ISO 42001

ISO 42001 · the AI policy

The AI policy, written from eleven answers

Clause 5.2 asks top management for one short AI policy, the first document an auditor reads: what the company uses AI for, its position and objectives, the requirements it commits to, and how it sits beside the security and data protection policies it does not replace, written below from eleven answers.

Do you build AI systems, use others' or both?
Do outputs affect decisions about people?
Do the systems process personal data?
Do you use generative AI?
Review cycle
The objectives the policy sets

Pick the ones you will measure; each becomes a line the management review reports on.

The policy

A short policy is a better one: an auditor reads it for the position, the accountability and the objectives, not for length.

# AI policy: [company]

Owner: [the system owner] · Approved by: [top management] · Review: at least annually

Written on  with the free page on getstandardos.com against Clause 5.2 of ISO/IEC 42001:2023. The wording is StandardOS's own; it is a starting point to approve and communicate, not a final answer, and it states no legal classification of any system.

## Purpose

This policy sets out how [company] develops, procures and uses artificial intelligence, today for [the uses of AI in the business], and who is accountable for it. It is the top document of the AI management system and the one every decision to build, buy or rely on an AI system refers back to.

## Scope

This policy applies to every AI system [company] builds, buys, embeds or operates, to the models and data behind the ones it builds, and to every person acting on behalf of [company] who designs, operates or relies on one.

## Our position

- We use AI where it makes our work better and we can explain what it is doing; where we cannot explain it, we do not rely on it.
- Every AI system has a stated intended use and a named owner; using a system outside that use is a decision someone takes and records, not a default.
- Where an output affects a person, a human able to review and overturn it stays in the loop, and the person affected can ask for that review.
- We assess what a system does to the people it touches before we rely on it, and again when its purpose, its data or its model changes.
- Personal data is used to build, tune or operate a system only on a lawful basis recorded in the record of processing, and never beyond the purpose it was collected for.
- Generated text, images or code are marked as such where a reader could take them for human work, and are checked by a person before they leave the company or reach production.

## Uses we rule out

[company] records here the uses of AI it rules out, however obvious they seem, so that the decision exists in writing; the list is reviewed with this policy.

## Accountability

[top management] owns this policy and approves it. [the system owner] runs the AI management system day to day: the inventory of AI systems, the impact assessments, the objectives and the reporting to top management. Each AI system has a named owner in the inventory, responsible for its intended use, its limits and its assessment.

## Objectives

This policy provides the framework for setting and reviewing the AI objectives. The current objectives, each measured and reported on at the management review, are:

- Every AI system has a recorded intended use and a named owner in the inventory, reviewed at least annually.
- Every system that affects people has an impact assessment before its first production use and after any material change.
- Every output that affects a person can be reviewed and overturned by a human, and the route to that review is written down.

## Requirements we commit to

- The AI literacy duty of the AI Act: everyone who operates or relies on an AI system on our behalf has the knowledge the role needs, and the measures are recorded.
- For the systems we build, the provider's duties of the AI Act as they apply to each system's classification, and the contractual commitments we give the customers who deploy them.
- For the systems we use, the deployer's duties of the AI Act as they apply to each system's classification, and the instructions for use of the provider we rely on.
- The transparency duties of the AI Act for AI-generated content and for systems that interact with people, where they apply to what we build or use.
- Data protection law for every system that processes personal data, including the impact assessment where the processing is likely to result in a high risk.
- For each system, a recorded determination of whether it is high-risk under the AI Act, made on the facts of that system and kept with its inventory entry; this policy states no such classification itself.

## Relationship to our other policies

This policy sits beside the information security, data protection and supplier policies rather than replacing them: an AI system is still an information system, its data is still data, and its provider is still a supplier. Where this policy and another appear to conflict, the matter is raised with the system owner and resolved in writing rather than by choosing.

## Communication and availability

This policy is published where every employee and contractor can read it, is part of onboarding and of the AI literacy measures, and is made available to customers, auditors and other interested parties on request.

## Review

This policy is reviewed at least annually at the management review, and whenever the company adopts a materially new AI capability, a system's purpose changes, or the regulatory position moves. Changes are versioned and approved through the document control of the management system.

Approved by [top management] on [date].

This policy is written from the answers given. It is not legal or certification advice; whether a system is high-risk under the AI Act is a determination on its own facts, the certification body assesses the policy at the audit, and the words on the certificate are its own.
Is a system high-risk? The determination

StandardOS writes this policy and the ones under it

The AI policy is the first document StandardOS writes for an ISO 42001 system, with the impact assessment, data governance and supplier policies under it generated in the same words and versioned; the inventory it promises, the assessments and the literacy records are then rows and dates, not intentions.

The AI literacy recordThe fundamental rights impact assessmentThe Annex A controls