Auditen
Home / Frameworks / ISO 42001 / Leadership and the AI policy
ISO 42001 · Clause 5

Leadership and the AI policy

Leadership and the AI policy require top management to demonstrate active commitment to the Artificial Intelligence Management System (AIMS). This involves establishing a formal, documented AI policy that aligns with organizational goals and ensuring that the AIMS is integrated into the company's core business processes.

What it means

This requirement moves AI governance from a purely technical task to a strategic management responsibility. Top management cannot simply delegate AI oversight; they must provide the necessary resources, authority, and direction to ensure the system functions effectively.

The AI policy serves as the foundational document for the entire AIMS. It defines the organization's approach to AI—including its ethical boundaries, risk appetite, and objectives—and provides a framework for setting more specific AI-related goals across the company.

In practice, this means that leadership must ensure that AI is not developed or deployed in a vacuum. There must be clear alignment between how the organization uses AI and its overall corporate mission and legal obligations.

How to meet it

Evidence an auditor asks for

  • The documented AI Policy, including version control and evidence of formal approval by top management.
  • Minutes from management review meetings that demonstrate leadership's involvement in AIMS decision-making and resource allocation.
  • An organizational chart or updated job descriptions showing assigned responsibilities for the AIMS.
  • Records proving the policy was communicated to staff (e.g., email broadcasts, intranet acknowledgement logs, or training attendance sheets).

Common pitfalls

  • Treating the AI policy as a "check-the-box" exercise by using generic templates that do not reflect the organization's actual AI use cases.
  • A disconnect where top management signs the policy but lacks basic understanding of the risks and objectives it outlines.
  • Failing to provide sufficient resources (time or money) to execute the commitments made in the policy, leading to a "paper-only" compliance system.