3.2 Clause 4: Organizational Context & AIMS Scope

Key Takeaways

  • Clause 4.1 determines relevant internal and external issues, whether climate change is relevant, intended AI-system purpose, and the organization’s roles.

  • Clause 4.2 identifies relevant interested parties, their relevant requirements, and which requirements the AIMS will address; its note recognizes climate-related requirements.

  • Clause 4.3 considers the 4.1 issues and 4.2 requirements when defining AIMS boundaries and applicability.

  • The AIMS scope must be available as documented information and determines the organization’s activities covered by the standard.

  • Clause 4.4 requires a documented AIMS with the necessary processes and interactions, maintained and continually improved.

Last updated: October 2026

Clause 4: context of the organization

Clause 4 defines the foundation on which every later AIMS decision rests. Risk criteria, policy, objectives, controls, monitoring, and improvement are credible only when they reflect the organization’s real purpose, roles, AI activities, interested parties, and operating environment.

4.1 Understanding the organization and its context

The organization determines external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcomes of the AIMS. It expressly determines whether climate change is a relevant issue. It also considers the intended purpose of the AI systems it develops, provides, or uses and determines its roles with respect to those systems.

Clause 4.1 does not separately say to “monitor and review” information about the issues. Keeping context current is sound management practice, but do not import that sentence from another management-system standard as ISO/IEC 42001 wording.

External issues can include laws and regulation, market expectations, social attitudes, scientific and technical developments, suppliers, economic conditions, and the environments in which AI outputs are used. Internal issues can include governance, strategy, culture, competencies, data and technology assets, organizational structure, risk appetite, contractual commitments, and existing management systems.

A SWOT or PESTLE workshop can help, but neither method is prescribed. The required result is that relevant issues, climate-change relevance, intended purpose, and organizational roles are determined. A copied list of generic “AI trends” that never influences scope, risks, objectives, or controls is weak context analysis.

Role matters

The same technology creates different issues depending on the organization’s role. A model producer controls training and architecture. A provider packages or supplies a system. A user integrates the system into a process and controls the context of use. An organization can occupy several roles at once. Context analysis should identify those roles rather than assuming that purchasing a vendor service places all responsibility upstream.

4.2 Interested parties and their requirements

The organization determines:

  • interested parties relevant to the AIMS;
  • relevant requirements of those interested parties; and
  • which of those requirements will be addressed through the AIMS.

Interested parties can include customers, users, employees, affected individuals or groups, regulators, suppliers, partners, owners, certification bodies, and communities. Relevance depends on the defined organization and AI activities.

Requirements can arise from law, regulation, contracts, standards, policies, service commitments, or legitimate stakeholder expectations. The clause notes that relevant interested parties can have requirements related to climate change. Not every preference becomes an AIMS obligation: the organization determines relevance and which requirements the management system will address.

A useful register may record the party, requirement, source, applicability, owner, related process, and review trigger. That is a practical format, not a required template.

4.3 Determining the AIMS scope

The organization determines the boundaries and applicability of the AIMS. When doing so, it considers:

  1. the internal and external issues from 4.1; and
  2. the interested-party requirements from 4.2.

The resulting scope is available as documented information. The clause then states that the scope determines the organization’s activities with respect to the document’s requirements on the AIMS, leadership, planning, support, operation, performance evaluation, improvement, controls, and objectives. Activities and AI roles therefore matter through the 4.1 context and the resulting boundary, but they are not a third separately listed 4.3 input.

A useful scope makes clear what organizational units, activities, products or services, locations, interfaces, and AI-related roles are included so that users can understand the management-system boundary.

The scope does not have to list every control exclusion. Control selection and exclusions belong in the risk-treatment process and Statement of Applicability. Nor does Clause 4.3 automatically require a separate essay justifying every AI system not named in the scope. However, a boundary designed to evade relevant activities or requirements will undermine conformity because the scope must be based on context and applicability.

Example scope reasoning

A health network implements an AIMS for AI-enabled diagnostic support used by three hospitals. It identifies:

  • external issues: medical-device obligations, clinical evidence expectations, supplier dependence, and changing diagnostic practice;
  • internal issues: clinical governance, radiology competence, data quality, cybersecurity, and legacy integration;
  • interested parties: patients, clinicians, regulators, the model supplier, privacy authorities, and hospital leadership; and
  • roles: user and customer of a third-party model, plus provider of a clinical service using it.

A defensible scope might cover governance, acquisition, integration, validation, operation, monitoring, and retirement of the diagnostic support service across those hospitals. It would also define interfaces with the supplier and with the existing security and quality systems.

4.4 The AI management system

Clause 4.4 requires the organization to establish, implement, maintain, continually improve, and document an AIMS, including the processes needed and their interactions, in accordance with the standard.

This means the AIMS is a working system rather than a document collection. Processes should connect. Context informs risks; risks and impacts inform treatment; treatment informs controls; objectives inform monitoring; audit and management review inform improvement.

A process map can show inputs, outputs, owners, sequence, criteria, records, and links. The standard does not prescribe a particular software platform, committee, or document hierarchy.

Common distinctions

  • Context identifies conditions that matter.
  • Interested-party analysis identifies relevant parties and requirements.
  • Scope sets boundaries and applicability.
  • The AIMS is the connected set of processes operating within that scope.
  • The SoA records necessary controls and inclusion/exclusion rationale after risk treatment.

Tip

If a scenario says an organization uses only vendor AI, do not conclude that Clause 4 is irrelevant. Its role as user or customer and its control over context of use are precisely the kinds of facts Clause 4 captures.

Test Your Knowledge

What is the principal output required by Clause 4.3?

A

A certificate issued by ISO

B

A public list of every source-code repository

C

A documented statement defining the boundaries and applicability of the AIMS

D

A fixed list of all Annex A controls marked mandatory

Test Your Knowledge

Which two inputs does Clause 4.3 expressly require the organization to consider when determining AIMS scope?

A

Only the annual AI budget and headcount

B

Only systems developed in-house and source-code ownership

C

Every preference expressed by any person

D

The Clause 4.1 issues and the Clause 4.2 requirements

Test Your Knowledge

Which statement best describes Clause 4.4?

A

It requires an AIMS with needed processes and interactions that is maintained and continually improved

B

It requires a single AI policy but no processes

C

It requires all 38 controls for every system

D

It applies only during certification audits

Sections you finish are checked off in the contents.