.

A.10 — Third parties and customers. Whoever sources AI from third parties or delivers it to customers must assess their roles and risks — cloud provider, foundation model, purchased tool.

The further annexes B, C and D

Annex A does not stand alone. Annex B provides the normative implementation guidance for the controls — the “how” behind the “what”. Annex C (informative) names potential AI risk sources and objectives as an aid for risk assessment. Annex D (informative) frames the use of the AIMS across industries and domains.

From catalogue to operation

The most common mistake is to treat Annex A as a tick-box list. An AIMS that consists only of ticked controls falls apart at the first real incident. Value emerges when the controls describe and steer the actual AI processes — then operations become measurably calmer, and the certificate is a by-product.

Two bridges matter here: many A-controls reach into information security (ISO/IEC 27001) — data, access, suppliers. And they create the framework in which the obligations of the EU AI Act — risk register, human oversight, documentation — can be organised cleanly, rather than patched together one by one.

We build AIMS by exactly this logic and work by it ourselves — as a TÜV Süd certified AI Officer; the ISO/IEC 42001 certification is in preparation. The first step is always a gap analysis: which controls are already in place and which are missing.

This article was created with AI assistance and editorially reviewed under the responsibility of Stephan Walkowiak. See our AI transparency statement for details.

NEXT STEP

Apply this to your company?

In an initial consultation we discuss what this topic looks like in your specific case — honestly, even if the answer is "not yet".