Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

ISO 42001 Documentation Requirements and Audit Records

Explore ISO 42001 documentation requirements, including AI policies, risk records, impact assessments and audit evidence for AIMS certification readiness.

  1. Home
  2. Knowledge Centre
  3. ISO 42001 Documentation Requirements and Audit Records

ISO 42001 Documentation Requirements and Audit Records

ISO 42001 Documentation Requirements and Audit Records
Understand the documentation required for ISO 42001, including AI policies, risk assessments, impact assessments, the Statement of Applicability, operational records and audit evidence. This guide explains how organisations can organise, control and maintain their AI Management System (AIMS) documentation for certification readiness.

ISO 42001 Documentation Requirements: Documents, Policies and Audit Records

Artificial intelligence is becoming part of business operations, from customer service and software development to data analysis, automation and decision support.

As organizations introduce AI into their activities, they need a structured way to document responsibilities, assess risks, maintain oversight and retain evidence of relevant controls.

ISO/IEC 42001:2023 establishes requirements for an Artificial Intelligence Management System (AIMS). An important part of this system is maintaining documented information that reflects how AI-related activities are managed.

For organizations preparing their documentation, the main challenge is not producing a large collection of forms. It is identifying which documents are relevant, keeping them current and ensuring that records reflect actual business practices.

This guide explains ISO 42001 documentation requirements, key documents, policies, records and audit evidence.

What Are ISO 42001 Documentation Requirements?

ISO 42001 documentation requirements concern the documented information an organization establishes, maintains and retains to support its Artificial Intelligence Management System.

This information may include:

  • Policies and documented commitments

  • Defined responsibilities

  • AI system and activity records

  • Risk assessment and treatment information

  • Control-related documentation

  • Operational procedures

  • Monitoring and performance records

  • Internal audit and management review evidence

  • Nonconformity and corrective action records

Documentation helps demonstrate how the organization manages AI-related activities and maintains oversight.

The required documentation will depend on the organization's size, AI activities, system complexity, management-system scope and applicable obligations.

A company developing AI products may require different records from an organization using external AI applications for internal business functions.

Is There a Fixed List of Documents Required for ISO 42001?

ISO/IEC 42001:2023 does not establish one identical documentation package or document count for every organization.

The standard identifies documented information requirements, while the organization determines the appropriate documentation structure according to its context and activities.

A practical documentation review should consider:

  • AI development, provision or use

  • Number and type of AI systems

  • Organizational structure

  • Applicable legal and contractual obligations

  • AI-related risks and impacts

  • Existing management-system arrangements

  • Relevant controls and operational processes

The purpose is to maintain sufficient documented information to support implementation and demonstrate conformity with applicable requirements.

ISO 42001 Documents Required: Main Documentation Categories

1. Artificial Intelligence Management System Scope

The AIMS scope identifies the organizational activities, functions, locations and AI-related processes covered by the management system.

It should accurately describe the defined boundaries and reflect actual operations.

For example, a technology company may include AI software development, integration, deployment support and AI-enabled services where these activities fall within its intended scope.

2. AI Policy

An AI policy communicates the organization's direction and commitments concerning artificial intelligence management.

Depending on its activities, it may address:

  • Responsible AI management

  • Governance responsibilities

  • Risk management

  • Compliance with applicable requirements

  • Human oversight where relevant

  • Monitoring and continual improvement

The policy should be approved, communicated and maintained as appropriate.

It should reflect the organization's actual AI activities rather than rely on generic wording.

3. AI Roles and Responsibilities

AI governance may involve senior management, IT, information security, legal, compliance, product owners and operational teams.

Relevant documented information may include:

  • Organization charts

  • Responsibility matrices

  • Role descriptions

  • AI governance committee responsibilities

  • Approval arrangements

  • Process ownership records

Responsibilities should be proportionate to the organization's size and complexity.

4. AI System Inventory

An AI system inventory helps identify systems and applications relevant to the AIMS.

Depending on the organization, it may record:

  • AI system or application name

  • Business purpose

  • System owner

  • Internal or external provider

  • Intended users

  • Relevant data sources

  • Deployment status

  • Associated risks

  • Review and monitoring arrangements

Maintaining an accurate inventory helps prevent AI applications from being overlooked across departments.

5. AI Risk Assessment and Risk Treatment Records

Organizations should establish an appropriate approach for identifying, assessing and treating relevant AI-related risks.

Potential considerations include:

  • Data quality and suitability

  • Information security

  • Privacy-related concerns

  • Unreliable or unintended outputs

  • Human oversight

  • Operational disruption

  • Third-party dependencies

  • Misuse or inappropriate application

  • Applicable legal and contractual obligations

Relevant records may include the assessment methodology, identified risks, evaluation results, treatment decisions, assigned responsibilities and monitoring arrangements.

A risk register may be used where appropriate, provided it reflects the actual risk-management process.

6. AI Impact Assessment Information

Where applicable, organizations should maintain information relating to AI impact assessment activities.

This may include:

  • Assessment criteria

  • Identified impacts

  • Mitigation measures

  • Approval information

  • Decisions

  • Review outcomes

The assessment approach should reflect the organization's AI activities, relevant risks and applicable requirements.

