ISO/IEC 42001 Annex A Controls List: All 38 Controls (A.2 to A.10)
ISO/IEC 42001:2023 Annex A contains 38 AI-specific controls organised into 9 control objectives (A.2 to A.10). This page lists every control, grouped by objective, with a one-line description, plus a short comparison to ISO 27001 Annex A and guidance on implementation priority.
Free ISO 42001 SoA template (XLSX): all 38 Annex A controls as a fillable Statement of Applicability, with Applicable, Justification, Implementation status and Owner columns.
Download the SoA template (XLSX)What Is ISO 42001 Annex A?
ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems (AIMS). Like other ISO management system standards, it combines high-level requirements (clauses 4 through 10) with a reference set of controls in Annex A, and implementation guidance in Annex B.
Annex A contains 38 controls across 9 control objectives, each objective representing a domain of AI-specific risk: AI policy, internal organisation, resources, impact assessment, AI system life cycle, data, information for interested parties, responsible use, and third-party relationships. The controls are deliberately high-level and principle-based, not prescriptive technical requirements.
An organisation implementing ISO 42001 selects which Annex A controls apply, documents them in a Statement of Applicability (SoA), and implements them proportionate to the AI risks identified in the AI system impact assessment. Annex B gives implementation-level guidance for each control.
ISO 42001 Annex A vs ISO 27001 Annex A
Both standards use an Annex A reference set of controls, but they address different risk domains and are structured differently.
In practice, organisations that already hold ISO 27001 certification find ISO 42001 easier to implement because the management-system clauses (context, leadership, planning, support, operation, evaluation, improvement) follow the same Harmonized Structure. The delta is the AI-specific Annex A, plus the AI system impact assessment process in Annex A.5.
Complete List of All 38 ISO 42001 Annex A Controls
Below is every ISO/IEC 42001:2023 Annex A control, grouped by its parent control objective, with a one-line summary of what the control requires. Use these as a reference when building your Statement of Applicability or preparing for a certification audit.
Need the full detail? Each control code below links to its in-depth guidance on ControlStack, our free AU compliance-control tool. Or look up any ISO 42001 control on ControlStack →
Work through these 38 controls in a spreadsheet: download the free Statement of Applicability (SoA) template (XLSX) and mark each control Applicable, with justification, status and owner.
Download the SoA template (XLSX)A.2: Policies related to AI (3 controls)
A.3: Internal organisation (2 controls)
A.4: Resources for AI systems (5 controls)
A.5: Assessing impacts of AI systems (4 controls)
A.6: AI system life cycle (9 controls)
A.7: Data for AI systems (5 controls)
A.8: Information for interested parties of AI systems (4 controls)
A.9: Use of AI systems (3 controls)
A.10: Third-party and customer relationships (3 controls)
Implementation Priority
Not every control requires the same urgency in a first ISO 42001 implementation. A practical sequencing that maps to the typical maturity journey:
- Start with A.2 and A.3. You cannot implement anything coherent without an AI policy (A.2.2), alignment with existing organisational policies (A.2.3), defined AI roles (A.3.2), and a concerns-reporting process (A.3.3). These five controls establish the governance baseline.
- Then A.5: impact assessment process. ISO 42001 is a risk-based standard. Without an impact assessment process (A.5.2-A.5.5), you cannot decide which other controls apply at what depth. Do this second.
- Then A.4: resource documentation. A.4.2-A.4.6 describes what data, tooling, compute, and human resources your AI systems use. This inventory feeds directly into the life cycle and data controls.
- Then A.7 and A.6: data and life cycle. These are the operational heavy lifting. Data controls (A.7.2-A.7.6) and life cycle controls (A.6.1.2-A.6.2.8) are where most implementation effort lands.
- Then A.8 and A.10: interested parties and suppliers. External communication, user-facing documentation, supplier due diligence, and customer obligations. These depend on earlier inventories being in place.
- Finally A.9: use of AI systems. Responsible use processes typically come last because they formalise behaviours that earlier controls make possible.
For a structured implementation path covering every Annex A control, the PECB ISO 42001 Lead Implementer course walks through each in sequence with templates and worked examples.
Resources
- ISO 42001 Certification Guide: Full walkthrough of what ISO 42001 is, why it matters, and the Australian adoption context.
- PECB ISO 42001 Foundation Course: Self-paced introduction to AIMS concepts, $399 AUD.
- PECB ISO 42001 Lead Implementer Course: Full implementation methodology with Annex A walkthroughs, $849 AUD.
- PECB ISO 42001 Lead Auditor Course: Audit ISO 42001 against Annex A controls, $849 AUD.
- PECB training courses: Browse all PECB-accredited ISO 27001, ISO 42001, and ISO 31000 courses.
- ISO 42001 practice questions: Free exam-style questions to test your knowledge of the Annex A controls.
- ISO 27001 Annex A Controls: All 93 controls listed and explained, useful for mapping to ISO 42001.
- ISO 27001 vs NIST CSF Comparison: If you are also considering the NIST CSF path.
ISO 42001 Implementation Checklist
Use this ISO 42001 checklist to work through all 38 Annex A controls across the nine objectives (A.2 to A.10). It condenses the control tables above into a scannable ISO 42001 requirements checklist you can track as you build your AI management system. Tick items off below (your progress is saved in this browser), or download the printable version.
Download all 38 controls: the printable Implementation Checklist (PDF), or the fillable Statement of Applicability template (XLSX) with Applicable, Justification, status and owner columns.
A.2: Policies related to AI
- A.2.2 AI policy
- A.2.3 Alignment with other organisational policies
- A.2.4 Review of the AI policy
A.3: Internal organisation
- A.3.2 AI roles and responsibilities
- A.3.3 Reporting of concerns
A.4: Resources for AI systems
- A.4.2 Resource documentation
- A.4.3 Data resources
- A.4.4 Tooling resources
- A.4.5 System and computing resources
- A.4.6 Human resources
A.5: Assessing impacts of AI systems
- A.5.2 AI system impact assessment process
- A.5.3 Documentation of AI system impact assessments
- A.5.4 Assessing AI system impact on individuals or groups of individuals
- A.5.5 Assessing societal impacts of AI systems
A.6: AI system life cycle
- A.6.1.2 Objectives for responsible development of AI system
- A.6.1.3 Processes for responsible design and development of AI systems
- A.6.2.2 AI system requirements and specification
- A.6.2.3 Documentation of AI system design and development
- A.6.2.4 AI system verification and validation
- A.6.2.5 AI system deployment
- A.6.2.6 AI system operation and monitoring
- A.6.2.7 AI system technical documentation
- A.6.2.8 AI system recording of event logs
A.7: Data for AI systems
- A.7.2 Data for development and enhancement of AI system
- A.7.3 Acquisition of data
- A.7.4 Quality of data for AI systems
- A.7.5 Data provenance
- A.7.6 Data preparation
A.8: Information for interested parties of AI systems
- A.8.2 System documentation and information for users
- A.8.3 External reporting
- A.8.4 Communication of incidents
- A.8.5 Information for interested parties
A.9: Use of AI systems
- A.9.2 Processes for responsible use of AI systems
- A.9.3 Objectives for responsible use of AI system
- A.9.4 Intended use of the AI system
A.10: Third-party and customer relationships
- A.10.2 Allocation of responsibilities
- A.10.3 Suppliers
- A.10.4 Customers
Frequently Asked Questions
Common questions about ISO 42001 Annex A controls and implementation.
How many controls are in ISO 42001 Annex A?
ISO/IEC 42001:2023 Annex A contains 38 controls organised into 9 control objectives (A.2 through A.10). The objectives cover AI policy, internal organisation, resources, impact assessment, system life cycle, data, information for interested parties, use of AI systems, and third-party relationships.
Are ISO 42001 Annex A controls mandatory?
No. They are informative. ISO/IEC 42001 requires organisations to take a risk-based approach: you document which controls apply in a Statement of Applicability (SoA), justifying inclusions and exclusions against your AI risk assessment. Unlike some standards, Annex A in ISO 42001 is not a prescriptive checklist; it is a reference set of controls you select from.
How does ISO 42001 Annex A compare to ISO 27001 Annex A?
Both standards use Annex A to house a reference set of controls, but they target different risks. ISO 27001 Annex A has 93 controls across four themes (organisational, people, physical, technological) and focuses on the confidentiality, integrity, and availability of information assets. ISO 42001 Annex A has 38 controls across nine objectives and focuses on AI-specific concerns: bias, transparency, data quality, human oversight, societal impact, and AI supply chain. Organisations that already run an ISO 27001 ISMS can extend it to ISO 42001 without rebuilding governance.
Where does Annex B fit in?
Annex B is an implementation guidance annex: it provides practical guidance for each Annex A control, helping organisations translate the control requirement into operational practice. Annex B is informative (not normative), meaning it supports implementation without adding mandatory requirements.
Do I need to implement every Annex A control?
No. You run a risk assessment against the AI systems in your scope, then document in the Statement of Applicability which Annex A controls you have included, excluded, or modified, with justification. This is the same approach ISO 27001 uses. In practice, most organisations implementing an AIMS implement the majority of Annex A controls because AI-specific risks are broad and the controls are high-level rather than deeply prescriptive.
How do I get certified against ISO 42001?
Certification requires an accredited certification body to audit your AI Management System (AIMS) against ISO/IEC 42001 requirements in a two-stage audit. Before engaging an auditor, most organisations run a gap analysis, implement clauses 4 to 10 and the relevant Annex A controls, run an internal audit, and hold a management review. The PECB ISO 42001 Lead Implementer course covers the full implementation pathway.
Where can I see the full ISO 42001 standard?
ISO/IEC 42001:2023 is a licensed publication. You can purchase the standard from iso.org or from an authorised reseller such as Standards Australia (as AS ISO/IEC 42001:2023). It is not included in training courses. The exam only covers material delivered in the course, but having a copy is recommended as a professional reference.
Is there an ISO 42001 checklist?
Yes, a practical ISO 42001 implementation checklist works through all 38 Annex A controls across the nine objectives (A.2 to A.10), from AI policy and roles through to data management, transparency, and ongoing monitoring.
Ready to implement ISO 42001?
The PECB ISO 42001 Lead Implementer course covers every Annex A control with implementation templates, worked examples, and certification exam preparation, self-paced eLearning with exam voucher included.
Authorised PECB Training Partner
While you're here
Want to get certified?
Turn your free resources into a recognised professional credential. PECB courses go from Foundation all the way through to Lead Implementer and Lead Auditor: starting at $399 AUD.