4.3 Clause 6.2 AI Objectives & Planning to Achieve Them
Key Takeaways
- Clause 6.2 requires AI objectives at relevant functions and levels that are consistent with the AI policy and preferably measurable, monitored, communicated, and updated.
- Planning to achieve AI objectives must address what will be done, what resources are required, who is responsible, when it will be completed, and how results will be evaluated.
- Strong AI objectives are specific, measurable (or otherwise evaluable), tied to trustworthy-AI outcomes, and owned—not slogans such as “be ethical with AI.”
- Auditors interview objective owners, sample plans and performance data, and check consistency with risk treatment priorities and management review inputs.
- Weak objectives often lack baselines, owners, resources, or evaluation methods, making Clause 9 performance evaluation and continual improvement un-auditable.
4.3 Clause 6.2 AI Objectives & Planning to Achieve Them
Auditor focus: Are AI objectives real management targets consistent with the AI policy—or unowned slogans? Can the auditee show what will be done, by whom, with which resources, by when, and how success is evaluated? Follow objectives into monitoring (Clause 9) and management review.
Clause 6.2 connects leadership’s AI policy to operational performance. Without credible objectives, the AIMS has direction but no navigational instruments. Lead auditors treat 6.2 as both a document review item (Stage 1) and an implementation trail (Stage 2).
Requirements of Clause 6.2
The organization shall establish AI objectives at relevant functions and levels. The AI objectives shall:
- Be consistent with the AI policy.
- Be measurable (if practicable).
- Take into account applicable requirements.
- Be monitored.
- Be communicated.
- Be updated as appropriate.
The organization shall retain documented information on the AI objectives.
When planning how to achieve its AI objectives, the organization shall determine:
| Planning element | Auditor meaning | Example evidence |
|---|---|---|
| What will be done | Concrete actions/projects, not aspirations | Initiative charter, backlog items, control implementations |
| What resources will be required | People, compute, budget, tools, data access | Budget lines, headcount, GPU/tooling approvals |
| Who will be responsible | Named owners/roles with authority | RACI, objective owner appointments |
| When it will be completed | Time-bound milestones | Roadmap dates, OKR cycles |
| How results will be evaluated | Metrics, methods, frequency, decision rules | KPI definitions, dashboards, review minutes |
These five planning questions are exam favorites: if any is missing for material objectives, Stage 2 findings are likely.
Consistency with AI Policy and Risk Priorities
AI objectives should cascade from the AI policy themes established under Clause 5—e.g., fairness, safety, transparency, security, human oversight, accountability—and from risk treatment priorities under 6.1.3. A common gap is policy language about “bias mitigation” with objectives only about “model accuracy” and “time-to-deploy.” Auditors compare:
- AI policy commitments.
- Top residual risks and impact assessment hotspots.
- Stated AI objectives and KPIs.
- Actual resourcing and performance data.
Misalignment (policy promises without objectives, or objectives that ignore top residual AI risks) supports findings against 6.2 and often weakens Clause 9.3 management review effectiveness.
Good vs Weak AI Objectives
| Weak objective | Why it fails audit scrutiny | Stronger objective |
|---|---|---|
| “Be ethical with AI.” | Not measurable; no owner/plan | “By Q4, complete AI system impact assessments for 100% of high-impact systems before production release; zero high-impact releases without approved AISIA.” |
| “Improve AI quality.” | No baseline or metric | “Reduce production model performance drift incidents requiring emergency rollback by 40% vs prior year, measured monthly via MLOps incident tags.” |
| “Comply with all AI laws.” | Vague; not actionable plan | “Map applicable AI regulatory obligations for EU and US operations by 30 June; close 100% of critical compliance gaps identified in the legal register by year-end.” |
| “Increase AI adoption.” | May conflict with responsible-AI policy if unconstrained | “Increase approved AI use-cases in scope by 20% while maintaining residual risk within acceptance criteria and completing A.6 verification gates for each release.” |
| “Train staff on AI.” | Incomplete without evaluation | “Achieve 95% completion of role-based AI competence modules for model owners and approvers by 31 March; verify via assessments and sampling of change approvals.” |
Characteristics of strong AI objectives:
- Specific to AIMS outcomes (not only business sales targets).