7. Statement of Applicability (SoA)

The Statement of Applicability records the controls considered for the management system, their applicability and relevant implementation status or justification.

ISO 42001 includes controls in Annex A. Organizations should evaluate these in relation to their context, risks, requirements and management-system scope.

The SoA should reflect documented decisions rather than be treated as a routine form-filling exercise.

8. AI Operational Procedures

Operational documentation explains how relevant AI activities are managed.

Depending on the organization's scope, this may cover:

  • AI system development

  • Deployment and operational changes

  • Data management

  • Human oversight

  • Supplier and third-party AI services

  • System monitoring

  • Incident handling

  • Performance evaluation

  • System retirement or withdrawal

Procedures may be integrated into existing documentation where responsibilities and controls remain clear.

9. Competence and AI Awareness Records

Organizations should maintain relevant evidence that personnel have the competence and awareness needed for their assigned responsibilities.

Examples include:

  • Training plans

  • Attendance records

  • Competence assessments

  • Role-specific qualifications

  • Awareness communications

  • Training effectiveness reviews

The records should correspond to the responsibilities of the personnel involved.

10. Supplier and Third-Party AI Records

Where external AI platforms, software providers, cloud services or other relevant technology suppliers are used, organizations may maintain records relating to their management.

These may include:

  • Supplier evaluations

  • Contractual requirements

  • Risk reviews

  • Approval information

  • Monitoring arrangements

  • Supplier communications

The organization should identify relevant third-party services and dependencies within the AIMS.

11. AI Monitoring and Performance Records

Monitoring information helps demonstrate how relevant AI activities and management-system processes are evaluated.

Depending on the organization's activities, records may include:

  • Monitoring results

  • Performance indicators

  • AI-related incident trends

  • Control effectiveness reviews

  • Management reporting

  • Improvement actions

Monitoring should align with relevant objectives and identified risks.

12. Internal Audit Records

Internal audit records provide evidence that the organization evaluates its AIMS against applicable requirements.

Relevant documented information may include:

  • Internal audit programme

  • Audit scope and criteria

  • Audit plans

  • Findings

  • Nonconformity records

  • Corrective actions

  • Follow-up results

Internal audits should examine actual implementation and effectiveness rather than document availability alone.

13. Management Review Records

Management review enables senior management to evaluate the continuing suitability, adequacy and effectiveness of the AIMS.

Records may include:

  • Review inputs

  • Management-system performance information

  • Audit results

  • Changes affecting the system

  • Resource requirements

  • Decisions

  • Assigned action items

Records should demonstrate that relevant matters were reviewed and decisions were followed up.

14. Nonconformity and Corrective Action Records

When an issue is identified, the organization should have a process for addressing it and evaluating corrective-action effectiveness.

Supporting evidence may include:

  • Description of the issue

  • Immediate correction

  • Cause analysis

  • Corrective action

  • Assigned responsibility

  • Completion evidence

  • Effectiveness review

The objective is to address underlying issues rather than simply close findings.

ISO 42001 Documentation Checklist

Use this checklist to review the availability of relevant documented information.

  • AIMS scope is defined.

  • AI policy is established.

  • AI responsibilities are assigned.

  • Relevant AI systems and activities are identified.

  • Applicable requirements are considered.

  • Risk assessment methodology is established.

  • Risk assessment and treatment information is maintained.

  • Relevant impact assessment activities are addressed.

  • Applicable controls have been evaluated.

  • Statement of Applicability is maintained where applicable.

  • Operational processes are documented.

  • Competence and awareness evidence is available.

  • Relevant supplier arrangements are addressed.

  • Monitoring information is retained.

  • Internal audit records are available.

  • Management review records are maintained.

  • Nonconformities and corrective actions are tracked.

  • Document control arrangements are established.

This is a preparation checklist, not a universal mandatory document list. The organization should determine its actual requirements from the standard and its own context.

ISO 42001 Audit Evidence: What Records May Be Reviewed?

Documented information should support the demonstration of implementation.

Documentation area Examples of supporting evidence
AIMS scope Approved scope and covered activities
AI policy Approval and communication records
Governance Assigned responsibilities
Risk management Assessment and treatment records
Controls Applicability and implementation evidence
Competence Training and competence records
Operations Process implementation records
Monitoring Performance and review information
Internal audit Programme, findings and follow-up
Management review Review records and decisions
Corrective action Cause analysis and effectiveness evidence

The relevant evidence depends on the organization's activities and applicable requirements.

A procedure that exists but is not followed does not, by itself, demonstrate effective implementation.

Common ISO 42001 Documentation Mistakes

Using Generic Templates Without Adaptation

Documents should reflect actual AI activities, risks and responsibilities. Generic templates may leave important operational matters unaddressed.

Maintaining Documents Without Implementation

A written procedure alone does not demonstrate that the process is operating. Relevant implementation evidence should be retained.

Overlooking Third-Party AI Applications

AI tools used by different departments may be missed when there is no complete understanding of organizational AI use.

