3.1 Annex SL High-Level Structure & Clauses Overview
Key Takeaways
- ISO/IEC 42001:2023 uses the ISO Harmonized Structure (formerly Annex SL), sharing clause titles and core text patterns with ISO 9001, ISO/IEC 27001, and ISO 14001 for Clauses 4–10.
- Clauses 4–10 are mandatory normative requirements expressed with “shall”; organizations cannot exclude body clauses the way they may justify Annex A control exclusions.
- Annex A provides a reference set of AI-related controls; the Statement of Applicability links risk and context decisions to which controls are implemented or excluded.
- Lead auditors use the HLS as a common map for integrated AIMS–ISMS–QMS audits, reducing duplicated interviews while still testing AI-specific requirements.
- PDCA maps roughly as Plan (4–7), Do (8), Check (9), and Act (10), but auditors still evaluate each clause against objective evidence, not only the PDCA label.
3.1 Annex SL High-Level Structure & Clauses Overview
Auditor focus: ISO/IEC 42001 is built on the same high-level structure as ISO 9001, ISO/IEC 27001, and ISO 14001. That structure is your audit roadmap—not optional scaffolding. Clauses 4–10 are mandatory; Annex A is a reference control catalogue linked through applicability decisions.
ISO/IEC 42001:2023 specifies requirements for an Artificial Intelligence Management System (AIMS). Like other modern ISO management system standards, it follows the ISO Harmonized Structure (historically called Annex SL). For a Lead Auditor, HLS knowledge is practical: it tells you which clause owns which evidence, how multi-standard integrated audits can share interviews, and why a missing “shall” in the body is never “N/A because we are a small team.”
What Annex SL / HLS Gives Auditors
The Harmonized Structure standardizes:
- Clause numbers and titles for Clauses 4–10
- Core definitions shared across management system standards (organization, top management, documented information, process, risk, etc.)
- Common normative phrasing so leadership, planning, support, operation, evaluation, and improvement work the same way across disciplines
Organizations with an ISMS (ISO/IEC 27001), QMS (ISO 9001), or EMS (ISO 14001) can align AIMS governance with shared management review, internal audit, and documented-information controls—when the IMS is real, not three disconnected binders. Nuance: shared structure does not mean shared evidence. An ISMS context analysis that never mentions foundation-model suppliers, model drift, or AI regulation does not satisfy AIMS Clause 4.1.
Clauses 4–10 Overview Table
| Clause | Title | Core question for the auditor | Typical evidence |
|---|---|---|---|
| 4 | Context of the organization | Why this AIMS exists here, for whom, and within which boundaries? | Context analysis, interested-party register, scope statement, process overview |
| 5 | Leadership | Does top management own AI governance, policy, and role clarity? | AI policy, RACI/role charters, management interviews, resource decisions |
| 6 | Planning | Are AI risks, opportunities, impact assessments, and objectives planned? | Risk methodology, AI risk assessments, impact assessments, AI objectives, change plans |
| 7 | Support | Are competence, awareness, communication, and documented information sufficient? | Training records, competence matrices, AI communication plans, controlled documents/records |
| 8 | Operation | Are planned AI lifecycle and operational controls actually executed? | Operational procedures, lifecycle gates, vendor controls, runbooks, change tickets |
| 9 | Performance evaluation | Is the AIMS monitored, audited, and reviewed with data? | Metrics/KPIs, internal audit reports, management review minutes, monitoring of AI systems |
| 10 | Improvement | Are nonconformities, incidents, and improvements handled systematically? | Corrective actions, improvement logs, post-incident reviews, trend analysis |
PDCA mapping (useful, not a substitute for clause tests)
| PDCA stage | Primary clauses | Auditor caution |
|---|---|---|
| Plan | 4 Context, 5 Leadership, 6 Planning, 7 Support | “We planned it” is not enough if operations ignore the plan |
| Do | 8 Operation | Watch for shadow AI projects outside operational control |
| Check | 9 Performance evaluation | Metrics must include AI-relevant performance and conformity, not only generic IT uptime |
| Act | 10 Improvement | Recurring model failures without systemic action signal weak Act |
Mandatory “Shall” Language
Normative body requirements use “shall.” That language creates audit criteria you can raise nonconformities against. Soft guidance, examples, and Annex notes may use “should,” “can,” or “may”—those are not automatic nonconformity hooks unless the organization made them binding (for example through its own AI policy or customer contracts).
