ISO 42001 GOVERNANCE

AI policy

Part of: Annex A.2: Policies Related to AI

Description

Documented policy defining organizational approach to AI development, deployment, and use aligned with values and legal obligations.

Implementation Guidance

Policy Structure

Draft a formal AI policy covering: purpose and scope, ethical principles (fairness, transparency, accountability, privacy), risk appetite statement, roles and responsibilities, and compliance obligations (EU AI Act, sector-specific regulations).

Approval and Governance

Obtain board or executive committee approval with documented sign-off. Assign a policy owner responsible for annual review and updates triggered by regulatory changes, incidents, or strategic shifts.

Integration

Align AI policy with existing corporate policies (information security, data privacy, procurement, HR). Reference ISO 42001 clause requirements and map policy sections to Annex A controls.

Evidence Requirements

  • Board-approved AI policy document with version control
  • Policy review schedule and update history
  • Executive sign-off records
  • Policy mapping to regulatory requirements

Related Controls

AI Acceptable Use Policy