DoAIRight
ISO/IEC 42001

ISO 42001 Annex A Controls Explained: A.2 to A.10 Guide

PUBLISHED 06 AUG 2026

ISO 42001 Annex A provides a practical normative framework of reference control objectives and controls designed to address risks and manage impacts across the entire artificial intelligence lifecycle. Spanning domains A.2 through A.10, these controls cover AI policies, internal oversight, resource allocation, ethical impact assessments, lifecycle governance, data management, transparency, system usage, and third-party relationships. Organizations implementing an AI Management System (AIMS) perform risk and impact evaluations to determine which controls are applicable, documenting their choices in a Statement of Applicability (SoA).

Overview of ISO 42001 Annex A

While Clauses 4 through 10 of ISO/IEC 42001 establish the core requirements for an AI Management System, Annex A functions as a targeted control catalog. It gives organizations actionable mechanisms to mitigate specific AI risks and maximize responsible deployment.

Selecting Annex A controls is not an all-or-nothing exercise. Instead, control selection relies on your unique organizational context, risk assessment, and impact analysis regarding individuals, groups, and society.

Breakdown of Annex A Control Domains (A.2 to A.10)

A.2 Policies Related to AI

  • Control Objective: Ensure top management establishes clear, actionable direction for responsible AI alignment.
  • Key Requirements: Organizations must define and communicate top-level AI policies aligned with ethical principles, legal obligations, and business objectives. These policies must be periodically reviewed to reflect evolving technology and regulatory landscapes.

A.3 Internal Organization

  • Control Objective: Assign accountability and governance structures for AI systems.
  • Key Requirements: Establish clear roles, operational responsibilities, and reporting pathways for AI oversight. This includes establishing cross-functional governance structures that separate conflicting duties and mandate cross-departmental accountability.

A.4 Resources for AI Systems

  • Control Objective: Ensure adequate infrastructure, tooling, and human competencies are provided.
  • Key Requirements: Organizations must allocate sufficient resources—including computing power, specialized software, quality data, and skilled personnel—to support safe AI development and operation. Continuous training programs must be maintained to keep staff competencies current.

A.5 Assessing Impacts of AI Systems

  • Control Objective: Evaluate potential consequences on individuals, groups, and broader society.
  • Key Requirements: Conduct structured impact assessments across the full system lifecycle. These assessments must evaluate potential societal harm, unfair bias, safety hazards, and human rights implications, ensuring proportional safeguards are instituted.

A.6 AI System Life Cycle

  • Control Objective: Manage AI systems systematically from initial design to eventual decommissioning.
  • Key Requirements: Define operational controls for every lifecycle phase, including concept, design, data acquisition, model training, verification, validation, deployment, monitoring, and retirement. Traceability and version control must be preserved throughout.

A.7 Data for AI Systems

  • Control Objective: Ensure data quality, integrity, privacy, and provenance across training, testing, and operation.
  • Key Requirements: Implement controls for data acquisition, preprocessing, labeling, bias detection, and lineage tracking. Data handling practices must align with applicable privacy laws and organizational fairness goals.

A.8 Information for Interested Parties

  • Control Objective: Foster transparency, explainability, and appropriate communication.
  • Key Requirements: Provide external stakeholders, system operators, and affected individuals with clear information regarding AI capabilities, limitations, intended purpose, and underlying operational logic where appropriate.

A.9 Use of AI Systems

  • Control Objective: Ensure responsible operational usage and continuous human oversight.
  • Key Requirements: Establish clear guidelines for acceptable AI use, implement operational monitoring, mandate appropriate human-in-the-loop oversight mechanisms, and train end-users to prevent automated decision-making failures.

A.10 Third-Party and Customer Relationships

  • Control Objective: Mitigate risks introduced by AI suppliers, vendors, partners, and external integrations.
  • Key Requirements: Perform due diligence on third-party AI models, components, and datasets. Establish contractual controls to enforce security, fairness, performance, and transparency standards throughout the supply chain.

Implementing Annex A Controls in Your AIMS

To effectively apply these controls, follow a structured management approach:

  1. Conduct Context & Risk Assessment: Identify your organization's role (provider, producer, or deployer) and evaluate systemic risks.
  2. Evaluate Impacts: Measure how your AI applications affect individuals, specialized groups, and society.
  3. Draft the Statement of Applicability (SoA): Formally justify why specific Annex A controls are included or excluded.
  4. Integrate and Automate: Embed control mechanisms into current engineering, IT, and legal workflows.

Before undergoing an external audit, evaluating your maturity level is critical. Using DoAIRight’s free readiness assessment allows you to benchmark your current governance against ISO/IEC 42001 requirements, spot compliance gaps early, and streamline preparation for an accredited human auditor.

Frequently asked

Are all ISO 42001 Annex A controls mandatory?

No. Annex A controls are selectable based on your risk assessment and impact analysis. Any excluded controls must be formally justified in your Statement of Applicability (SoA).

What is the difference between Clause 6 Planning and Annex A controls?

Clause 6 defines the process for evaluating AI risks, societal impacts, and setting objectives. Annex A provides specific reference control objectives and controls used to mitigate those identified risks.

Does DoAIRight issue ISO 42001 certifications?

No. DoAIRight provides tools and guidance to help organizations implement an AIMS and achieve certification readiness. Official ISO/IEC 42001 certification can only be granted by an accredited third-party certification body employing independent human auditors.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score