Auditen
Home / Frameworks / ISO 42001 / Context and scope of the AI management system
ISO 42001 · Clause 4

Context and scope of the AI management system

Clause 4 requires organizations to define the boundaries and parameters of their AI Management System (AIMS). You must identify internal and external factors that influence your AI objectives, determine which stakeholders have requirements for your AI systems, and formally document exactly what is—and is not—included in the AIMS scope.

What it means

In practice, this clause prevents you from implementing controls in a vacuum. Before deciding how to manage AI risks or quality, you must first understand the "context" of your organization. This includes external factors like regulatory environments (e.g., the EU AI Act), industry standards, and market pressures, as well as internal factors like corporate culture, existing technical infrastructure, and resource availability.

You are also required to identify "interested parties." These are stakeholders—such as customers, regulators, employees, or shareholders—who may be impacted by your use of AI. You must determine their specific needs and requirements because these directly influence the risk assessment and control selection processes later in the standard.

Finally, you must establish a formal scope. The scope is the boundary of your AIMS; it defines which business units, products, or geographic locations are governed by these rules. Without a clearly defined scope, an organization cannot effectively measure compliance or provide auditors with a baseline for verification.

How to meet it

Evidence an auditor asks for

  • A documented Context Analysis report identifying internal and external issues.
  • An Interested Parties Matrix listing stakeholders and their associated AI-related requirements.
  • A signed Scope Statement or Policy document that defines the physical, organizational, and technical boundaries of the AIMS.
  • Records of management review meetings where the context and scope were discussed and approved.

Common pitfalls

  • Defining a scope that is too broad (e.g., "all AI in the company") without having the operational capacity to actually govern every single instance.
  • Treating context as a static document rather than updating it when new regulations emerge or the organization's AI strategy shifts.
  • Confusing the *technical* specifications of an AI model with the *organizational* scope of the management system.