- Measurable or evaluable with defined data sources.
- Achievable with allocated resources (auditors check resourcing realism).
- Relevant to policy, risks, and interested-party requirements.
- Time-bound with review points.
- Owned by a person/role with authority to escalate blockers.
Relevant Functions and Levels
“Relevant functions and levels” means objectives are not only an executive poster. Typical cascade:
- Enterprise / AIMS owner: portfolio residual risk, certification readiness, major incident rates, impact-assessment coverage.
- Product / AI system owners: fairness metrics, human-oversight effectiveness, transparency disclosures, model performance SLOs.
- Data / MLOps: data quality thresholds, lineage completeness, monitoring coverage, retrain SLA.
- Security / privacy: adversarial testing cadence, access control to models/data, privacy incident linkage.
- HR / competence: role-based training completion for AI decision-makers.
Auditors sample vertical consistency: does a corporate fairness objective appear in product KPIs and testing gates?
Audit Interview Techniques for Objective Owners
Use structured interviews; record names, roles, and evidence references.
Opening probes
- “Which AI objectives do you own, and how do they connect to the AI policy?”
- “What is the baseline and current performance for each metric?”
- “Show the plan: actions, resources, dates, and evaluation method.”
- “When did you last update an objective because risk or impact findings changed?”
- “What happens if a milestone is missed—who escalates, and to which forum?”
Cross-checks: metrics vs dashboards (9.1), resources vs budget, owners vs appointments, communication evidence, and management-review updates.
Scenario: Unowned slogan objectives
Document review: AI objectives list three bullets: “Responsible AI,” “Customer trust,” “Innovation.” No metrics, no owners, no plans.
Interviews: The CISO believes Legal owns AI objectives; Legal believes the AI Center of Excellence owns them; the CoE points to a slide deck from last year.
Finding logic: Nonconformity against 6.2—objectives are not established as measurable/monitored management objectives with documented planning elements. Secondary observation: weak integration with 6.1 risk treatment and 9.3 management review.
Scenario: Good objective trail
Objective: “For customer-facing generative AI, achieve ≥98% of production responses within approved content-safety and groundedness thresholds by 30 September; evaluate weekly.”
Plan evidence: safety filter project, evaluation dataset ownership (NLP lead), compute budget approval, weekly scorecard to AI governance committee, escalation if two consecutive weeks below threshold. Residual risk for hallucination was previously rated high; this objective is a treatment effectiveness measure. Auditors can verify end-to-end.
Integration with Other Clauses (Auditor Map)
| Related clause | Integration point |
|---|---|
| 5.2 AI policy | Objectives must be consistent with policy commitments |
| 6.1 Risks/impacts | Objectives often measure treatment effectiveness |
| 6.3 Changes | Major objective shifts may require planned AIMS changes |
| 7.1–7.2 Resources/competence | Plans must be resourced with competent people |
| 9.1 Monitoring | Objectives require measurement methods and data quality |
| 9.3 Management review | Objectives status is a typical review input |
| 10 Improvement | Missed objectives drive corrective action / improvement |
Common nonconformities
- ISO 27001 objectives with “AI” find-and-replace only.
- Objectives not communicated to people who must achieve them.
- Plans without evaluation methods.
- Metrics disconnected from trustworthy AI (e.g., only “models deployed”).
- No update when residual risk or law changes.
Document findings with objective wording, missing planning elements, and absent performance records.
When planning how to achieve AI objectives under Clause 6.2, which set of determinations is required?
Which AI objective is strongest for audit purposes?
During interviews, three managers each claim someone else owns the published AI objectives, and no performance data exists. What is the most appropriate audit conclusion focus?
Why should AI objectives be consistent with the AI policy under Clause 6.2?