Compliance Framework Alignment
ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system (AIMS), Clauses 4–10 ISO/IEC 42001:2023 — Clause 6.1 (AI risk assessment 6.1.2, AI risk treatment 6.1.3, AI system impact assessment 6.1.4) and Clause 6.2 (AI objectives) ISO/IEC 42001:2023 — Annex A control objectives A.2 (Policies related to AI) to A.10 (Third-party and customer relationships) ISO/IEC 42005:2025 — Guidance for the AI system impact assessment process ISO/IEC 23894:2023 — Guidance on AI risk management EU AI Act (Regulation (EU) 2024/1689) — risk-based obligations, incl. Article 27 fundamental-rights impact assessment (optional alignment) NIST AI Risk Management Framework (AI RMF 1.0) — Govern, Map, Measure, Manage functions (optional alignment) This is an AI Management System (AIMS) policy under ISO/IEC 42001:2023 — a management SYSTEM establishing governance, risk, controls and continual improvement across the AI lifecycle, not a stand-alone AI-use policy. ISO/IEC 42001 certification requires a full AIMS implementation, including an AI risk assessment and treatment process, an AI system impact assessment process, a Statement of Applicability against Annex A, internal audits and management review by an accredited certification body. This is a governance template, not legal, certification or conformity-assessment advice.
ACME AI TECHNOLOGIES PVT LTD AI MANAGEMENT SYSTEM (AIMS) POLICY Aligned with ISO/IEC 42001:2023
Effective Date [Effective Date]
Review Date [Review Date]
Standard ISO/IEC 42001:2023 (AIMS)
Role in AI value chain Developer / provider of AI systems
AI Accountable Owner Priya Nair (Chief AI Officer / Head of Responsible AI )
AI Governance Contact ai-governance@company.com Management Statement — CEO / MD name (for management statement) , CEO/MD:
Acme AI Technologies Pvt Ltd is committed to the responsible development and use of artificial intelligence. We establish, implement, maintain and continually improve an AI Management System (AIMS) conforming to ISO/IEC 42001:2023. Top management is accountable for this AIMS, provides the resources it needs, and integrates AI governance and responsible-AI principles into how we design, deploy and operate AI systems.
1. AI Policy Statement and Objectives
This AI Management System (AIMS) Policy sets Acme AI Technologies Pvt Ltd 's direction for the governance of artificial intelligence and satisfies the top-level AI policy required by ISO/IEC 42001:2023 Clause 5.2 and Annex A control A.2 (Policies related to AI). Acme AI Technologies Pvt Ltd commits to developing and using AI that is lawful, ethical and trustworthy, and to managing AI risks and impacts systematically. In line with Clause 6.2 (AI objectives), the organisation sets and monitors measurable AI objectives — for example: no unmitigated high or unacceptable AI risks in production; an AI system impact assessment completed before every material deployment or change; defined human-oversight for every AI system that affects people; and closure of AI corrective actions within target timeframes. Objectives are reviewed at management review and updated as the AIMS matures.
2. Context of the Organisation and Interested Parties
In accordance with Clause 4, Acme AI Technologies Pvt Ltd determines the internal and external issues relevant to its AI activities and the needs and expectations of interested parties. Acme AI Technologies Pvt Ltd acts as developer / provider of ai systems. Interested parties include: individuals and groups affected by AI outputs (data subjects, end users, vulnerable and under-represented groups); customers and business partners; employees who build or operate AI; regulators and supervisory authorities; auditors and certification bodies; and society at large. The scope of the AIMS covers: Scope of the AI management system . The scope, the organisation's role(s), and the boundaries of the AIMS are documented and kept current.
3. Leadership, Roles and Responsibilities
Top management demonstrates leadership and commitment to the AIMS (Clause 5) and ensures it is integrated into the organisation's processes. Overall accountability for the AIMS rests with Priya Nair , Chief AI Officer / Head of Responsible AI (ai-governance@company.com ). Consistent with Annex A control A.3 (Internal organisation), roles, responsibilities and authorities for AI are defined and communicated, including: an accountable owner for AI governance; system, product or model owners accountable for each AI system; a function (or committee) responsible for AI risk, ethics and impact review; and named oversight roles able to monitor, override or stop AI systems. Segregation of duties and escalation paths — including to senior management or the board for high-impact matters — are established. Where the organisation acts as a deployer, responsibilities allocated to it by upstream providers are also recorded.
