Achieving ISO/IEC 42001 certification requires more than writing a few AI policies. Organizations need documented evidence that they have established, implemented, maintained, and continually improved an Artificial Intelligence Management System (AIMS).
That includes documentation covering AI governance, risk management, impact assessments, controls, responsibilities, monitoring, audits, and continual improvement.
But there is an important distinction:
ISO 42001 does not require every organization to create the same number of standalone documents.
The amount and type of documented information depend on factors such as the organization’s size, activities, AI systems, complexity, and risks.
What Documents Are Required for ISO 42001?
ISO 42001 requires organizations to maintain documented information necessary for the effectiveness of their AIMS. The core documentation generally falls into four areas:
- AI Management System documentation
- AI risk and impact documentation
- AI governance and control documentation
- Evidence demonstrating that the AIMS is operating
The objective isn’t to create as many documents as possible. It is to create enough documented information to demonstrate that AI governance is defined, implemented, monitored, and continually improved.
ISO 42001 Documentation Checklist
1. AIMS Scope
The AI Management System scope defines what is covered by your ISO 42001 program. It should establish the relevant organizational boundaries, AI activities, systems, processes, locations, and services included within the AIMS. A clearly defined scope prevents confusion about which AI systems and processes must be governed.
2. AI Policy
The AI Policy establishes management’s commitment to responsible AI governance. It should provide direction for how the organization manages AI-related risks, responsibilities, objectives, and applicable requirements. However, a policy alone is not enough. Auditors will expect evidence that the commitments described in the policy are actually implemented.
3. AI Roles and Responsibilities
ISO 42001 requires organizations to establish appropriate responsibilities and authorities for the AIMS. Documentation should make it clear:
- Who owns AI governance?
- Who manages AI risks?
- Who approves AI systems?
- Who performs assessments?
- Who monitors AI systems?
- Who handles AI-related incidents?
AI governance often spans security, legal, compliance, engineering, product, and executive teams, making clearly defined accountability essential.
4. AI Objectives
Organizations should establish measurable AI-related objectives and define how those objectives will be monitored. Objectives could address areas such as:
- AI risk assessment
- AI inventory coverage
- AI incident management
- Employee training
- Third-party AI assessments
- AI governance maturity
The important point is that objectives should be measurable enough to demonstrate progress.
5. AI Risk Assessment and Risk Treatment
Risk management is at the heart of ISO 42001. Organizations need a defined AI risk assessment methodology explaining how AI risks are identified, analyzed, evaluated, and treated. They should also maintain records of actual risk assessments and document how identified risks are addressed. Typical AI risks may involve:
- Privacy
- Security
- Bias
- Transparency
- Explainability
- Reliability
- Data quality
- Regulatory compliance
- Third-party AI
- Human oversight
A useful risk management structure connects:
Risk → Risk Owner → Treatment → Control → Evidence
6. AI System Impact Assessment
AI systems can affect individuals, groups, organizations, and society in ways that traditional information security assessments may not fully capture. An AI System Impact Assessment helps organizations evaluate these potential consequences.
Depending on the use case, assessments may consider issues involving privacy, fairness, safety, transparency, human autonomy, and other relevant impacts. The assessment should be proportionate to the AI system and its intended use.
7. Statement of Applicability
The Statement of Applicability (SoA) documents which applicable controls have been selected and provides the rationale for their inclusion or exclusion. For ISO 42001, this is particularly important because Annex A introduces AI-specific controls.
The SoA should connect applicable controls to the organization’s AI risks, objectives, and implementation evidence.
8. AI System and Data Documentation
Organizations need visibility into the AI systems they develop, deploy, or use. An AI inventory can help establish:
- What AI systems exist
- Who owns them
- What they are used for
- What data they process
- What third parties support them
- What risks they present
Organizations should also maintain appropriate documentation around AI-related data, including data sources, quality, provenance, usage, and governance.
You cannot effectively govern AI that you cannot identify.
9. AI Lifecycle and Human Oversight Documentation
AI governance should extend across the AI lifecycle, from development and validation through deployment, monitoring, changes, and retirement. Organizations should document appropriate governance around:
- AI development
- Validation and testing
- Deployment
- Monitoring
- Change management
- Human oversight
- Exceptions and escalation
This becomes especially important for AI systems involved in consequential decisions or customer-facing processes.
10. Training and Competence Records
Organizations need evidence that people responsible for the AIMS have the appropriate competence. This may include:
- AI governance training
- Security training
- Role-specific qualifications
- Awareness programs
- Competency records
The documentation should demonstrate that personnel understand the responsibilities associated with their roles.