Maintaining an Incomplete AI Inventory

An incomplete inventory can affect risk assessment, oversight and monitoring.

Treating the SoA as a Form-Filling Exercise

Control applicability should be based on organizational context, relevant risks and documented decisions.

Creating Excessive Paperwork

Duplicated procedures and unnecessary forms can make the management system difficult to maintain.

Documentation should be controlled, proportionate and useful to those responsible for AI governance.

Can ISO 42001 and ISO 27001 Documentation Be Integrated?

Organizations with an existing ISO 27001 management system may already maintain information security policies, risk assessment processes, competence records, internal audit arrangements, management reviews and corrective action processes.

Some of these arrangements may support ISO 42001 implementation.

However, ISO 27001 and ISO 42001 have different purposes. An integrated approach may reduce duplication, but AI-specific management-system requirements must still be addressed.

Where relevant, organizations may also consider privacy management arrangements such as ISO 27701.

Documentation Considerations for UAE Businesses

For organizations operating in Dubai, Abu Dhabi, Sharjah, Ajman, Ras Al Khaimah, Fujairah and Umm Al Quwain, documentation should reflect the actual AI activities and locations included in the management-system scope.

Examples of differing documentation needs include:

  • AI software developers: Development, testing, deployment and monitoring records.

  • SaaS providers: AI-enabled services and third-party dependencies.

  • Financial technology companies: Operational, security and contractual risk information.

  • Professional service firms: Records concerning AI use in service delivery.

  • Organizations using AI internally: Defined responsibilities, acceptable-use arrangements and relevant oversight.

Businesses operating from DIFC, ADGM, DMCC, JAFZA, Dubai Internet City, Dubai Silicon Oasis, Masdar City, KEZAD and other UAE locations should determine the relevant scope according to their legal entity, activities and locations.

Applicable legal, regulatory, contractual and customer requirements should also be considered.

How Should ISO 42001 Documentation Be Maintained?

A practical approach involves the following activities:

Identify the relevant AI activities: Establish which systems, processes and functions fall within the AIMS.

Review existing documented information: Determine whether current governance, security, privacy, quality or operational arrangements can be used.

Identify documentation gaps: Compare existing information with applicable requirements.

Assign ownership: Establish who prepares, reviews, approves and maintains relevant documents.

Maintain implementation evidence: Retain records that demonstrate processes are operating.

Review and update: Revisit documentation when relevant activities, systems, risks or requirements change.

For information about the broader certification scope and assessment arrangements, see the ISO 42001 certification guide in UAE.

Conclusion

ISO 42001 documentation should provide a clear record of how an organization manages AI-related activities, responsibilities, risks and controls.

A practical documentation system is not measured by the number of forms it contains. Its value lies in whether the information is relevant, controlled, current and supported by actual implementation.

Organizations should begin with their AI system inventory, scope, risk assessment and governance arrangements before developing additional documentation.

Discuss ISO 42001 Documentation and Audit Requirements

SCS Certification can discuss the certification assessment process, proposed scope and applicable audit arrangements for organizations preparing an AI management system.

Prepare Your Organization for ISO 42001 Certification
https://www.scscertification.com/contactus.php

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

Relevant documented information may include the AIMS scope, AI policy, objectives, risk assessment and treatment records, Statement of Applicability, operational information, audit records and management review evidence.
No. The documented information required depends on the organisation's context, scope, AI activities, risks and applicable requirements.
A document generally provides instructions, policies or defined arrangements. A record provides evidence that an activity, decision or result has occurred.
An inventory is a practical way to maintain visibility of AI systems within the AIMS scope and support governance and risk management.
It should establish the organisation's direction and commitments for AI management and provide a framework for relevant AI objectives.
Relevant evidence may include assessment criteria, identified risks, evaluation results, treatment decisions, responsibilities and review records.
The SoA is an important documented element of the management system, recording applicable controls, inclusion or exclusion decisions, justification and implementation status.
Relevant external AI systems, services and suppliers should be considered within the organisation's AIMS scope and applicable risk and operational arrangements.
Depending on roles and needs, records may include training completion, competence assessments, awareness activities and role-specific learning.
Depending on the system and scope, evidence may include approvals, monitoring results, change records, incident information and relevant operational procedures.
Organisations should retain documented evidence of their internal audit programme, audit results, findings and follow-up activities.
They should demonstrate that relevant inputs were reviewed and that decisions, actions and improvement needs were recorded.
Organisations should establish suitable arrangements for approval, version control, access, revision, retention and protection of documented information.
Relevant documents and processes may be reused where suitable, but AI-specific requirements must be assessed and addressed separately.
A frequent issue is a gap between documented policies and actual operational practices, including incomplete risk records or unclear responsibilities.
Review them at planned intervals and when relevant changes occur, such as changes to AI systems, risks, suppliers or organisational responsibilities.
Yes. Digital systems can support document control and evidence management, provided the organisation maintains appropriate access, integrity, availability and retention arrangements.
No. Documentation is only one part of the assessment. The organisation must also demonstrate that its AIMS meets applicable requirements and is effectively implemented.