4. AI Risk Management
Acme AI Technologies Pvt Ltd operates a documented AI risk management process satisfying Clause 6.1 and informed by ISO/IEC 23894. It comprises: (a) AI risk assessment (Clause 6.1.2) — a repeatable process to identify AI risks and rate them by likelihood and consequence against defined risk criteria and the organisation's AI objectives, covering risks to individuals, groups and society as well as to the organisation; (b) AI risk treatment (Clause 6.1.3) — selecting treatment options (modify, avoid, share/transfer, or retain) and determining the necessary controls; and (c) comparison of the selected controls against Annex A and production of a Statement of Applicability (SoA) that records which controls apply, the justification for their inclusion or exclusion, and their implementation status. Residual AI risks are formally accepted by the accountable owner. Risks are recorded in an AI risk register and reviewed on a defined cycle and on trigger events.
5. AI System Impact Assessment Process
In accordance with Clause 6.1.4 and Annex A control objective A.5 (Assessing impacts of AI systems), and following the process and documentation guidance of ISO/IEC 42005:2025, Acme AI Technologies Pvt Ltd establishes and maintains a process to assess the impacts of AI systems on individuals, groups and society. An AI system impact assessment is completed before deployment and repeated on material change, retraining, or a newly identified harm. Each assessment documents the intended purpose and reasonably foreseeable misuse, the affected parties, and potential harms across fairness, safety, privacy, security, transparency, human autonomy and environmental dimensions, together with likelihood, severity, mitigations, residual impact and an acceptability decision. Where the system processes personal data, the assessment is aligned with the Data Protection Impact Assessment required under the DPDP Act, 2023 (India) or Article 35 GDPR (EU). Where the EU AI Act applies, the process is designed to also satisfy the Article 27 fundamental-rights impact assessment for high-risk AI systems. Impact assessments are retained as controlled records and feed the AI risk register.
6. Annex A Controls — Policies, Organisation and Resources (A.2–A.4)
Acme AI Technologies Pvt Ltd implements the Annex A controls selected in its Statement of Applicability, starting with the foundational areas: A.2 Policies related to AI — this policy and supporting topic-specific policies (data, transparency, human oversight, acceptable use, security) are documented, approved, communicated and reviewed; A.3 Internal organisation — AI roles, responsibilities and reporting lines are defined as set out above; and A.4 Resources for AI systems — the organisation identifies and documents the resources its AI systems depend on, including data, tooling and computing resources, human competence, and information about the AI systems themselves, so that resources are adequate, appropriate and under control across the lifecycle.
7. Annex A Controls — AI System Life Cycle and Data (A.6–A.7)
A.6 AI system life cycle — Acme AI Technologies Pvt Ltd defines responsible-AI objectives and requirements for AI systems and manages their design, development, verification and validation, deployment, operation and monitoring, and retirement, with documentation, testing and change control at each stage so that systems behave as intended before and during use. A.7 Data for AI systems — the organisation governs data used to develop and operate AI, addressing data provenance, quality, relevance and representativeness, data preparation, and the acquisition and use of data (including personal and special-category data) in a lawful and controlled manner, because data quality directly shapes the fairness, accuracy and reliability of AI outputs.
8. Annex A Controls — Information, Use and Third Parties (A.8–A.10)
A.8 Information for interested parties of AI systems — Acme AI Technologies Pvt Ltd provides appropriate information to users and affected parties, including documentation of intended use and limitations, how to report concerns or contest outcomes, and disclosure where a person is interacting with, or subject to a decision materially informed by, an AI system. A.9 Use of AI systems — the organisation defines and enforces responsible processes and objectives for the operational use of AI, including acceptable-use conditions and monitoring so systems are used within their intended purpose. A.10 Third-party and customer relationships — responsibilities are allocated and managed across the AI value chain: suppliers of AI systems, models, data and services are assessed and bound by contractual AI, security and data obligations, and information needed by customers to use the organisation's AI responsibly is provided.
