Annex A.2
ISO 42001 GOVERNANCE

Policies Related to AI

Description

Covers establishment of AI-specific policies addressing ethical use, acceptable use, human oversight, and stakeholder engagement throughout the AI lifecycle.

Controls

IDControlDescription
A.2.1AI policyDocumented policy defining organizational approach to AI development, deployment, and use aligned with values and legal ...
A.2.2Acceptable use policy for AIPolicy defining permitted and prohibited uses of AI systems, including boundaries for autonomous decision-making and hum...
A.2.3Human oversight of AI systemsPolicy establishing requirements for meaningful human oversight, intervention mechanisms, and escalation procedures for ...
A.2.4Stakeholder engagement in AI policyPolicy ensuring diverse stakeholder participation in AI policy development, including affected communities and domain ex...

Implementation Guidance

Develop comprehensive, board-approved AI policy framework addressing ethical principles, risk appetite, and compliance requirements. Define clear boundaries for AI use cases with explicit prohibited applications (e.g., social scoring, unauthorized surveillance). Establish oversight mechanisms proportionate to AI system risk level, including human-in-the-loop requirements for high-risk decisions.

Evidence Requirements

Approved AI policy suite

Policy review and approval records

Stakeholder consultation documentation

Policy dissemination and acknowledgment records