Skip to content
arrow_back
Annex A 2.3psychologyISO/IEC 42001:2023

Alignment with Other Organisational Policies

Work out which of your existing organisational policies are affected by, or already apply to, your goals for AI systems, then amend or cross-reference them so the two do not contradict each other.

record_voice_over

Plain language

Your organisation already has rules written down for things like privacy, security, safety, records and hiring. This control asks you to look at what you want to do with AI (your AI objectives) and figure out which of those existing rules either touch the AI work or need updating because of it. For example, your privacy policy already covers personal information, so if an AI tool uses customer data, the privacy policy applies and may need a few extra lines about automated decisions.

Framework

ISO/IEC 42001:2023

Control effect

Proactive

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall determine where other policies can be affected by or apply to, the organisation''s objectives with respect to AI systems.
psychologyISO/IEC 42001:2023Annex A 2.3
priority_high

Why it matters

If you never map your AI objectives against existing policies, an AI hiring tool can quietly breach your own anti-discrimination or recruitment policy and screen out a protected cohort, surfacing later as a complaint to the Australian Human Rights Commission or the OAIC. A chatbot trained on customer records can also collide with a privacy policy that never authorised that use, forcing you to switch the system off and notify affected individuals while you reconcile the two documents.

settings

Operational notes

Keep a simple register that lists each existing policy (privacy, information security, safety, quality, records management, HR and recruitment, procurement, code of conduct) against a note on whether your AI objectives affect it, apply to it, or leave it untouched. Revisit the register whenever you set a new AI objective or stand up a new AI use case, because a policy that was irrelevant last year may now be in scope. Where you find a conflict or a gap, decide explicitly whether to amend the existing policy or carve the AI rule into your AI policy, and record which document now owns the point so nobody has to guess.

build

Implementation tips

  • Get whoever owns your management policies (often the company secretary or a governance lead) to pull together the full list of existing policies (privacy, information security, safety, quality, records, recruitment, procurement and the code of conduct) and run each one against your stated AI objectives to mark whether the objective affects that policy or that policy already applies to the AI work. This is the determination the control actually asks for, so capture it in one register.
  • Have the privacy or data-protection policy owner check, line by line, whether the AI objectives bring new processing your current Privacy Act 1988 commitments do not cover, and add the missing wording (for example a note on automated decisions) directly into that policy rather than leaving it only in the AI policy.
  • Askthe information security lead to confirm whether your existing security policy already applies to AI models, training data and prompts, and where it does not reach, decide openly whether to widen the security policy or to handle the point in the AI policy so there is one clear owner per rule
  • Where the AI objective touches people decisions, get the HR or recruitment policy owner to read those policies against the objective so any AI-assisted screening or monitoring stays inside your existing anti-discrimination and recruitment commitments before the tool goes live.
  • Follow the ISO 42001 Annex B.2.3 guidance and have a senior manager sign off the completed alignment register, recording for each policy whether it was amended, cross-referenced to the AI policy, or confirmed as unaffected, and set a trigger to redo this whenever a new AI objective or use case appears.
fact_check

Audit / evidence tips

  • AskAsk for the register or matrix that maps AI objectives against the organisation's other policies.GoodThe register names each existing policy, marks which are affected by or apply to the AI objectives, and points to the resulting amendment or cross-reference.
  • AskAsk to see a policy that was amended because of AI, such as the privacy or recruitment policy.GoodThe amended policy shows dated, approved changes that address the AI objective identified in the alignment review.
  • AskAsk the person who owns the AI policy which other policies it depends on and where that is written down.GoodThe owner shows two-way cross-references linking the AI policy to the specific other policies it relies on.
  • AskAsk for evidence that the alignment review was repeated when a new AI use case was approved.GoodThe register has a dated entry showing it was rechecked when the new AI use case was introduced.
  • AskAsk for the gap analysis covering policies that were silent on AI.GoodEvery identified gap carries a recorded decision naming which document now owns the AI-specific rule.
link

Cross-framework mappings

How Annex A 2.3 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(3)expand_less
Annex A 5.1Annex A 2.3 requires the organisation to determine where other organisational policies are affected by, or apply to, the organisation’s o...
Annex A 5.10Annex A 2.3 requires identifying which existing policies are impacted by or constrain AI objectives
Annex A 5.12Annex A 2.3 requires the organisation to determine how AI objectives interact with other organisational policies
handshakeSupports(3)expand_less
Annex A 5.4Annex A 2.3 requires determining how AI objectives affect or are constrained by other organisational policies
Annex A 5.31Annex A 2.3 requires identifying which organisational policies apply to or are affected by AI objectives
Annex A 5.36Annex A 2.3 requires the organisation to identify policy intersections and impacts arising from AI objectives

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all A.2 Policies related to AI controls, or browse the full ISO 42001 Annex A library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls