[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-iso-42001-ai-policy-for-a-software-company-what-clause-5-2-asks-for-the-ten-sections-the-ai-act-duties-it-names-the-mistakes-an-auditor-flags-and-a-page-that-writes-it":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-iso-42001-ai-policy-for-a-software-company-what-clause-5-2-asks-for-the-ten-sections-the-ai-act-duties-it-names-the-mistakes-an-auditor-flags-and-a-page-that-writes-it","The ISO 42001 AI policy for a software company: what Clause 5.2 asks for, the ten sections, the AI Act duties it names, the mistakes an auditor flags, and a page that writes it","Clause 5.2 of ISO\u002FIEC 42001 asks top management for an AI policy that fits what the company uses AI for, gives the frame for the AI objectives, commits to the requirements that apply and to improving the system, is documented, communicated and available, and says how it sits beside the other policies. Three Annex A controls, A.2.2, A.2.3 and A.2.4, ask for the policy, its alignment with the other policies and its review. A short AI policy for a software company runs to ten sections: purpose, scope, position, the uses ruled out, accountability, objectives, the requirements that apply, the other policies, communication and review. The requirements section is where the AI Act enters: the literacy duty of Article 4, the transparency duties of Article 50 where the company generates content, and a recorded high-risk determination per system that the policy itself never asserts. A free page writes the policy from eleven answers in six languages.","2026-09-13",{"who":10,"when":11,"do":12},"Top management of a software company that builds AI into its product or uses others' AI in its work, and the person who runs the AI management system for them; the AI policy is the first document an ISO 42001 auditor asks for and the one every decision to build, buy or rely on an AI system refers back to.","Before the impact assessments and the inventory are started, because both are promised in it, and before the first internal audit, where Clause 5.2 is checked against the approval, the communication record, the objectives and the alignment with the security and data protection policies; then at every management review and whenever a new AI capability, a changed purpose or a moved regulatory position calls for it.","Write two pages in ten sections in the company's own words, state the position and the uses ruled out, name who approves it and who runs the system, set three to five measurable objectives, name the AI Act duties that apply without classifying any system in the policy, say how it sits beside the security and data protection policies, and publish it where every joiner reads it; the free page writes the draft from eleven answers.","\nThe AI policy is the shortest document in an ISO 42001 system and the one most often written wrong, because the easy version is the information security policy with the nouns changed. That version reads plausibly and answers the wrong standard: an AI management system asks at Clause 5.2 for a policy that fits what the company uses AI for, gives the frame for the AI objectives, commits to the requirements that apply and to improving the system, is documented, communicated and available, and, unlike its 27001 cousin, says how it sits beside the other policies of the organisation. Three Annex A controls carry the same three ideas: A.2.2 asks for the policy, A.2.3 for its alignment with the other policies, A.2.4 for its review. This article reads the clause for a software company, sets out the ten sections a two-page AI policy carries, names the AI Act duties the policy has to mention and the one classification it must not make, lists what an auditor flags, and describes the [free page](\u002Fiso-42001\u002Fai-policy) that writes the policy from eleven answers in six languages.\n\n## What the clause asks for, and where it differs from the security policy\n\nFour of the things Clause 5.2 asks for are about content and three about handling, and the content is where the AI policy parts from the security policy. Fit for purpose means the policy names what the company actually uses AI for, support triage or contract review or code assistance, and whether it builds the systems or uses others', because the duties differ. The frame for the objectives means the policy says which objectives of Clause 6.2 it sets, and an AI objective is about intended use, impact, human review, data provenance, incidents and literacy rather than about confidentiality and availability. The commitment to the requirements that apply is where the regulation enters, since the AI Act puts duties on a provider and a deployer that no security policy mentions. And the alignment with the other policies is a section of its own: an AI system is still an information system under the security policy, its data is still data under the data protection policy, its provider is still a supplier under the supplier policy, and the AI policy has to say what happens where they seem to disagree. The handling is the same as in 27001: documented under Clause 7.5 with an owner, a version and an approval, communicated so that a new joiner can say what it asks of them, and available to a customer or an auditor on request.\n\n## The ten sections of a short AI policy\n\nPurpose: what the company uses AI for today and who is accountable, in one paragraph that names the uses. Scope: which systems, the ones built, bought, embedded or operated, and which people. Position: the handful of sentences that make the policy the company's own, that AI is used where the work gets better and its behaviour can be explained, that every system has a stated intended use and a named owner, that a human stays able to review and overturn an output that affects a person, that impact is assessed before reliance and again on change, that personal data is used only on a recorded lawful basis, and that generated content is marked and checked. The uses ruled out: the decisions the company will not delegate to a system, written down so that the decision exists, however obvious it seems. Accountability: who owns and approves the policy, who runs the system day to day, and that every system has an owner in the inventory. Objectives: three to five measurable lines. The requirements that apply: the section below. The relationship to the other policies: alongside, not instead, with a route for conflicts. Communication and availability: onboarding, the literacy measures, and availability on request. Review: the cycle and the three triggers, a materially new capability, a changed purpose, a moved regulatory position.\n\n## The AI Act duties the policy names, and the one thing it must not say\n\nThe requirements section is short and specific. The AI literacy duty of Article 4 binds every provider and deployer, so the policy commits the company to giving everyone who operates or relies on a system the knowledge their role needs, and points to the [literacy record](\u002Fai-act\u002Fai-literacy) that shows it. Where the company builds systems, it commits to the provider's duties as they apply to each system's classification and to the commitments it gives the customers who deploy them; where it uses others' systems, to the deployer's duties and to the instructions for use of the provider it relies on. Where it generates text, images or code, the transparency duties of Article 50 apply to what it builds or uses. Where it processes personal data, data protection law applies, the impact assessment included where the processing is likely to result in a high risk. And for each system, the policy commits to a recorded determination of whether it is high-risk under the AI Act, made on the facts of that system and kept with its inventory entry. What the policy must not do is make that determination itself: a sentence saying \"our systems are not high-risk\" is a legal conclusion about facts the policy does not hold, and an auditor reads it as exactly that. The [high-risk determination](\u002Fai-act\u002Fhigh-risk) is a page of its own, per system, and the [fundamental rights impact assessment](\u002Fai-act\u002Ffundamental-rights-impact-assessment) follows where the answer is yes.\n\n## The mistakes an auditor flags\n\nThe security policy with the nouns changed, which has no position on AI, no uses ruled out and no inventory. \"Responsible AI\" as adjectives, with no objective that can be measured and nothing in the management review that measures it. A classification in the policy, high-risk or not, asserted for every system at once. No route for a person affected by an output to reach a human who can overturn it, in a company whose systems affect people. Silence on generative AI in a company where everyone uses it. No sentence on how the policy sits beside the security, data protection and supplier policies, so that the first conflict is settled by whoever notices it. And the usual three: no approval, no communication record, no review since the first version. Each is a finding at the first audit, and each is avoided by writing the ten sections and dating them.\n\n## What to do with it\n\nAnswer the eleven questions on the [free page](\u002Fiso-42001\u002Fai-policy): what the company uses AI for, whether it builds systems, uses others' or both, whether outputs affect decisions about people, whether the systems process personal data, whether it uses generative AI, the uses it rules out, who runs the system, who approves the policy, the review cycle and the objectives it will measure. The page writes the ten sections in plain words, names the AI Act duties the answers call for and the determination each system still needs, and says how the policy sits beside the others. Edit it to sound like the company, have the approver sign and date it, publish it where every joiner reads it, and start the inventory and the impact assessments it promises. StandardOS writes the AI policy and the impact assessment, data governance and supplier policies under it from the same answers, versioned, and turns the inventory, the assessments and the literacy records into rows and dates; the [Annex A controls](\u002Fiso-42001\u002Fcontrols) say what each of the three policy controls asks for in StandardOS's words.\n",1789383982925]