Skip to content

Scope, clauses & Annex A

ISO/IEC 42001 is a management-system standard. Its scope is not simply the AI system selected on an intake form. Define the organisation, functions, sites, activities, technologies and lifecycle responsibilities covered by the AIMS.

Record:

  • Scope name and version.
  • Organisational and physical boundaries.
  • Functions, business units and sites.
  • Activities across development, provision, procurement and use.
  • Included AI systems or system classes.
  • Interfaces and dependencies.
  • Interested parties and relevant requirements.
  • Exclusions and why they do not affect the ability to achieve intended AIMS outcomes.
  • Accountable owner and approver.
  • Approval date and change triggers.

The scope is saved as it is edited. The visible save status distinguishes an unsaved change, saving in progress, successful save and a save failure that needs retry. Do not leave the page while a failure remains unresolved.

Establish internal and external issues, interested parties, the AIMS scope and the processes needed to establish, implement, maintain and improve it.

Assess top-management leadership, integration into business processes, resources, policy, responsibilities and reporting.

Assess risks and opportunities, AI risk criteria, risk assessment and treatment, AI system impact assessment, objectives, plans and controlled change.

Assess resources, competence, awareness, communication and the creation, control, availability, protection, retention and change of documented information.

Assess operational planning and control and the repeated performance of AI risk assessment, treatment and impact-assessment processes in the operating lifecycle.

Assess monitoring, measurement, analysis, evaluation, internal audit and management review. The focus is whether the AIMS is suitable, adequate and effective, not just whether activities occurred.

Assess nonconformity handling, corrective action and continual improvement, including whether causes are addressed and remediation effectiveness is verified.

Gamut separates compound clause statements into 173 atomic checks. This matters because a clause can contain several distinct duties—for example to define criteria, perform an activity, retain documented information and review results.

For each atomic check:

  • Read its clause anchor and advisory.
  • Determine the evidence population.
  • Inspect design and operating evidence.
  • Test a representative sample.
  • Record conformity and assurance separately.
  • Raise a finding where adverse evidence remains.

The wording in Gamut is assessment guidance. The licensed standard remains the normative source.

Annex A provides a reference set of AI controls organised around themes including:

  • AI policy.
  • Internal organisation.
  • Resources for AI systems.
  • Impact assessment.
  • AI system lifecycle.
  • Data.
  • Information for interested parties.
  • Use of AI systems.
  • Third-party and customer relationships.

Gamut represents 38 Annex A controls individually. Each requires an applicability decision in the Statement of Applicability.

For every Annex A control, record:

  • Applicable, not applicable or still undetermined.
  • Risk and requirement basis.
  • Implementation or treatment status.
  • Evidence.
  • Exclusion justification and alternative treatment where relevant.
  • Owner and review.

An exclusion is not valid merely because the control is inconvenient or because another framework does not require it. The decision should be traceable to scope, risks, opportunities, interested party requirements and selected treatment.

Review the AIMS scope after:

  • Acquisition, restructuring or new sites.
  • A materially different AI product, service or role.
  • Entry into a new jurisdiction or regulated sector.
  • Significant outsourcing or provider change.
  • New training, foundation-model or agentic activity.
  • Major incident or nonconformity trend.
  • Change to interested-party requirements.
  • Certification programme or audit-cycle change.