Skip to content
arrow_back
Annex A 6.1.3psychologyISO/IEC 42001:2023

Processes for Responsible AI System Design and Development

Write down the specific step-by-step processes your teams follow to design and build each AI (artificial intelligence) system responsibly, so responsible practices are built into how the system is made rather than left to chance.

record_voice_over

Plain language

This control is about how your artificial intelligence (AI) systems get designed and built, and making sure responsible practices are baked into that process rather than added as an afterthought. "Responsible" here means the way you build the AI deliberately guards against harm: checking the data and model for bias (the system unfairly favouring or disadvantaging some groups), testing that it is safe and accurate before release, building in human oversight (a person who can review or override the AI), and being able to explain how it reaches its results. The control asks you to define and document the specific processes your teams follow to do this: in plain terms, a written, repeatable set of steps that says, for each AI system, how it moves from idea to design to a built, tested system, and where the responsibility checks happen along the way. It is not enough to describe the finished AI; you have to describe the process used to create it. For example, your documented process might require a design review before coding starts, a bias and fairness test before training is signed off, a safety and accuracy test before release, and a named person who must approve human-oversight controls. Writing this down means every project follows the same responsible steps, and you can show an auditor or regulator exactly how each system was built, not just claim it was done carefully.

Framework

ISO/IEC 42001:2023

Control effect

Preventative

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall define and document the specific processes for the responsible design and development of the AI system.
psychologyISO/IEC 42001:2023Annex A 6.1.3
priority_high

Why it matters

If you never define a responsible design-and-development process, each AI project is built however its team decides on the day, and the safety and fairness checks that should be mandatory simply get skipped under deadline pressure. A model can then go live without anyone testing it for bias against a protected group or building in a way for a person to override it, so a discriminatory hiring or credit-scoring tool ships unnoticed and is only discovered after it has harmed applicants, exposing the organisation to an OAIC complaint and forcing the system to be withdrawn and rebuilt.

settings

Operational notes

Treat the documented process as a living procedure: when you adopt a new model type (for example a generative AI tool), face a new regulatory expectation, or learn from an incident, update the process steps and the responsibility checkpoints rather than leaving the document frozen. Make sure the process names who must sign off at each responsible-design gate (design review, bias and fairness testing, safety and accuracy testing, human-oversight approval) so a project cannot quietly skip a stage. Periodically check a sample of recent projects against the documented process to confirm teams are actually following the steps, not just that the document exists.

build

Implementation tips

  • The person who owns your AI work (often called the AI lead, the manager accountable for how AI is built and run) should write a single design-and-development procedure that lays out the stages every AI project must pass through (concept, design review, build, testing, and release) and the responsible-design check that has to happen at each stage.
  • Build the responsible practices directly into the process steps: the procedure should require a bias and fairness test (checking the AI does not unfairly disadvantage particular groups) before a model is trained, and a safety and accuracy test before it is released, so these checks are mandatory rather than optional.
  • Whoever runs each project should record evidence as each stage is completed (the signed-off design review, the test reports, and the release approval) so the project file shows the responsible process was genuinely followed, not just intended.
  • When designing each system, the development team should decide and document how a person can oversee, review, or override the AI's outputs, and how the system's results can be explained, treating these as design decisions made early rather than features added after the build.
  • The AI lead should set named sign-off points so a project cannot move to the next stage until the right person has approved it (for example approval to begin training and approval to release) which stops any project quietly skipping a responsible-design step under deadline pressure.
fact_check

Audit / evidence tips

  • AskAsk for the documented process or procedure your organisation follows to design and develop its AI systems responsibly.GoodThere is a written, repeatable design-and-development process that names the stages and the responsible-design check required at each one.
  • AskPick one recent AI system and ask for the records proving each step of that documented process was actually carried out for it.GoodThe project file shows each documented stage was completed in order, with dated evidence for the responsible-design checks.
  • AskAsk who must approve a project before it moves from one stage to the next, and for evidence those approvals occurred.GoodDefined approval gates name who signs off at each stage, and the records show approvals were given before the project advanced.
  • AskAsk how human oversight and the ability to explain the AI's results were built in during development.GoodThe process requires human-oversight and explainability controls to be designed in, and the project records show they were built and tested before release.
  • AskAsk when the documented process itself was last reviewed and updated.GoodThe process has a dated review history showing it was updated when AI types, regulations, or incidents changed what responsible development requires.
link

Cross-framework mappings

How Annex A 6.1.3 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

link_off

No cross-framework mappings recorded yet.

See all A.6 AI system life cycle controls, or browse the full ISO/IEC 42001:2023 library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls