8.1 Control Objective A.9: Use of AI Systems & Human Oversight

Key Takeaways

  • A.9 has three controls: A.9.2 responsible-use processes, A.9.3 responsible-use objectives, and A.9.4 intended use.

  • There is no A.9.3 human-oversight control in ISO/IEC 42001:2023.

  • Responsible-use processes translate policy and objectives into operating procedures for AI users.

  • Responsible-use objectives are documented and taken into account in operation.

  • The organization ensures the AI system is used according to intended use and accompanying documentation.

Last updated: October 2026

Annex A.9: use of AI systems

A.9 ensures that the organization uses AI systems responsibly and in accordance with organizational policies. It has three controls, numbered A.9.2 through A.9.4. It does not contain a control called “human oversight of AI systems.”

A.9.2 Processes for responsible use

The organization defines and documents processes for responsible use of AI systems.

These processes govern how people and organizational units select, configure, access, operate, monitor, change, and stop using AI systems. They can cover:

  • approved and prohibited uses;
  • authorization and access;
  • user competence and instructions;
  • input and data handling;
  • output interpretation and verification;
  • escalation, incident, and concern reporting;
  • monitoring and record keeping;
  • supplier changes; and
  • suspension or retirement.

The appropriate process depends on the system. A general-purpose assistant, industrial controller, fraud model, and clinical support system need different operating rules.

An “acceptable use policy” can support this control, but the control requires processes rather than one document with a prescribed title. Tool allow-lists, technical restrictions, training, and workflow controls are examples.

A.9.3 Objectives for responsible use

The organization identifies and documents objectives to guide responsible use of AI systems.

These objectives complement Clause 6.2 and A.6.1.2. Development objectives guide how systems are designed; use objectives guide how the organization operates them.

Examples include maintaining appropriate human decision authority, preventing use outside approved purpose, achieving timely incident escalation, protecting confidential inputs, or verifying high-consequence outputs. Measures should fit context. The control does not prescribe HITL, HOTL, and human-in-command as three mandatory objectives.

Objectives should influence the responsible-use process. A statement that “AI will be used ethically” is weak unless operating criteria, responsibilities, controls, and evaluation make it actionable.

A.9.4 Intended use of the AI system

The organization ensures that the AI system is used according to its intended uses and accompanying documentation.

Intended-use information can define:

  • purpose and tasks;
  • target users and affected context;
  • supported inputs, languages, populations, or environments;
  • output meaning and limitations;
  • required user competence or review;
  • dependencies and operating conditions; and
  • uses that are not supported.

Controls can include training, interface design, access restrictions, configuration limits, monitoring, contractual terms, or technical guardrails. “Operational design domain” is a useful term in some sectors but is not mandatory vocabulary for every AI system.

Foreseeable misuse

Clause 6.1.4 considers foreseeable misuse in impact assessment. A.9.4 ensures use follows intended use and documentation. Together they support prevention and response for function creep, accidental misuse, and adversarial use.

Prompt injection can be a relevant misuse for an LLM-enabled application. A.9 does not mandate one defense such as a dual-model architecture or regex filter. Effective treatment can combine least privilege, separation of instructions and data, tool authorization, validation, monitoring, testing, and user guidance.

Human oversight: where it belongs

Human oversight can be selected when needed to treat risk or impact and can be reflected in policy, responsible-use objectives, processes, requirements, deployment, operation, user information, and competence. Annex B guidance discusses human involvement in several contexts.

Common patterns are useful design shorthand:

  • human-in-the-loop: human action before execution;
  • human-on-the-loop: monitoring with intervention ability; and
  • human-in-command: strategic authority and system-level control.

ISO/IEC 42001 Annex A does not label A.9.3 as human oversight or require all three patterns. The organization chooses an effective arrangement. A human reviewer without competence, time, information, or authority may provide little control. Conversely, some low-consequence processes can be managed through automation limits and monitoring without review of every output.

Use versus development

QuestionPrimary Annex group
How is responsible development guided?A.6.1
What lifecycle requirements and evidence apply?A.6.2
How will the organization responsibly operate the system?A.9.2 and A.9.3
Is operation within intended use?A.9.4
How are supplier/customer responsibilities allocated?A.10

An organization that only purchases AI can still need all three A.9 controls because it decides how the system is used.

Example

A law firm authorizes a generative tool for internal research summaries. Its A.9.2 process restricts confidential uploads, requires source verification, defines approved accounts, and routes suspected errors. A.9.3 objectives include preventing unverified generated citations from reaching clients. A.9.4 ensures the tool is not used as an autonomous source of legal advice outside documented capabilities.

A second-person review may be an appropriate control for client work, but it is a decision based on risk and intended use, not a universal A.9.3 requirement.

Accurate map

  • A.9.2 processes for responsible use
  • A.9.3 objectives for responsible use
  • A.9.4 intended use

Important

A question claiming “Control A.9.3 mandates HITL/HOTL/HIC” is based on an incorrect control catalogue.

Test Your Knowledge

What does A.9.3 address?

A

Human oversight modes

B

Event logging

C

Supplier contracts

D

Objectives for responsible use of AI systems

Test Your Knowledge

Which control ensures the AI system is used according to intended uses and accompanying documentation?

A

A.9.4

B

A.9.2

C

A.8.4

D

A.10.2

Test Your Knowledge

How should HITL, HOTL, and human-in-command be treated in this guide?

A

As the three mandatory A.9 controls

B

As useful oversight patterns that may be selected in response to risk and impact

C

As prohibited terminology

D

As exam delivery modes

Sections you finish are checked off in the contents.