Skip to content
arrow_back
Annex A 2.2psychologyISO/IEC 42001:2023

AI Policy

The organisation writes down an approved policy that sets the rules for how it builds and uses AI systems, and states which AI activities the policy covers.

record_voice_over

Plain language

Your organisation needs one written, approved document that says how it is allowed to build and use AI systems: things like what AI may be used for, what is off limits, and what rules people must follow. The policy should also say plainly which AI work it governs (for example, only customer-facing AI, or every AI tool staff touch), so nobody has to guess whether it applies to them. AI system means software that learns patterns from data to make predictions or decisions, such as a chatbot or a tool that scores job applicants.

Framework

ISO/IEC 42001:2023

Control effect

Preventative

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall document a policy for the development or use of AI systems.
psychologyISO/IEC 42001:2023Annex A 2.2
priority_high

Why it matters

If there is no documented AI policy, a team can quietly launch something like an automated loan-decline or resume-screening tool with no agreed rules, and when it rejects a protected cohort, the organisation has no written position to point to when a regulator such as the Office of the Australian Information Commissioner (OAIC) asks who authorised it and on what basis. Auditors treat a missing or undated AI policy as a top-level gap that can fail the whole management system, and remediation means halting AI projects until the policy is written and approved. The absence also leaves staff inventing their own rules for both building and using AI, so practice varies team to team with no way to enforce a baseline.

settings

Operational notes

Date and version every release of the policy and record who approved it, so the current rules are never in doubt. Refresh it whenever AI use materially changes or a relevant law shifts (such as new EU AI Act obligations or Privacy Act 1988 reforms), rather than waiting for a fixed annual slot. Make sure the scope statement still matches reality. If the organisation starts developing its own models when the policy only covered buying AI, the scope line has to be updated.

build

Implementation tips

  • Get an accountable leader or the leadership team to approve a single AI policy that states the organisation's intent for AI and the limits on it: for example which uses are allowed, which are banned, and what decisions AI must never make alone. Hold a short session to agree these points, then capture them in one document rather than scattering rules across emails.
  • Whoever owns the policy should write a clear scope section at the front saying exactly which AI activities it governs (building your own models, using bought-in AI tools, staff use of generative AI, or all of these) so the document maps directly to the development-or-use wording in the requirement and no team is left guessing.
  • Make sure the policy speaks to both halves of the requirement: have a section on developing AI systems (how models are built, tested and documented) and a separate section on using AI systems (how staff and the business may operate them day to day), so neither side is left uncovered.
  • Put a version number, an approval date and the approver's name on the document, and store it where staff can find it, so anyone can confirm they are reading the current approved rules rather than an old draft.
  • The policy owner should set a trigger to revisit the policy whenever AI use changes materially or a relevant law moves, write the new review date into the document, and circulate a short note to staff summarising what changed.
fact_check

Audit / evidence tips

  • AskRequest the current AI policy document and the record of who approved it and when.GoodThe organisation produced a single approved, dated AI policy that an accountable leader or committee signed off.
  • AskRead the scope section of the policy.GoodThe policy clearly names the AI development and use activities it governs so a reader can tell whether their work is in scope.
  • AskAsk whether the policy covers both building AI and using AI, and point to where each is addressed.GoodThe policy addresses both the development and the use of AI systems, matching the requirement, not just one of the two.
  • AskRequest the policy's revision history or change log.GoodThe change log shows the policy is kept current and was reviewed after the most recent material change in AI use or law.
  • AskAsk how staff are told about the AI policy and request the proof.GoodThe organisation can show the approved policy was published to the people expected to follow it.
link

Cross-framework mappings

How Annex A 2.2 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.1Annex A 2.2 requires the organisation to document a policy specifically for the development or use of AI systems
handshakeSupports(2)expand_less
Annex A 5.4Annex A 2.2 requires the organisation to document a policy for AI system development or use
Annex A 5.36Annex A 2.2 requires the organisation to document a policy for AI system development or use

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all A.2 Policies related to AI controls, or browse the full ISO 42001 Annex A library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls