Writing an AI policy for ISO 42001
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 42001
The AI policy is the apex document of your AI management system — leadership's statement of intent that every AI control hangs from.
The apex document
As ISO 27001 requires an information security policy, ISO 42001 requires an AI policy: a top-management statement of how the organisation approaches AI responsibly. It is the apex document of the AIMS — the framework of intent that the AI-specific controls and processes implement.
What it contains
A workable AI policy states your principles for responsible AI (fairness, transparency, accountability, human oversight, safety), the scope of AI it governs, the roles and responsibilities for AI governance, and the organisation's commitments — to assess impact, to oversee high-risk systems, to govern data. It frames, not duplicates, the detailed controls.
Keep it aligned to reality
The failure mode is an aspirational policy disconnected from how the company actually builds and uses AI. The policy should reflect your real AI footprint and commitments you will keep — a policy promising oversight you do not provide is worse than a modest one you honour. Align it to your AI inventory and risk.
Communicate and maintain
Like any policy, it must be approved by leadership, communicated, and reviewed as your AI use evolves. SentinelPanda holds the AI policy alongside the AIMS controls and acknowledgements, keeping it current and linked to the program.