Skip to content
arrow_back
Annex A 9.3psychologyISO/IEC 42001:2023

Objectives for Responsible Use of AI System

Write down the specific goals your organisation wants its AI use to live up to (things like fairness, safety, transparency, human oversight and staying within the law) so every AI project has a clear benchmark to be judged against.

record_voice_over

Plain language

This control asks you to put in writing what "using AI responsibly" actually means for your organisation, as a set of named objectives (for example: treat people fairly, be safe, be transparent about when AI is used, keep a human accountable, and obey the law). The point is to create a yardstick: when someone proposes a new AI use or you review an existing one, you can hold it up against these written objectives and decide whether it measures up. Without that written yardstick, "responsible" means a different thing to every team, and there is nothing concrete to check a decision against later.

Framework

ISO/IEC 42001:2023

Control effect

Preventative

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall identify and document objectives to guide the responsible use of AI systems.
psychologyISO/IEC 42001:2023Annex A 9.3
priority_high

Why it matters

If you have never written down what responsible AI use means for your organisation, you have no benchmark to judge whether any given AI system is acceptable, so approval decisions become inconsistent and rest on whoever happens to be in the room. When an AI use later causes harm (say a hiring tool that quietly disadvantages older applicants) you cannot show a regulator or an OAIC complainant the standard the system was supposed to meet, because none was ever set, and your governance committee has nothing to audit project decisions against. The gap also tends to surface in an ISO 42001 certification audit as a major nonconformity, because A.9.3 is the foundation the rest of the "use of AI" controls reference.

settings

Operational notes

The objectives should be concrete enough to test a real project against, and between them they should cover the things ISO 42001 expects responsible use to address: fairness and non-discrimination, safety and reliability, transparency (being open about when and how AI is used), accountability (a named human owns each decision), human oversight, privacy, and compliance with law such as the Privacy Act 1988. Keep the list short and plain so staff actually use it, and tie each objective back to your organisation's AI policy and risk appetite rather than copying a generic principles list. Re-examine the objectives when your AI strategy changes, when you adopt a materially new type of AI use, or when a new obligation lands (for example the EU AI Act if you sell into the EU, or the NSW AI Assurance Framework if you serve NSW government), and record who approved each version so the history is auditable.

build

Implementation tips

  • Get the AI or product lead to draft the first list of objectives by translating your organisation's values and AI policy into named goals such as fairness, safety, transparency, accountability, human oversight and legal compliance, with one plain sentence each saying what it means here. Keep it to a single page so people will actually read it.
  • Have the risk or compliance owner pressure-test each draft objective against a real or planned AI use and ask 'how would we know if a system failed this?' If an objective cannot be checked against a real project, rewrite it until it can.
  • Take the objectives to your governance body, executive committee or board for formal sign-off, and record the date and approver, because A.9.3 wants these objectives identified and documented as an organisational position, not an informal team note.
  • Build the objectives into your AI project intake or approval step so every new AI use is explicitly assessed against each one before it goes live, which turns the document from a poster into a working gate.
  • Make the head of governance the named owner who re-opens the objectives when the AI strategy shifts, a materially new type of AI use is adopted, or a new obligation lands such as the EU AI Act or the NSW AI Assurance Framework, and keep each revision dated so the history is clear.
fact_check

Audit / evidence tips

  • AskRequest the organisation's documented objectives for responsible use of AI.GoodThe organisation produces a document that names each responsible-use objective and explains in a line or two what it means for their AI.
  • AskAsk who approved the objectives and when, and request the version history or approval record.GoodThere is a dated, signed-off version of the objectives with a clear owner, and the approval sits with senior management or a governance body.
  • AskAsk how a new or existing AI project is checked against these objectives, and request one worked example.GoodA completed project assessment shows the AI system was weighed against each documented objective with notes on how it meets them.
  • AskAsk the staff who build or run AI to tell you, in their own words, what the responsible-use objectives are.GoodPractitioners can name the main objectives or point straight to where they are published, showing the objectives are used and not shelfware.
  • AskAsk what triggers a review of the objectives and request the most recent review record.GoodThe organisation can show its objectives were reviewed against a defined trigger and can point to the dated record of that review.
link

Cross-framework mappings

How Annex A 9.3 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ASD ISM

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
ISM-1999Annex A 9.3 requires the organisation to identify and document objectives that guide the responsible use of AI systems (e.g., safety, hum...
handshakeSupports(2)expand_less
ISM-0047Annex A 9.3 requires the organisation to identify and document objectives to guide responsible AI use, which must be approved and controlled
ISM-1998Annex A 9.3 requires the organisation to identify and document objectives to guide responsible AI use, including how AI will be used acro...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all A.9 Use of AI systems controls, or browse the full ISO 42001 Annex A library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls