ISO/IEC 42001 Readiness: 38 Controls, One Honest Score
Defensible AI

ISO/IEC 42001 Readiness: 38 Controls, One Honest Score

The AI management system standard is auditable, certifiable — and widely misrepresented. Here is what readiness actually consists of: 38 Annex A controls, a Statement of Applicability with a justification for every inclusion and exclusion, 12 clause artifacts, and a score that only means something because it can say 'not ready'.

AI
AIAgentree Team
AI Governance
July 28, 2026
11 min read

ISO/IEC 42001 Readiness Assessment: Annex A Controls and Statement of Applicability

ISO/IEC 42001:2023 is the international standard for AI management systems (AIMS). Certification readiness consists of: the 38 Annex A controls organized in control groups A.2 through A.10, covering AI policies, internal organization, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships; a Statement of Applicability in which every control is either included or excluded with a documented justification, as required by clause 6.1.3; and the management-system clause artifacts — approximately 12 documents covering scope, policy, risk process, objectives, competence, operation, performance evaluation and improvement. Readiness is preparation for a certification audit; certification is issued only by an accredited certification body. ISO/IEC 42001 conformity is not EU AI Act compliance. AIAgentree implements readiness tracking over all 38 controls with an SoA, clause-artifact tracking, and an honest readiness score.

Share:
TL;DR

ISO/IEC 42001 readiness is three concrete deliverables: 38 Annex A controls assessed, a Statement of Applicability with justified inclusions AND exclusions, and the clause artifacts. A readiness score you cannot fail is not a score.

  • 38 controls, A.2–A.10 — from AI policies through impact assessment to third-party relationships.
  • The SoA is the centerpiece — every control included or excluded, each with a documented justification (clause 6.1.3).
  • 12 clause-artifact documents — the management-system paperwork an auditor reads first.
  • Honesty constraints — readiness ≠ certification, and ISO ≠ EU AI Act compliance. Both distinctions are load-bearing.

There is a tell that separates serious ISO/IEC 42001 preparation from certification theater, and it fits in one question:

"Which Annex A controls did you exclude, and where is that written down?"

Teams doing it right answer instantly — the exclusions, with justifications, are in the Statement of Applicability. Teams doing theater have never excluded anything.

What ISO/IEC 42001 Is (and Is Not)

ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS) — the same management-system architecture as ISO 27001, applied to AI: leadership commitment, risk process, operational controls, performance evaluation, continual improvement. It is certifiable: an accredited body can audit your AIMS and issue a certificate.

Two boundary stakes before anything else, because the market keeps pulling them out. Readiness is not certification — everything in this post prepares you for the audit; the certificate is issued only by an accredited certification body after its own assessment. And ISO/IEC 42001 is not EU AI Act compliance — one is a voluntary management-system standard, the other is binding product law with its own obligations. The overlap is substantial and useful; the equivalence claimed in some vendor decks does not exist. We map the actual overlap in ISO 42001 vs EU AI Act.

The 38 Annex A Controls (A.2–A.10)

Annex A is the control catalog: 38 controls in nine groups. Where the management-system clauses ask "do you run a system?", Annex A asks "do these specific safeguards exist?":

GroupThemeWhat an assessor looks for
A.2Policies related to AIAn AI policy exists, is approved, and is reviewed
A.3Internal organizationRoles, responsibilities, and reporting lines for AI are assigned
A.4Resources for AI systemsData, tooling, human competence and providers are identified and documented
A.5Assessing impacts of AI systemsImpact assessments on individuals, groups and society are performed and recorded
A.6AI system life cycleRequirements, design, verification, deployment, operation and monitoring are managed — with records
A.7Data for AI systemsData acquisition, quality, provenance and preparation are controlled
A.8Information for interested partiesUsers and affected parties get the information they need — including incident reporting paths
A.9Use of AI systemsResponsible-use processes, intended-use boundaries, and objectives are defined
A.10Third-party and customer relationshipsSupplier and customer responsibilities for AI are allocated and managed

Notice how many groups reduce, in evidence terms, to records of decisions about AI systems — A.5's impact assessments, A.6's life-cycle records, A.9's use decisions. This is why decision-level records are the natural evidence substrate for 42001 work: the controls ask for exactly the artifacts a decision-tracing pipeline produces as exhaust.

The Statement of Applicability: Where Honesty Lives

The Statement of Applicability (SoA) is the document clause 6.1.3 requires: a table over all 38 controls in which each one is marked included or excluded — and justified either way. Included controls point at their implementation; excluded controls state why they genuinely do not apply.

The SoA is where certification theater goes to die, because it forces two honest acts. First, exclusions must be argued, not hidden — "A.10 third-party controls excluded because no third parties touch the AI life cycle" is a claim an auditor will test. Second, inclusions must be evidenced — a control marked implemented with no artifact behind it is a finding waiting to happen. An SoA with zero exclusions and zero gaps has almost always been filled in backwards, from the desired score to the claims.

In AIAgentree, the SoA is a first-class object: every control carries its inclusion/exclusion state and justification, and included controls link to their evidence. The readiness score is computed over that — which is why it can genuinely reach ready, and why it can genuinely say not ready. A score that cannot fail is decoration.

The 12 Clause Artifacts

Annex A gets the attention, but a certification audit starts with the management-system clauses (4–10), and those demand documents. In practice the set is about a dozen artifacts:

  • Scope of the AIMS — which systems, sites and activities the management system covers
  • AI policy and objectives — leadership's commitments, and measurable targets
  • Risk assessment and treatment process — how AI risks are identified, scored, and treated
  • The Statement of Applicability — see above; it is both a clause requirement and the Annex A index
  • Competence and awareness records — who is qualified to do what
  • Operational planning and control records — the life-cycle documentation A.6 expects
  • Performance evaluation — internal audit results, management review minutes
  • Nonconformity and corrective-action records — what went wrong and what changed

AIAgentree tracks these as a clause-artifact set — 12 documents with status — so "are we document-complete for stage 1?" is a glance, not an archaeology project.

"If It's Not EU Compliance, Why Bother?"

A reasonable challenge, given the boundary stakes above. Three reasons organizations pursue 42001 readiness anyway:

  • Procurement is converging on it. Enterprise buyers increasingly ask for AIMS evidence the way they ask for ISO 27001 — a certificate, or at least a credible readiness posture, shortens security review.
  • It is the management-system complement to product law. The EU AI Act regulates systems; 42001 organizes the organization around them. The Act's quality-management expectations for providers rhyme with an AIMS, so the work compounds rather than competes — see the EU AI Act flow walk-through for the product-law side.
  • It forces the honesty infrastructure. The SoA's justify-everything discipline and the audit trail behind each control are valuable independent of any certificate — they are the same records that make individual decisions defensible.

Diagnostic question: if an assessor asked for your SoA today, would you be handing over a considered document with justified exclusions — or generating one from scratch under deadline?

A Readiness Path That Fits in a Quarter

Weeks 1–2

Scope and inventory

Define the AIMS scope; list the AI systems inside it. Small honest scope beats broad aspirational scope.

Weeks 3–6

Walk the 38 controls

For each: include or exclude with justification, and attach evidence for inclusions. This drafts your SoA as you go.

Weeks 7–10

Close the clause artifacts

Draft the dozen management-system documents; most are short if the control work is done.

Weeks 11–13

Score honestly, then decide

Run the readiness score, read the not-ready items, and only then decide whether to engage a certification body. Readiness first, certificate second.

Sources & Further Reading

Frequently Asked Questions

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the international standard for AI management systems (AIMS). It applies the classic management-system architecture — leadership, risk process, operational controls, performance evaluation, improvement — to an organization's development and use of AI, with a catalog of 38 controls in Annex A. It is certifiable by accredited bodies.

How many controls does ISO/IEC 42001 Annex A contain?

38 controls, organized into nine groups labelled A.2 through A.10: AI policies, internal organization, resources, impact assessment, AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships. Each control is either implemented with evidence or excluded with a documented justification in the Statement of Applicability.

What is a Statement of Applicability?

The Statement of Applicability (SoA), required by clause 6.1.3, is the document in which an organization declares, for every Annex A control, whether it is included or excluded — with a justification either way, and with included controls pointing at their implementation evidence. It is the centerpiece of both the readiness effort and the certification audit.

Does ISO/IEC 42001 readiness mean we are certified?

No. Readiness means your controls, SoA and clause artifacts are prepared for a certification audit. Certification is granted only by an accredited certification body after its own stage 1 and stage 2 audits. A readiness score — including an honest 'not ready' — tells you whether engaging that body is worth the fee yet.

Is ISO/IEC 42001 certification the same as EU AI Act compliance?

No. ISO/IEC 42001 is a voluntary management-system standard; the EU AI Act is binding law with product-level obligations, deadlines, and penalties. The two overlap substantially — risk management, documentation, oversight — so the work compounds, but conformity with the standard does not discharge the legal obligations, and vendors claiming equivalence are wrong.

How does AIAgentree support ISO/IEC 42001 readiness?

With readiness tracking over all 38 Annex A controls, a first-class Statement of Applicability where every control is included or excluded with a documented justification and evidence links, tracking for the 12 clause-artifact documents, and a readiness score computed honestly over that state — one that can genuinely reach ready, and genuinely say not ready. This supports certification preparation; the certificate itself comes from an accredited body.

Related Topics

Related Articles

AI

AIAgentree Team

AI Governance

The AIAgentree team is building decision tracing infrastructure for AI agents. Our mission is to make AI reasoning visible, auditable, and improvable.

Get an honest readiness score.

Book a 30-minute session: we walk the SoA discipline with your team and show the 38-control tracker, clause artifacts, and the score that can say 'not ready'.

See the Readiness Tracker