Annex A.2
ISO 42001
GOVERNANCE
Policies Related to AI
Description
Covers establishment of AI-specific policies addressing ethical use, acceptable use, human oversight, and stakeholder engagement throughout the AI lifecycle.
Controls
| ID | Control | Description |
|---|---|---|
| A.2.1 | AI policy | Documented policy defining organizational approach to AI development, deployment, and use aligned with values and legal ... |
| A.2.2 | Acceptable use policy for AI | Policy defining permitted and prohibited uses of AI systems, including boundaries for autonomous decision-making and hum... |
| A.2.3 | Human oversight of AI systems | Policy establishing requirements for meaningful human oversight, intervention mechanisms, and escalation procedures for ... |
| A.2.4 | Stakeholder engagement in AI policy | Policy ensuring diverse stakeholder participation in AI policy development, including affected communities and domain ex... |
Implementation Guidance
Develop comprehensive, board-approved AI policy framework addressing ethical principles, risk appetite, and compliance requirements. Define clear boundaries for AI use cases with explicit prohibited applications (e.g., social scoring, unauthorized surveillance). Establish oversight mechanisms proportionate to AI system risk level, including human-in-the-loop requirements for high-risk decisions.
Evidence Requirements
Approved AI policy suite
Policy review and approval records
Stakeholder consultation documentation
Policy dissemination and acknowledgment records