4.1 Annex A Overview & Control Architecture (38 Controls Across 9 Objectives A.2–A.10)

Key Takeaways

  • ISO/IEC 42001 Annex A contains 38 normative AI-specific controls categorized under 9 distinct control objectives numbered A.2 through A.10.
  • Control selection is discretionary based on the risk assessment (Clause 6.1.2) and formally documented in the mandatory Statement of Applicability (SoA, Clause 6.1.3).
  • Annex B provides informative implementation guidance for each Annex A control; Annex C catalogues organizational objectives and risk sources; Annex D addresses use of the AIMS across domains and with other management systems.
  • Unlike ISO/IEC 27001 which targets the CIA triad of general information assets, ISO/IEC 42001 Annex A specifically targets trustworthy, fair, safe, transparent, and compliant AI system behavior across the full lifecycle.
  • Verified per-objective control counts are A.2:3, A.3:2, A.4:5, A.5:4, A.6:9, A.7:5, A.8:4, A.9:3, and A.10:3 (total 38).
Last updated: July 2026

4.1 Annex A Overview & Control Architecture (38 Controls Across 9 Objectives A.2–A.10)

An Artificial Intelligence Management System (AIMS) constructed in accordance with ISO/IEC 42001:2023 relies on two interconnected structural pillars: the high-level management system requirements detailed in Clauses 4 through 10 (structured according to the ISO Harmonized Structure, formerly Annex SL) and the normative catalog of operational controls contained in Annex A. While Clauses 4 through 10 establish organizational context, leadership commitments, risk management frameworks, resource provisioning, performance evaluations, and continual improvement mechanisms, Annex A provides the concrete, verifiable control measures necessary to mitigate AI-specific risks across an enterprise.

For professionals preparing for the PECB ISO/IEC 42001 Lead Implementer examination, mastering the architecture, taxonomy, scoping methodology, and implementation logic of Annex A is essential. Lead Implementers must understand not only the technical mandate of each control, but also how controls are systematically evaluated, selected, tailored, justified, documented, and audited within complex operational ecosystems.


Structure of Annex A: 9 Control Objectives and 38 Normative Controls

Annex A defines 38 normative controls organized beneath 9 distinct control objectives, designated sequentially as A.2 through A.10 (A.1 is reserved as an introductory overview clause in standard ISO numbering). Each control objective represents a strategic domain of AI governance, addressing specialized risks that emerge throughout the artificial intelligence lifecycle, data pipeline, user interaction boundary, and third-party supply chain.

Control ObjectiveControl Count & DesignationsPrimary Operational FocusKey Technical & International Standards Alignment
A.2 Policies related to AI3 Controls (A.2.2–A.2.4)AI policy definition, alignment with other organizational policies, and scheduled or event-driven policy reviewISO/IEC 38507 (Governance of AI), OECD Principles on AI
A.3 Internal organization2 Controls (A.3.2–A.3.3)AI roles and responsibilities plus confidential channels for reporting AI concernsISO/IEC 42001 Clause 5.3, UNESCO Ethics of AI
A.4 Resources for AI systems5 Controls (A.4.2–A.4.6)Documentation of data, tooling, system/computing, and human resources that AI systems depend onISO/IEC 42001 Clause 7.1–7.2, NIST AI RMF Govern
A.5 Assessing impacts of AI systems4 Controls (A.5.2–A.5.5)AI system impact assessment process, documentation, and triggered reassessment across people, groups, and societyISO/IEC 23894, EU AI Act Article 27 (FRIA)
A.6 AI system life cycle9 Controls (A.6.1.2–A.6.1.3; A.6.2.2–A.6.2.8)Responsible objectives, design/development, verification/validation, deployment, operation/monitoring, technical documentation, and event loggingISO/IEC 5338 (AI Lifecycle), ISO/IEC 22989
A.7 Data for AI systems5 Controls (A.7.2–A.7.6)Data for development/enhancement, acquisition, quality, provenance, and preparationISO/IEC 5259 Series (Data Quality for Analytics & ML), GDPR
A.8 Information for interested parties4 Controls (A.8.2–A.8.5)User documentation, external reporting, incident communication, and information for interested partiesEU AI Act transparency obligations, IEEE 7001
A.9 Use of AI systems3 Controls (A.9.2–A.9.4)Processes and objectives for responsible use, plus intended-use boundaries and operational monitoringNIST AI RMF (Measure & Manage)
A.10 Third-party and customer relationships3 Controls (A.10.2–A.10.4)Allocation of responsibilities across the AI supply chain, supplier due diligence, and customer responsibilitiesISO/IEC 27036 (Supplier Relationships), EU AI Act Article 28

Structural Interplay: Annex A (Normative) vs. Annexes B, C & D (Informative)

ISO/IEC 42001 includes one normative control annex and three informative annexes. Lead Implementers must distinguish their audit standing:

  1. Annex A (Normative): The reference control catalogue. Selected controls recorded in the Statement of Applicability (SoA) become auditable requirements. Auditors assess conformity against the control statements in Annex A.
  2. Annex B (Informative): Implementation guidance for each Annex A control (examples and recommended approaches). Auditors may use Annex B to evaluate effectiveness, but organizations may implement equivalent approaches if justified.
  3. Annex C (Informative): Potential AI-related organizational objectives and risk sources (for example bias, security, and explainability) to feed risk assessment — not a second mandatory control list.
  4. Annex D (Informative): Guidance on using the AIMS across domains/sectors and integrating it with other management systems (for example ISO 9001 or ISO/IEC 27001). Domain 2 of the PECB Lead Implementer exam explicitly expects an overview of Annexes A–D.

