2.1 Annex SL High-Level Structure & Harmonized Management System Principles

Key Takeaways

  • ISO/IEC 42001 follows the ISO Harmonized Structure (formerly Annex SL), establishing standardized clause titles, core text, and common definitions across Clauses 4 through 10.
  • The Harmonized Structure enables seamless integration between ISO/IEC 42001 (AIMS), ISO/IEC 27001 (ISMS), ISO 9001 (QMS), and ISO 22301 (BCMS) within an Integrated Management System (IMS).
  • Clauses 4 through 10 operationalize the Plan-Do-Check-Act (PDCA) cycle: Plan (Clauses 4, 5, 6, 7), Do (Clause 8), Check (Clause 9), and Act (Clause 10).
  • While standard Annex SL governance applies, ISO/IEC 42001 introduces AI-specific mandates including explicit AI system lifecycle management, AI risk assessments, and specialized Annex A/B/C control frameworks.
  • The Statement of Applicability (SOA) acts as the normative bridge, justifying the inclusion or exclusion of Annex A controls based on context and risk assessment outcomes.
Last updated: July 2026

2.1 Annex SL High-Level Structure & Harmonized Management System Principles

Modern organizational governance increasingly relies on standardized management systems published by the International Organization for Standardization (ISO). To ensure consistency, ease of implementation, and seamless alignment across different disciplines, ISO introduced Annex SL (now formally designated as the ISO Harmonized Structure). ISO/IEC 42001:2023—the world's first certifiable standard for an Artificial Intelligence Management System (AIMS)—is fully built upon this Harmonized Structure. For a Lead Implementer, understanding the underlying architecture of Clauses 4 through 10 is essential for building a robust AIMS and integrating it with existing management frameworks.


Overview of the ISO Harmonized Structure (Annex SL)

The ISO Harmonized Structure provides identical clause numbers, standardized clause titles, uniform core definitions, and shared normative text across all modern ISO management system standards. This standard structural blueprint ensures that an organization implementing multiple standards does not need to duplicate baseline administrative or governance mechanisms.

The normative clauses of ISO/IEC 42001:2023 spans seven key sections:

  • Clause 4: Context of the Organization — Defining internal and external factors, interested party expectations, and AIMS scope.
  • Clause 5: Leadership — Setting top management commitment, executive accountability, organizational roles, and the AI Policy.
  • Clause 6: Planning — Identifying AI risks and opportunities, establishing AI objectives, and planning structural changes.
  • Clause 7: Support — Provisioning resources, ensuring competence, fostering awareness, executing communications, and managing documented information.
  • Clause 8: Operation — Operationalizing AI risk treatments, AI system lifecycle controls, and AI Impact Assessments (AIIA).
  • Clause 9: Performance Evaluation — Monitoring metrics, evaluating AI model behavior, conducting internal audits, and carrying out management reviews.
  • Clause 10: Improvement — Managing nonconformities, handling AI incidents, taking corrective actions, and driving continual improvement.

Operationalizing the Plan-Do-Check-Act (PDCA) Cycle

The Harmonized Structure explicitly operationalizes the classic Plan-Do-Check-Act (PDCA) iterative management cycle within the AIMS architecture. This ensures that AI management is never treated as a static one-time project, but rather as an evolving operational discipline.

                     +--------------------------+
                     |   Context & Leadership   |
                     |     (Clauses 4 & 5)      |
                     +------------+-------------+
                                  |
                                  v
+-----------------------+   +------------+   +-----------------------+
|       PLANNING        |-->|     DO     |-->|         CHECK         |
|   (Clauses 6 & 7)     |   | (Clause 8) |   |       (Clause 9)      |
+-----------------------+   +------------+   +-----------------------+
            ^                                            |
            |                  +------------+            |
            +------------------|    ACT     |<-----------+
                               | (Clause 10)| 
                               +------------+
  1. Plan (Clauses 4, 5, 6, 7): Establish the AIMS context, secure executive leadership, formulate the AI policy, identify AI-specific risks, set measurable AI objectives, and provision required support resources.
  2. Do (Clause 8): Implement and execute operational planning, AI lifecycle controls, third-party AI supplier controls, and AI risk treatment plans.
  3. Check (Clause 9): Continually monitor, measure, analyze, and evaluate AI system behavior, audit compliance, and evaluate AIMS performance against objectives.
  4. Act (Clause 10): Take prompt corrective action when nonconformities, unexpected AI behavior, or model drift occur, driving ongoing system enhancement.

Integrated Management System (IMS) Synergies

Because ISO/IEC 42001 shares the Harmonized Structure with standards such as ISO/IEC 27001 (Information Security Management System), ISO 9001 (Quality Management System), and ISO 22301 (Business Continuity Management System), organizations can construct a unified Integrated Management System (IMS).

Rather than creating siloed policies and duplicate administrative boards, an organization can harmonize overlapping requirements:

  • Unified Leadership & Governance: Top management can oversee AI governance, information security, and quality through a combined governance board.
  • Harmonized Risk Assessment: AI risks (such as algorithmic bias or model failure) can be integrated into the broader enterprise risk management (ERM) framework alongside cybersecurity and operational risk.
  • Shared Support Infrastructure: Training, document control procedures, awareness programs, and internal audit teams can serve multiple standards simultaneously.

Annex SL Standard Clauses vs. ISO/IEC 42001 AI-Specific Focus

While Annex SL supplies the generic governance shell, ISO/IEC 42001 infuses AI-tailored requirements throughout each clause:

ClauseStandard Harmonized ElementISO/IEC 42001 AI-Specific Focus Area
Clause 4Organization Context & Interested PartiesAI system complexity, ethical concerns, societal impacts, regulatory landscape (e.g., EU AI Act), data subjects.
Clause 5Leadership & Policy CommitmentTop management commitment to responsible AI, ethical AI principles, fairness, transparency, and accountability.
Clause 6Risk & Opportunity PlanningAI-specific risk assessment, AI system impact assessment (AIIA), model lifecycle risks, Statement of Applicability (SOA).
Clause 7Resource & Competence ManagementData infrastructure, specialized AI engineering skills, data science competence, model card documentation.
Clause 8Operational Planning & ControlControls for AI system design, development, training data quality, model deployment, and third-party AI integration.
Clause 9Performance Monitoring & AuditTracking model drift, algorithmic fairness metrics, explainability evaluation, AI safety logging, internal audit.
Clause 10Nonconformity & Corrective ActionRoot-cause analysis for AI model hallucinations, bias incidents, unexpected autonomous actions, and safety breaches.

The Role of the Statement of Applicability (SOA)

A critical concept introduced in Clause 6.1.3 of ISO/IEC 42001 is the Statement of Applicability (SOA). Similar to ISO/IEC 27001, the SOA serves as the definitive normative document listing all controls from Annex A (Normative Controls), stating whether each control is selected or excluded, providing justification for exclusions, and documenting implementation status. The SOA bridges high-level Annex SL planning clauses with practical operational safeguard implementation.

Test Your Knowledge

What is the primary structural benefit of ISO/IEC 42001 adopting the ISO Harmonized Structure (formerly Annex SL)?

A
B
C
D
Test Your Knowledge

In the context of the Plan-Do-Check-Act (PDCA) cycle within ISO/IEC 42001, which set of clauses represents the 'Check' stage?

A
B
C
D
Test Your Knowledge

Which document required by ISO/IEC 42001 links the risk assessment process in Clause 6 with the operational safeguards in Annex A?

A
B
C
D