2.5 Clause 8, 9 & 10: Operation, Performance Evaluation & Continual Improvement Requirements

Key Takeaways

  • Clause 8.1 requires operational planning and control to implement risk treatments, manage AI lifecycles, control outsourced processes, and conduct AI Impact Assessments (AIIA).
  • Clause 8.2 and 8.3 mandate executing AI risk assessments and risk treatments at planned intervals or when significant changes occur across AI lifecycles.
  • Clause 9.1 requires systemic monitoring, measurement, analysis, and evaluation of AIMS and AI model performance, including tracking model drift, fairness, and safety logs.
  • Clause 9.2 mandates independent Internal Audits, while Clause 9.3 requires periodic Top Management Reviews to assess AIMS suitability, adequacy, and effectiveness.
  • Clauses 10.1 and 10.2 establish protocols for managing nonconformities, carrying out root-cause analysis for AI safety incidents, and driving systematic Continual Improvement.
Last updated: July 2026

2.5 Clause 8, 9 & 10: Operation, Performance Evaluation & Continual Improvement Requirements

The ultimate test of an Artificial Intelligence Management System (AIMS) lies in its operational execution, objective evaluation, and ongoing adaptation. Clause 8 (Operation) operationalizes the risk treatment plans and controls defined during planning. Clause 9 (Performance Evaluation) provides the monitoring, auditing, and executive review mechanisms to verify system efficacy. Finally, Clause 10 (Improvement) ensures that nonconformities and AI safety incidents drive systematic corrective actions and continual system enhancement.


Clause 8: Operation

Clause 8 transforms AIMS policies and risk treatment plans into active operational controls across the AI system lifecycle.

1. Operational Planning and Control (8.1)

The organization must plan, implement, and control the processes needed to meet requirements and implement actions determined in Clause 6 by:

  • Establishing operational criteria for AI processes (e.g., model performance thresholds, data validation pipelines, bias mitigation checks).
  • Implementing process control in accordance with established criteria.
  • Keeping documented information to demonstrate that processes have been carried out as planned.
  • Controlling planned changes and reviewing consequences of unintended changes.
  • Ensuring that outsourced processes and third-party AI components (e.g., foundation model APIs or pre-trained weights) are controlled.

2. AI Impact Assessment - AIIA (8.1.1)

ISO/IEC 42001 introduces a specific requirement for conducting an AI Impact Assessment (AIIA). Before deploying or significantly modifying an AI system, the organization must assess potential impacts on individuals, groups, and society—evaluating fairness, privacy, safety, human autonomy, and legal rights.

3. Executing AI Risk Assessments & Treatments (8.2 & 8.3)

The organization must perform AI risk assessments (8.2) and execute AI risk treatments (8.3) at planned intervals or when significant changes occur, maintaining documented evidence of outcomes.


Clause 9: Performance Evaluation

Clause 9 establishes the mechanisms used to evaluate whether the AIMS is operating effectively and achieving its intended outcomes.

                         +---------------------------+
                         |   CLAUSE 9 EVALUATION     |
                         +---------------------------+
                                       |
         +-----------------------------+-----------------------------+
         |                             |                             |
         v                             v                             v
+------------------+         +------------------+         +------------------+
|       9.1        |         |       9.2        |         |       9.3        |
|   Monitoring &   |         |  Internal Audit  |         |Management Review |
|   Measurement    |         |   (Conformance)  |         |   (Executive)    |
+------------------+         +------------------+         +------------------+

1. Monitoring, Measurement, Analysis, and Evaluation (9.1)

The organization must determine what needs to be monitored and measured, the methods used, when monitoring occurs, and when results are analyzed. For AI systems, key metrics include:

  • Model Performance Drift: Tracking performance degradation over time due to shifting input data distributions.
  • Fairness & Bias Metrics: Quantifying disparate impact or statistical parity across demographic groups.
  • Explainability & Transparency: Measuring model interpretability and audit trail completeness.
  • Safety & Security Logs: Recording adversarial prompt attempts, unexpected outputs, or policy violations.

2. Internal Audit (9.2)

The organization must conduct Internal Audits at planned intervals to provide information on whether the AIMS:

  • Conforms to the organization's own requirements for its AIMS and the requirements of ISO/IEC 42001.
  • Is effectively implemented and maintained. Auditors must be independent of the activity being audited to ensure objectivity and impartiality.

3. Management Review (9.3)

Top Management must review the organization's AIMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Inputs include audit results, AI metric trends, risk assessment updates, interested party feedback, and nonconformities. Outputs include decisions regarding continual improvement opportunities and necessary AIMS modifications.


Clause 10: Improvement

Clause 10 closes the PDCA loop by ensuring that deficiencies drive learning and structural enhancement.

1. Nonconformity and Corrective Action (10.1)

When a nonconformity or AI safety incident occurs (e.g., a chatbot generating dangerous instructions, a severe model bias outbreak, or an unauthorized data exposure), the organization must:

  • React promptly to control, correct, and deal with consequences.
  • Evaluate the need for action to eliminate the root causes through systematic Root Cause Analysis (RCA).
  • Implement necessary corrective actions.
  • Review the effectiveness of corrective actions taken and update AIMS risks/opportunities if necessary.

2. Continual Improvement (10.2)

The organization must continually improve the suitability, adequacy, and effectiveness of the AIMS using audit results, metric analysis, corrective actions, and management review outcomes.


Lifecycle Execution Matrix across Clauses 8, 9, and 10

PhaseStandard ClausePrimary Focus & Action ItemsKey Output / Artifact
ExecutionClause 8: OperationImplement controls, run data validation, perform AIIA, control third-party AI APIs.AIIA Report, Operational Logs, Verification Checklists.
EvaluationClause 9: PerformanceTrack model drift, measure fairness, conduct internal audits, hold executive reviews.Internal Audit Report, KPI Dashboard, Management Review Minutes.
AdaptationClause 10: ImprovementConduct root-cause analysis on AI errors, fix nonconformities, retrain models safely.Corrective Action Request (CAR), Updated SOA, Revised Models.
Test Your Knowledge

Under ISO/IEC 42001 Subclause 8.1.1, what is the primary purpose of conducting an AI Impact Assessment (AIIA)?

A
B
C
D
Test Your Knowledge

An AI recommendation model experiences 'performance drift' due to changing user behavior, leading to inaccurate outputs. Under which clause is the ongoing tracking of this phenomenon mandated?

A
B
C
D
Test Your Knowledge

What is a mandatory requirement for internal auditors conducting AIMS audits under Subclause 9.2?

A
B
C
D
Test Your Knowledge

When an AI chatbot generates unauthorized harmful advice, what immediate sequence of actions does Clause 10.1 mandate?

A
B
C
D