Skip to content

ISO 42001 Annex A controls

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 42001

ISO 42001's Annex A is the AI-governance control set — the concrete things you do to manage AI responsibly, selected to fit your risk.

Controls selected by risk

As in ISO 27001, ISO 42001 pairs the mandatory management clauses with an Annex of controls you choose from based on your AI risk assessment. You do not implement every control blindly — you select the ones relevant to your AI systems and risks, and document the decision in an applicability statement (the AIMS equivalent of the SoA).

What the controls cover

  • AI lifecycle: responsible development, testing, deployment, and decommissioning of AI systems.
  • Data: governance over the data used to develop and operate AI (provenance, quality, privacy).
  • Transparency and information for users; human oversight of AI decisions.
  • Impact assessment — the effects of AI systems on individuals and society.

Familiar shape, new substance

The mechanism (select, justify, document, implement, evidence) is identical to ISO 27001, but the substance is AI-specific — the controls address risks security management never considered: fairness, explainability, oversight, and societal impact. That novelty is the whole reason the standard exists.

Map to your AI systems

In practice you apply the Annex controls to the AI systems in your inventory, scaled to each system's risk. SentinelPanda links the ISO 42001 controls to your AI system inventory and keeps the applicability statement and evidence current.

ISO 42001 explained Building an AI system inventory AI impact assessments

Run your compliance program in one workspace.