ISO 42001 Annex A controls: the 38 controls, explained
Annex A is where ISO 42001 gets concrete. This guide walks through all 38 AI controls across the 9 objectives, how you choose which apply to your organisation, and how they connect to the rest of the standard. It pairs with our guide to ISO 42001 requirements.
AramGRC Team·ISO 42001 & Assurance·September 18, 2026·11 min read
What is Annex A of ISO 42001?
Annex A of ISO/IEC 42001 is the catalogue of AI-specific controls — 38 controls organised under 9 control objectives (categories A.2 to A.10). Where clauses 4–10 are the mandatory management-system requirements, Annex A is the menu of controls you draw from to treat your AI risks. You select the controls that apply to your context and justify what you include and exclude — the same Statement-of-Applicability logic used in ISO 27001.
Clauses vs Annex A: what's the difference?
The clauses tell you to run a management system; Annex A tells you what specific AI controls that system can deploy. Clauses 4–10 are required for every certified organisation. Annex A controls are selected based on the risks and impacts your AI systems actually carry, so two certified organisations can have very different control sets. The bridge between them is your risk and impact assessment: it decides which Annex A controls are in scope.
The 9 Annex A control objectives
Each objective groups related controls. Here is what each category covers:
A.2 Policies related to AI — Establishing, approving and maintaining an AI policy and supporting topic-specific policies.
A.3 Internal organisation — Defining AI roles, responsibilities and reporting lines, including accountability for AI risk.
A.4 Resources for AI systems — Documenting the resources — data, tooling, compute, and human competence — that AI systems depend on.
A.5 Assessing impacts of AI systems — Conducting AI system impact assessments on individuals, groups and society, not just the business.
A.6 AI system life cycle — Responsible design, development, verification, deployment and operation across the AI lifecycle.
A.7 Data for AI systems — Managing data quality, provenance, preparation and governance for training and operation.
A.8 Information for interested parties — Providing transparency and documentation to users, customers and regulators.
A.9 Use of AI systems — Ensuring AI is used for its intended purpose, with human oversight and responsible operation.
A.10 Third-party and customer relationships — Due diligence and clear allocation of responsibilities with suppliers, foundation-model providers and customers.
How you choose which controls apply
You don't implement all 38 controls by default. Instead, your risk and impact assessment identifies the AI risks that matter for your systems, and you select the Annex A controls that treat them — documenting your reasoning in a Statement of Applicability. A low-risk internal productivity tool and a high-risk credit-decision model will justify very different control sets. The A.5 impact-assessment controls lean directly on ISO/IEC 42005, the companion standard for AI system impact assessments.
Annex B, C and D: the supporting annexes
Annex A doesn't stand alone. Annex B gives control-by-control implementation guidance — how to actually operationalise each control. Annex C catalogues potential AI-related objectives and risk sources (bias, security, explainability, fairness) to feed your risk assessment. Annex D covers applying the AIMS across specific domains and sectors. Read together, they turn the control list into a working programme.
Common Annex A mistakes
The nonconformities auditors see most: copy-pasting the same control set across systems with very different risk profiles; excluding controls without a documented justification; and claiming a control is in place with no evidence that it operates. Annex A rewards specificity — a control mapped to a real risk, with a named owner and current evidence, is worth more than a fully populated checklist that no one maintains.
Key takeaways
Annex A contains 38 AI controls across 9 objectives (categories A.2–A.10).
Clauses 4–10 are mandatory; Annex A controls are selected based on your AI risks.
Your risk and impact assessment decides which controls apply, documented in a Statement of Applicability.
Annex B (guidance), Annex C (risk sources) and Annex D (sectors) support Annex A.
Evidence that a control operates matters more than simply listing it.
How AramGRC helps
AramGRC runs the ISO/IEC 42001 gap assessment that scores your maturity against every applicable Annex A control and produces a certification-ready roadmap and Statement of Applicability — so you walk into the audit knowing which controls apply and that each is evidenced. See our ISO 42001 checklist and complete ISO 42001 guide.
Frequently asked questions
How many controls are in ISO 42001 Annex A?+
Annex A contains 38 controls organised under 9 control objectives (categories A.2 to A.10).
Are all ISO 42001 Annex A controls mandatory?+
No. Unlike clauses 4–10, Annex A controls are selected based on your AI risks. You justify which you include and exclude in a Statement of Applicability.
What is the difference between ISO 42001 clauses and Annex A?+
Clauses 4–10 are the mandatory management-system requirements; Annex A is the catalogue of AI-specific controls you choose from to treat your risks.
What are the 9 Annex A control objectives?+
AI policies, internal organisation, resources for AI systems, assessing impacts, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships.
What is a Statement of Applicability in ISO 42001?+
A document recording which Annex A controls you have applied, which you have excluded, and the justification for each — the same concept used in ISO 27001.
How do I decide which Annex A controls apply?+
Your risk and impact assessment identifies the risks your AI systems carry, and you select the controls that treat those risks proportionately.
What is Annex B in ISO 42001?+
Annex B provides implementation guidance for the Annex A controls — practical detail on how to operationalise each one.
How does Annex A relate to ISO 42005?+
The A.5 controls require AI system impact assessments, and ISO/IEC 42005 is the companion standard that gives the methodology for conducting them.
ISO 42001Annex AISO 42001 controlsAIMSAI Governance