Organizations are certified against Clauses 4–10 and the applicable Annex A controls documented in the SoA; Annexes B, C, and D help implementers design a complete, integrable system.

Loading diagram...
ISO/IEC 42001 Annex A Control Selection and Statement of Applicability (SoA) Workflow

Statement of Applicability (SoA) and Control Selection Methodology

Under Clause 6.1.3, an organization cannot simply adopt all 38 controls blindly, nor can it selectively pick controls without formal justification. The organization must compare its chosen risk treatment options against the complete catalog of controls in Annex A to verify that no necessary control has been omitted.

The output of this process is the Statement of Applicability (SoA), a mandatory document that serves as the centerpiece of an ISO/IEC 42001 certification audit. A compliant SoA must contain four essential elements for every single one of the 38 controls:

  1. Inclusion or Exclusion Decision: An explicit statement indicating whether the control is included in the AIMS boundary.
  2. Justification for Inclusion: The specific risk treatment rationale, legal requirement, business objective, or contractual mandate supporting inclusion.
  3. Implementation Status: Reference to documented policies, procedures, technical configurations, or MLOps pipelines demonstrating that the control is operational.
  4. Justification for Exclusion: An explicit, detailed business or risk-based justification for any control marked as excluded.

Lead Implementer Exam Warning: Blanket exclusions of entire control objectives—such as excluding Objective A.6 (AI System Life Cycle) by claiming "we only purchase third-party SaaS AI products"—are heavily scrutinized during Stage 1 and Stage 2 audits. Even if an organization does not train foundational AI models in-house, controls such as A.6.2.1 (Intended Use), A.6.2.7 (Deployment), A.6.2.8 (Operation and Monitoring), and A.10 (Third-Party Relationships) remain strictly applicable to ensure safe integration and third-party risk oversight.


Worked Implementation Scenario: Drafting an SoA for a Financial Enterprise

Scenario: FinTech Solutions Inc. is implementing an AIMS to govern two primary AI assets: (1) a custom-built, in-house credit risk scoring model trained on historical customer transaction data, and (2) an enterprise-wide generative AI chatbot integrated via a third-party Cloud API for customer support.

Lead Implementer Analysis & SoA Formulation:

  • Control A.2.2 (AI Policy): Included. Applicable to both assets. The organization publishes an overarching Responsible AI Policy establishing principles for credit fairness and chatbot customer transparency.
  • Control A.6.2.3 (AI System Development): Included for the credit risk scoring model (governing model code versioning and training pipeline reproducibility). Excluded for the customer support chatbot regarding internal model weight training, with the documented justification: "The chatbot relies on a third-party managed foundation model accessed via API. Direct model development controls are non-applicable; supply chain and integration risks are mitigated under Controls A.10.2 through A.10.4 and A.6.2.5 deployment testing."
  • Control A.7.2 (Data for Development and Enhancement of AI Systems): Included. Crucial for the credit risk scoring model to prevent historical dataset bias and ensure data provenance under ISO/IEC 5259.
  • Control A.8.2 (System Documentation and Information for Users): Included. Mandates clear disclosure to customers that they are interacting with an automated chatbot, satisfying both ISO 42001 Control A.8.2 and EU AI Act Article 50 requirements.

Exam Tips for Lead Implementers

  • Memorize the Structure: Remember that Annex A contains 38 controls across 9 control objectives (A.2 to A.10). A.1 is not a control objective.
  • Normative vs. Informative: Annex A is normative (selected controls become mandatory via the SoA). Annexes B, C, and D are informative (implementation guidance, risk sources, and cross-domain/MSS integration).
  • SoA Mechanics: An SoA must list all 38 controls. Omitting controls from the SoA document itself is an immediate major non-conformity during a Stage 1 audit.
  • ISO 27001 vs. ISO 42001: Remember that ISO 27001 protects information security (CIA triad), whereas ISO 42001 protects trustworthy AI behavior (fairness, safety, transparency, robustness, lifecycle governance).
Test Your Knowledge

How many normative controls and control objectives are defined in Annex A of ISO/IEC 42001:2023?

A
B
C
D
Test Your Knowledge

What is the normative status and primary functional relationship among Annexes A–D in ISO/IEC 42001?

A
B
C
D
Test Your Knowledge

Under Clause 6.1.3 of ISO/IEC 42001, how must an organization formally document and justify the exclusion of an Annex A control during a certification audit?

A
B
C
D
Test Your Knowledge

Which of the following highlights a primary distinction between ISO/IEC 27001 Annex A and ISO/IEC 42001 Annex A?

A
B
C
D