11. Monitoring and Measurement Records
An AIMS cannot remain static. Organizations should establish appropriate methods for monitoring and measuring the performance of their AI Management System. Records may include:
- AI risk metrics
- Control performance
- AI incidents
- Governance objectives
- AI system monitoring
- Compliance performance
These records help demonstrate that AI governance is actively managed rather than reviewed only before an audit.
12. Internal Audit and Management Review Records
Organizations preparing for certification should maintain evidence of internal audits and management reviews. Internal audits evaluate whether the AIMS meets applicable requirements and is effectively implemented.
Management reviews demonstrate leadership involvement in evaluating the performance and continued suitability of the AIMS. Together, these records provide evidence that the organization is actively evaluating its AI governance program.
13. Corrective Action Records
When an organization identifies a nonconformity or governance weakness, it needs to demonstrate how the issue was addressed. Corrective action records should show:
Issue → Root cause → Corrective action → Owner → Completion → Effectiveness
This creates evidence of continual improvement, rather than simply documenting problems.
What About ISO 42001 Annex A Documentation?
Annex A contains AI-specific controls covering areas such as:
- Policies related to AI
- Internal organization
- Resources for AI systems
- Assessing impacts of AI systems
- AI system lifecycle
- Data for AI systems
- Information for interested parties
- Use of AI systems
- Third-party and supplier relationships
A common misconception is that every Annex A control requires its own standalone document.
It doesn’t.
Organizations can often address multiple controls through integrated policies, procedures, assessments, registers, and operational records.
The better question is:
What evidence demonstrates that this applicable control is implemented and operating effectively?
That approach prevents organizations from creating unnecessary documentation simply to satisfy a checklist.
Mandatory Documents vs. Evidence: What’s the Difference?
This distinction is critical for ISO 42001. A policy or procedure explains what the organization intends to do. A record demonstrates that it actually did it.
For example:
AI Risk Management Methodology
Explains how risks are assessed.
AI Risk Assessment
Demonstrates that a specific AI system was assessed.
Similarly:
AI Incident Response Procedure
Defines how an incident should be handled.
AI Incident Record
Demonstrates how an actual incident was handled.
Auditors need evidence of implementation, not just beautifully written documents.
How to Avoid an ISO 42001 Documentation Nightmare
The biggest mistake organizations make is treating ISO 42001 as a documentation project. Instead, build documentation around your existing governance processes.
- Start with your AI inventory: Identify the AI systems your organization develops, deploys, integrates, or uses.
- Define your AIMS scope: Determine exactly what falls within your certification boundary.
- Perform a gap assessment: Identify weaknesses across governance, risk, controls, impact assessments, documentation, and evidence.
- Map requirements to existing processes: Where existing ISO 27001, SOC 2, privacy, security, or risk processes already address requirements, reuse them where appropriate.
- Automate evidence management: Centralize controls, evidence, risks, and remediation rather than managing ISO 42001 through disconnected spreadsheets and email threads.
How Accorian Helps Leading Organizations Prepare for ISO 42001
ISO 42001 implementation requires more than documentation. Organizations need to build an AIMS that works across AI governance, cybersecurity, risk management, compliance, and operations. Accorian supports organizations through:
- ISO 42001 gap assessments
- AI governance maturity assessments
- AIMS development and implementation
- AI risk assessments
- AI impact assessments
- Control mapping
- Policy and procedure development
- Audit readiness
- Certification support
Accorian combines this expertise with GORICO, its AI-enabled GRC platform, which centralizes control documentation, automates evidence collection, supports structured workflows, and improves visibility across stakeholders. This matters because ISO 42001 shouldn’t end when the certificate is issued.
AI systems evolve. Risks change. Regulations change. Vendors change. Your governance needs to keep up.
GORICO helps organizations move from manual, fragmented compliance management toward a more continuous approach to AI governance and evidence management.
ISO 42001 Documentation: Final Checklist
Before beginning certification, organizations should evaluate whether they have appropriate documented information covering:
- AIMS scope
- AI policy
- AI roles and responsibilities
- AI objectives
- AI risk methodology
- AI risk assessments
- Risk treatment
- Statement of Applicability
- AI impact assessments
- AI inventory
- Data governance
- AI lifecycle governance
- Human oversight
- Training and competence
- Monitoring and measurement
- Internal audits
- Management reviews
- Corrective actions
- Applicable Annex A controls
- Supporting operational evidence
The goal isn’t to create 20, 30, or 40 disconnected documents.
The goal is to create an AI Management System that can demonstrate how your organization identifies risk, governs AI, implements controls, and continuously improves.
Ready to determine whether your organization is ISO 42001 ready?
Accorian helps organizations move from AI governance gaps to an audit-ready AIMS, combining expert guidance with GORICO-powered evidence and compliance management.
Talk to an Accorian ISO 42001 expert today.