Body vs Annex A (critical for classification):
| Layer | Nature | Can the auditee exclude it? | Audit implication |
|---|---|---|---|
| Clauses 4–10 | Mandatory AIMS requirements | No exclusion of body requirements | Missing process = nonconformity against the clause |
| Annex A controls | Reference control set for AI management | Yes, with justified exclusion in the Statement of Applicability (SoA) | Unjustified exclusion or claimed implementation without evidence = nonconformity against planning/operation/SoA linkage |
| Annex B / related guidance | Implementation guidance (where provided by the standard family) | Not a free pass to ignore Annex A where applicable | Use for interview probes; do not treat guidance text as silent mandatory requirements |
Phrase findings against the requirement that failed (e.g., missing continual-improvement commitment in the AI policy under 5.2), not against “ISO in general.”
Relationship of Body Requirements to Annex A
Clauses 4–10 are the management system engine; Annex A is the AI control catalogue that engine selects and operates. Context and parties (4) surface issues; leadership/policy (5) set direction; planning (6) assesses risk/impact and drives which Annex A controls apply; support and operation (7–8) implement them across the lifecycle; evaluation and improvement (9–10) check and fix. The Statement of Applicability bridges risk/context decisions to Annex A. Trace: context issue → risk/impact → SoA decision → operational evidence. Broken chains are classic Stage 1/Stage 2 findings.
Using HLS for Integrated Audits
Many certification programs allow combined or integrated audits when an organization claims multiple management systems. HLS makes this efficient:
- Shared interviews: top management, internal audit, management review, document control, competence
- Shared samples: management review minutes can show ISMS and AIMS agenda items—if AI topics are actually present
- Distinct deep dives: AI system inventory, model risk, bias/fairness evidence, human oversight, third-party model APIs, impact assessments
Scenario: Integrated AIMS–ISMS Stage 2
You audit a fintech that holds ISO/IEC 27001 and is seeking ISO/IEC 42001. The CISO presents one management review pack. Security metrics and incident KPIs are excellent, but there is no agenda item on AI objectives, model performance drift, or AI-related nonconformities. The organization claims “AI is covered under information security.” As Lead Auditor you accept the integrated meeting structure, but you still raise a performance-evaluation / leadership gap if AI management outcomes are not reviewed as required for the AIMS. Integration reduces travel time; it does not collapse AI requirements into CIA-only thinking.
Practical Audit Use of the Clause Map
When you build an audit plan (ISO 19011 style), map processes to clauses: product ML teams primarily to 6–8 and lifecycle/data controls; legal/compliance to 4.1–4.2 and 5.2/6.1; HR to competence and awareness; executives to 5.1–5.2 and management review; internal audit to 9.2 with independence from AIMS ownership.
Common trap: Auditing only Annex A checklists while skimming Clauses 4–5. Without context and leadership, control samples lack criteria for “appropriate to the organization,” and findings become technical nits without system-level significance. Remember four field distinctions: HLS shared is not identical AIMS content; body “shall” differs from SoA exclusions; integrated efficiency is not evidence substitution; PDCA labels never replace clause-by-clause objective evidence.
Under ISO/IEC 42001, which statement correctly describes the relationship between Clauses 4–10 and Annex A?
An organization already certified to ISO/IEC 27001 claims its ISMS management review fully covers ISO/IEC 42001 Clause 9.3 because both standards share the Harmonized Structure. What is the correct auditor response?
In a PDCA view of ISO/IEC 42001, which clause set is primarily associated with the “Check” stage?
Why does Annex SL / the Harmonized Structure matter to an ISO/IEC 42001 lead auditor planning a multi-standard engagement?