Skip to main content

iso-42001-logo-300x300

ISO 42001 Clauses and Annexes Course

Short-format video series to help you understand the structure of ISO 42001, the world’s first AI management system standard.

This free course covers Clauses 4–10 and Annex A, so you can build a foundational understanding of how the standard is organized and what’s required for certification. Whether you’re considering implementation or already preparing for audit, this series will help you confidently move forward

Course Introduction

Introducing the “ISO 42001 Fundamentals” course, led by Sawyer Miller, Advisory & Assurance Director at risk3sixty. Join us to explore the structure of ISO 42001; including Clauses 4–10 and Annex A controls, and learn what it takes to build an AI Management System (AIMS) that’s audit-ready and aligned with global standards.

Lets Dive In

Overview of ISO 42001 Clauses 4-10

This video covers:

  • What Clauses 4–10 encompass in ISO 42001
  • How governance, risk, and leadership translate into AI-specific requirements
  • A clause-by-clause overview of the AI Management System structure

Annex 2: Crafting AI Policies in ISO 42001

This overview includes:

  • How to create and formalize policies specific to AI development and use
  • The importance of aligning AI policies with broader governance frameworks
  • Documentation expectations for certification under ISO 42001

Annex 3: Structuring AI Roles in ISO 42001

This video covers:

  • Structuring AI roles and accountability within your organization
  • Establishing channels for raising concerns during an AI system’s lifecycle

Annex 4: Managing AI Resources in ISO 42001

This overview includes:

  • How ISO 42001 requires organizations to define, apply, and monitor risk treatment plans for AI systems
  • Examples of controls that can mitigate AI-specific risks across use cases
  • Documentation and evaluation practices aligned with Clause 6 

Annex 5: Assessing Impacts of ISO 42001 AI Systems

This concise overview includes:

  • Risk assessment methods tailored to AI systems
  • Identifying potential harms and documenting impact evaluations

Annex 6: AI Systems Lifecycle of ISO 42001

This concise overview includes:

  • Requirements for managing AI systems through design, deployment, and retirement
  • Lifecycle governance, change control, and monitoring triggers

Annex 7: Data for AI Systems in ISO 42001

This concise overview includes:

  • Data governance rules specific to AI: consent, quality, storage, and data deletion
  • Ensuring compliance and integrity throughout the data lifecycle

Annex 8: Information for Interested Parties of ISO 42001

This concise overview includes:

  • How to structure AI information sharing, transparency, and stakeholder communication
  • Aligning AI reporting practices with ISO 42001 requirement

Annex 9: Use of AI Systems in ISO 42001

This concise overview includes:

  • Requirements for documenting how AI systems are used within the organization
  • How to define and monitor intended use cases, limitations, and safeguards
  • Ensuring AI usage aligns with stated objectives, values, and risk tolerance

Annex 10: Third-party and Customer Relationships in ISO 42001

This concise overview includes:

  • How ISO 42001 addresses AI-related risks across third-party providers and customer interactions
  • Responsibilities for ensuring external parties comply with your AI policies and risk controls
  • Key documentation and oversight practices for managing outsourced AI services or tools