ISO 42001 documentation and toolkit: what you actually need
ISO 42001 runs on documented information — but the goal is a working management system, not a binder of templates. This guide covers the documents ISO 42001 requires, what a good toolkit includes, and where templates help (and where they don't). It pairs with our ISO 42001 checklist.
AramGRC Team·ISO 42001 & Assurance·September 18, 2026·11 min read
What documentation does ISO 42001 require?
ISO 42001 requires documented information under clause 7.5 — the policies, procedures, and records that show your AI management system exists and operates. It deliberately does not prescribe a rigid document list; instead it requires you to maintain the documentation needed to run the system and prove it works. In practice, that resolves into a recognisable core set of documents, plus the ongoing records that evidence them.
The core ISO 42001 documents
Most certified AI management systems include the following:
AI policy — The top-level statement of intent, approved by leadership, setting your AI governance objectives.
Scope statement — Defining the boundary of the AIMS: which AI systems, business units and locations are covered.
AI risk assessment & treatment methodology — How you identify, evaluate and treat AI risks, with the records of having done so.
AI system impact assessment procedure — How you assess impacts on individuals and society, with completed assessments as records.
Statement of Applicability — Which Annex A controls apply, which are excluded, and why.
Roles & responsibilities — Who is accountable for AI governance, with competence records for those individuals.
AI system inventory — A current register of the AI systems in scope, their risk level and owners.
Supplier & third-party due diligence — Records for foundation-model and vendor AI, with contractual AI clauses.
Operational procedures — The controls that govern the AI lifecycle in practice.
Monitoring, internal audit & management review records — Evidence the system is measured, audited and improved.
Incident & nonconformity records — What went wrong, and the corrective action taken.
Mandatory documents vs helpful documents
Some documented information is explicitly required — an AI policy, the scope, the risk and impact assessment results, and evidence of monitoring, internal audit and management review. Others, like a detailed AI system inventory or a supplier register, are not named word-for-word but are effectively unavoidable because you cannot evidence the required clauses without them. Treat the named items as mandatory and the rest as practically necessary.
What a good ISO 42001 toolkit includes
An ISO 42001 toolkit is a starter pack of templates — policy templates, a risk-assessment template, an impact-assessment template, a Statement of Applicability template, and audit checklists. A good toolkit accelerates the writing phase and makes sure you don't miss a required document. The caution: a template is a starting point, not evidence. Auditors do not certify your templates; they sample your AI systems and ask for proof the controls operate. A toolkit gets you to a first draft faster — it does not get you certified on its own.
Reuse what you already have
If you hold ISO 27001 or ISO 9001, you already have much of the document-control, risk-register, internal-audit and management-review machinery ISO 42001 needs. Extend those documents to cover AI rather than creating a parallel set — the standards share a structure precisely so you can integrate them. This is usually the single biggest time-saver in building the documentation.
Common documentation mistakes
The two failure modes we see most: treating documentation as the goal (a beautiful policy no one follows is a nonconformity waiting to happen), and letting documents drift (an AI system inventory that is out of date within a quarter). Documentation earns its keep only when it reflects what the organisation actually does — and is kept current.
Key takeaways
ISO 42001 requires documented information under clause 7.5, not a fixed template list.
The core set: AI policy, scope, risk and impact assessments, Statement of Applicability, inventory, and operating records.
A toolkit of templates speeds up drafting but is not a substitute for evidence the controls operate.
Reuse ISO 27001 / ISO 9001 documentation rather than duplicating it.
Keep documents current — stale records are a common audit finding.
How AramGRC helps
AramGRC provides the ISO/IEC 42001 documentation set and gap assessment tailored to your AI systems — the policies, procedures and Statement of Applicability, plus the evidence trail auditors actually sample — so you build a working system, not just a binder. See the ISO 42001 checklist and requirements guide.
Frequently asked questions
What documentation does ISO 42001 require?+
Documented information under clause 7.5 — including an AI policy, scope, risk and impact assessment results, a Statement of Applicability, and records of monitoring, internal audit and management review — plus the supporting documents needed to run the system.
Is there a mandatory ISO 42001 document list?+
No fixed list. The standard requires the documented information needed to operate and evidence the AIMS, which resolves into a recognisable core set in practice.
What is an ISO 42001 toolkit?+
A starter pack of templates — policies, risk and impact assessment templates, a Statement of Applicability, and checklists — that speeds up building your documentation. It is a starting point, not certification evidence.
Are ISO 42001 templates enough to get certified?+
No. Templates help you draft documents faster, but auditors certify a working management system and sample evidence that controls operate, not the templates themselves.
What is a Statement of Applicability?+
A document listing which Annex A controls you have applied, which you have excluded, and the justification for each.
Can I reuse my ISO 27001 documentation for ISO 42001?+
Yes. Because the standards share a structure, you can extend existing document control, risk registers, internal audit and management review to cover AI rather than duplicating them.
What is the AI policy in ISO 42001?+
The top-level, leadership-approved statement of your organisation's AI governance intent and objectives, required under clause 5.
How much documentation does ISO 42001 need?+
Enough to operate and evidence the system — proportionate to your AI risk. Over-documentation is as much a risk as under-documentation; the test is whether the documents reflect what you actually do.
ISO 42001ISO 42001 toolkitISO 42001 documentationISO 42001 templatesAIMS