ISO 42001 Annex A controls
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 42001
ISO 42001's Annex A is the AI-governance control set — the concrete things you do to manage AI responsibly, selected to fit your risk.
Controls selected by risk
As in ISO 27001, ISO 42001 pairs the mandatory management clauses with an Annex of controls you choose from based on your AI risk assessment. You do not implement every control blindly — you select the ones relevant to your AI systems and risks, and document the decision in an applicability statement (the AIMS equivalent of the SoA).
What the controls cover
- AI lifecycle: responsible development, testing, deployment, and decommissioning of AI systems.
- Data: governance over the data used to develop and operate AI (provenance, quality, privacy).
- Transparency and information for users; human oversight of AI decisions.
- Impact assessment — the effects of AI systems on individuals and society.
Familiar shape, new substance
The mechanism (select, justify, document, implement, evidence) is identical to ISO 27001, but the substance is AI-specific — the controls address risks security management never considered: fairness, explainability, oversight, and societal impact. That novelty is the whole reason the standard exists.
Map to your AI systems
In practice you apply the Annex controls to the AI systems in your inventory, scaled to each system's risk. SentinelPanda links the ISO 42001 controls to your AI system inventory and keeps the applicability statement and evidence current.