9. Responsible-AI Principles
All AI systems in scope are governed by the following responsible-AI principles, which inform risk criteria, impact assessments and control selection: (a) Fairness — actively identifying and mitigating unfair bias and discriminatory outcomes across affected groups; (b) Transparency and explainability — being open about the use of AI and providing explanations proportionate to the stakes of the decision; (c) Human oversight — ensuring a competent person can understand, monitor, intervene in, override or stop each AI system that can affect people; (d) Accountability — assigning clear ownership for every AI system and for acting on assessments and incidents; (e) Safety and reliability — designing, testing and monitoring AI to perform robustly and to fail safely; (f) Privacy and data protection — applying data minimisation, purpose limitation and security to personal data used by AI; and (g) Security — protecting AI systems, models and data against adversarial attack, poisoning, leakage and misuse. These principles are mapped to the NIST AI RMF functions — Govern, Map, Measure and Manage — for organisations that adopt that framework alongside ISO/IEC 42001.
10. Support — Competence, Awareness, Communication and Documentation
Under Clause 7, Acme AI Technologies Pvt Ltd provides the resources, competence, awareness, communication and documented information needed for the AIMS. Personnel who develop, procure, operate or oversee AI hold the necessary competence, evidenced by training and records; awareness of this policy and of individuals' AIMS responsibilities is maintained across the organisation; internal and external communication relevant to the AIMS is planned; and documented information required by ISO/IEC 42001 and by the organisation is created, controlled and retained as evidence of a functioning management system.
11. Operation
Under Clause 8, Acme AI Technologies Pvt Ltd plans, implements and controls the processes needed to meet AIMS requirements and to carry out the actions determined in planning. This includes operationalising the AI risk assessment and treatment (Clauses 6.1.2–6.1.3) and the AI system impact assessment (Clause 6.1.4) at the points in the lifecycle where they are required, controlling planned changes and reviewing the consequences of unintended changes, and managing externally provided processes, products and services relevant to the AIMS so that operational controls remain effective in practice.
12. Performance Evaluation — Monitoring, Internal Audit and Management Review
Under Clause 9, Acme AI Technologies Pvt Ltd monitors, measures, analyses and evaluates the performance and effectiveness of the AIMS against its AI objectives and metrics. The organisation conducts internal audits of the AIMS at planned intervals to confirm it conforms to ISO/IEC 42001 and is effectively implemented. Top management performs a management review at least annually covering the status of AI risks and impacts, audit results, incidents and complaints, the performance of AI systems, changes affecting the AIMS, and opportunities for improvement, and records the resulting decisions and actions.
13. Improvement and Continual Improvement
Under Clause 10, Acme AI Technologies Pvt Ltd continually improves the suitability, adequacy and effectiveness of the AIMS. When a nonconformity or AI incident occurs, the organisation reacts to contain it, evaluates the need to eliminate its cause so it does not recur, implements corrective action, and reviews the effectiveness of that action, updating AI risks, impact assessments and controls as needed. Lessons from incidents, monitoring, audits and management review are fed back into the AI risk and impact processes so that governance strengthens over time.
14. Policy Compliance, Enforcement and Review
Compliance with this AIMS Policy and its supporting policies is mandatory for all Personnel and for third parties acting for Acme AI Technologies Pvt Ltd . Violations may result in disciplinary action up to and including termination and, where applicable, legal consequences. Priya Nair , Chief AI Officer / Head of Responsible AI is responsible for monitoring compliance. This policy is reviewed at least annually, following significant AI incidents, major organisational or technological change, or changes in applicable law or standards. The next scheduled review date is [Review Date]. Approved changes are communicated to all Personnel.
Annex A Control Areas — Statement of Applicability Summary Annex A objective Control area Applies Owner A.2 Policies related to AI Yes Priya Nair , Chief AI Officer / Head of Responsible AI A.3 Internal organisation Yes Priya Nair , Chief AI Officer / Head of Responsible AI A.4 Resources for AI systems Yes [Resource / data owner] A.5 Assessing impacts of AI systems Yes [Impact assessment owner] A.6 AI system life cycle Yes [AI system / product owner] A.7 Data for AI systems Yes [Data governance owner] A.8 Information for interested parties of AI systems Yes [Product / comms owner] A.9 Use of AI systems Yes [Operations owner] A.10 Third-party and customer relationships Yes [Procurement / vendor owner]
Illustrative summary — replace the "Applies" and "Owner" columns with the organisation's actual Statement of Applicability decisions. Under ISO/IEC 42001, each Annex A control's inclusion or exclusion must be justified against the AI risk assessment; Annex A is a reference set, not a fixed checklist.
This AI Management System (AIMS) Policy has been approved by the management of Acme AI Technologies Pvt Ltd and is effective from [Effective Date].
CEO / Managing Director
CEO / MD name (for management statement)
______________________
AI Accountable Owner
Priya Nair
______________________