← Back to blog

ISO 42001 Annex A controls: the 38 controls, explained

ISO 42001 Annex A controls: the 38 controls, explained

Annex A is where ISO 42001 gets concrete. This guide walks through all 38 AI controls across the 9 objectives, how you choose which apply to your organisation, and how they connect to the rest of the standard. It pairs with our guide to ISO 42001 requirements.

AramGRC Team·ISO 42001 & Assurance·September 18, 2026·11 min read

What is Annex A of ISO 42001?

Annex A of ISO/IEC 42001 is the catalogue of AI-specific controls — 38 controls organised under 9 control objectives (categories A.2 to A.10). Where clauses 4–10 are the mandatory management-system requirements, Annex A is the menu of controls you draw from to treat your AI risks. You select the controls that apply to your context and justify what you include and exclude — the same Statement-of-Applicability logic used in ISO 27001.

Clauses vs Annex A: what's the difference?

The clauses tell you to run a management system; Annex A tells you what specific AI controls that system can deploy. Clauses 4–10 are required for every certified organisation. Annex A controls are selected based on the risks and impacts your AI systems actually carry, so two certified organisations can have very different control sets. The bridge between them is your risk and impact assessment: it decides which Annex A controls are in scope.

The 9 Annex A control objectives

Each objective groups related controls. Here is what each category covers:

  • A.2 Policies related to AI — Establishing, approving and maintaining an AI policy and supporting topic-specific policies.
  • A.3 Internal organisation — Defining AI roles, responsibilities and reporting lines, including accountability for AI risk.
  • A.4 Resources for AI systems — Documenting the resources — data, tooling, compute, and human competence — that AI systems depend on.
  • A.5 Assessing impacts of AI systems — Conducting AI system impact assessments on individuals, groups and society, not just the business.
  • A.6 AI system life cycle — Responsible design, development, verification, deployment and operation across the AI lifecycle.
  • A.7 Data for AI systems — Managing data quality, provenance, preparation and governance for training and operation.
  • A.8 Information for interested parties — Providing transparency and documentation to users, customers and regulators.
  • A.9 Use of AI systems — Ensuring AI is used for its intended purpose, with human oversight and responsible operation.
  • A.10 Third-party and customer relationships — Due diligence and clear allocation of responsibilities with suppliers, foundation-model providers and customers.

How you choose which controls apply

You don't implement all 38 controls by default. Instead, your risk and impact assessment identifies the AI risks that matter for your systems, and you select the Annex A controls that treat them — documenting your reasoning in a Statement of Applicability. A low-risk internal productivity tool and a high-risk credit-decision model will justify very different control sets. The A.5 impact-assessment controls lean directly on ISO/IEC 42005, the companion standard for AI system impact assessments.

Annex B, C and D: the supporting annexes

Annex A doesn't stand alone. Annex B gives control-by-control implementation guidance — how to actually operationalise each control. Annex C catalogues potential AI-related objectives and risk sources (bias, security, explainability, fairness) to feed your risk assessment. Annex D covers applying the AIMS across specific domains and sectors. Read together, they turn the control list into a working programme.

Common Annex A mistakes

The nonconformities auditors see most: copy-pasting the same control set across systems with very different risk profiles; excluding controls without a documented justification; and claiming a control is in place with no evidence that it operates. Annex A rewards specificity — a control mapped to a real risk, with a named owner and current evidence, is worth more than a fully populated checklist that no one maintains.

Key takeaways

  • Annex A contains 38 AI controls across 9 objectives (categories A.2–A.10).
  • Clauses 4–10 are mandatory; Annex A controls are selected based on your AI risks.
  • Your risk and impact assessment decides which controls apply, documented in a Statement of Applicability.
  • Annex B (guidance), Annex C (risk sources) and Annex D (sectors) support Annex A.
  • Evidence that a control operates matters more than simply listing it.

How AramGRC helps

AramGRC runs the ISO/IEC 42001 gap assessment that scores your maturity against every applicable Annex A control and produces a certification-ready roadmap and Statement of Applicability — so you walk into the audit knowing which controls apply and that each is evidenced. See our ISO 42001 checklist and complete ISO 42001 guide.

Frequently asked questions

How many controls are in ISO 42001 Annex A?+

Annex A contains 38 controls organised under 9 control objectives (categories A.2 to A.10).

Are all ISO 42001 Annex A controls mandatory?+

No. Unlike clauses 4–10, Annex A controls are selected based on your AI risks. You justify which you include and exclude in a Statement of Applicability.

What is the difference between ISO 42001 clauses and Annex A?+

Clauses 4–10 are the mandatory management-system requirements; Annex A is the catalogue of AI-specific controls you choose from to treat your risks.

What are the 9 Annex A control objectives?+

AI policies, internal organisation, resources for AI systems, assessing impacts, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships.

What is a Statement of Applicability in ISO 42001?+

A document recording which Annex A controls you have applied, which you have excluded, and the justification for each — the same concept used in ISO 27001.

How do I decide which Annex A controls apply?+

Your risk and impact assessment identifies the risks your AI systems carry, and you select the controls that treat those risks proportionately.

What is Annex B in ISO 42001?+

Annex B provides implementation guidance for the Annex A controls — practical detail on how to operationalise each one.

How does Annex A relate to ISO 42005?+

The A.5 controls require AI system impact assessments, and ISO/IEC 42005 is the companion standard that gives the methodology for conducting them.

ISO 42001Annex AISO 42001 controlsAIMSAI Governance

The ISO 42001 series

ISO 42001 Certification

Start here — what ISO 42001 is, what it requires, costs, and how to get certified.

ISO/IEC 42001: The Complete Guide to the AI Management System Standard

The world's first certifiable AI management system standard — requirements, Annex A controls, certification, cost, training and India relevance.

What Is ISO/IEC 42001? The AI Management System Standard Explained

The standard explained in plain language.

ISO 42001 Requirements

The clauses and Annex A controls ISO 42001 asks for.

ISO 42001 Annex A Controls: All 38 Controls Across 9 Objectives

The 38 AI controls across 9 objectives (A.2–A.10), and how you select which apply.

You're here

ISO 42001 Certification Cost

What ISO 42001 certification costs, including in India.

ISO 42001 Checklist

A step-by-step readiness checklist for certification.

ISO 42001 Documentation & Toolkit: Mandatory Policies, Templates & Records

The mandatory policies, procedures and records — and what a good ISO 42001 toolkit includes.

ISO 42001 vs ISO 27001

How the AI and information-security standards differ.

How to Get ISO 42001 Certified

The certification process, step by step.

ISO 42001 Lead Auditor

Courses and credentials for individuals.

ISO 42001 Lead Implementer: Role, Training & Certification

The role that builds and runs the AIMS — course, exam and how it differs from Lead Auditor.

ISO 42001 Certification in India: One AIMS for DPDP, MeitY and RBI FREE-AI

DPDP Act, MeitY guidelines and RBI FREE-AI, mapped to one AIMS.

ISO 42001 vs NIST AI RMF vs the EU AI Act: How They Map

A standard, a voluntary framework and a law — how they fit together.

ISO 42001 for Startups & SMEs: A Right-Sized Path to AI Governance

How smaller AI companies scope, cost and pursue certification proportionately.

ISO 42001 Certified Companies: Who's Certified & Why It Matters

Who is certifying, why the list is growing, and how to verify a certificate.

WhatsApp