DoAIRight
ISO/IEC 42001

ISO 42001 Mandatory Documents and Records Checklist

PUBLISHED 06 AUG 2026

To comply with ISO/IEC 42001:2023, an organization must maintain and retain specific documented information across its Artificial Intelligence Management System (AIMS). Mandatory ISO 42001 documents include the AIMS scope, AI policy, risk and impact assessment methodologies, and AI objectives. Mandatory records consist of evidence proving these processes are executed, such as risk assessment results, competence records, internal audit reports, and management review minutes. Preparing these artifacts thoroughly ensures your organization is ready for an accredited certification audit under ISO/IEC 42006.

Mandatory Documents vs. Mandatory Records in ISO 42001

ISO management system standards use the single term "documented information" to cover both living documents and historical records. However, ISO/IEC 42001 distinguishes between two types of requirements:

  • Documented information to be maintained (Documents): Policy statements, procedures, methodologies, and framework definitions. These are living files that guide operations and must be kept up to date.
  • Documented information to be retained (Records): Historical evidence showing that standard requirements were met, controls were executed, and decisions were documented. Records cannot be altered retroactively.

Establishing both categories is critical for internal governance and third-party verification.

Clause-by-Clause ISO 42001 Mandatory Documented Information

To achieve certification readiness, organizations must prepare mandatory documents and records aligned with Clauses 4 through 10 of the standard:

Clause 4: Context of the Organization

  • Scope of the AIMS (Clause 4.3): A formal document defining the boundaries, applicability, internal/external issues, and affected stakeholders of your AI management system.

Clause 5: Leadership

  • AI Policy (Clause 5.2): High-level policy establishing top management's commitment to responsible AI, legal compliance, risk mitigation, and continuous improvement.
  • Roles and Responsibilities (Clause 5.3): Documentation detailing authorities and responsibilities assigned for AI oversight and ethical governance.

Clause 6: Planning

  • AI Risk Assessment Process & Results (Clause 6.1): Documented methodology for identifying and evaluating AI risks, accompanied by execution records.
  • AI Impact Assessment Process & Results (Clause 6.1 / Annex A.5): Documented framework to assess potential impacts of AI systems on individuals, specific groups, and society at large, alongside actual impact assessment records.
  • AI Objectives and Action Plans (Clause 6.2): Measurable operational goals for responsible AI and the strategic plans designed to achieve them.

Clause 7: Support

  • Competence Records (Clause 7.2): Proof of employee skills, training, education, and professional qualifications relevant to managing AI risks.
  • Documented Information Control Procedures (Clause 7.5): Guidelines governing how AIMS documentation is created, updated, approved, and protected.

Clause 8: Operation

  • Operational Planning and Control Information (Clause 8.1): Operating procedures, development lifecycle guidelines, and evidence that AI processes run under controlled conditions.
  • AI System Life Cycle Documentation (Clause 8.1 / Annex A.6): Logs and records tracking AI system design, specification, verification, validation, deployment, and decommissioning.

Clause 9: Performance Evaluation

  • Monitoring and Measurement Records (Clause 9.1): Data and logs measuring AI system performance, accuracy, fairness, and compliance metrics.
  • Internal Audit Results (Clause 9.2): Formal audit programs, plans, and audit reports proving regular internal evaluations of the AIMS.
  • Management Review Minutes (Clause 9.3): Recorded decisions, outcomes, and actions taken during executive reviews of AI management performance.

Clause 10: Improvement

  • Nonconformity and Corrective Action Records (Clause 10.1): Documentation of system failures, incident investigations, root cause analyses, and corrective measures implemented.

Key Annex A Control Documentation

Beyond core clause requirements, ISO/IEC 42001 Annex A specifies controls that require tailored documentation based on your Statement of Applicability (SoA):

  • Policies Related to AI (Annex A.2): Specific topic-level policies covering ethical AI guidelines, data privacy, and safe system development.
  • Data Management & Traceability Records (Annex A.7): Documentation detailing data acquisition, cleaning, labeling, lineage, and bias mitigation strategies.
  • Information for Interested Parties (Annex A.8): Transparency notices, user disclosures, and system documentation provided to end-users and impacted parties.
  • Third-Party and Vendor Records (Annex A.10): Contracts, due diligence assessments, and audit logs managing third-party AI suppliers and foundational model providers.

Streamlining ISO 42001 Documentation

Over-documenting creates unnecessary administrative burden, while missing critical records leads to audit nonconformities. Focus on creating clear, concise procedures and automated logging mechanisms wherever possible.

Platforms like DoAIRight provide free readiness assessment tools and structured implementation guidance to help organizations build a compliant document structure. Note that while readiness tools simplify gap analysis and preparation, formal ISO/IEC 42001 certification must be issued independently by an accredited certification body following rigorous human-led audits.

Frequently asked

What is the difference between ISO 42001 documents and records?

Documents are living governance tools (such as policies, methodologies, and guidelines) that describe how work should be done. Records are historical proof (such as audit logs, impact assessment outputs, and training records) proving those policies were followed.

Are AI Impact Assessments mandatory under ISO 42001?

Yes. ISO/IEC 42001 explicitly requires documented methodologies and recorded outcomes for assessing AI impacts on individuals, groups, and society.

Can automated platforms generate all ISO 42001 mandatory documented information?

Software can supply templates, policy frameworks, and readiness tracking, but your organization must customize policies to your context and retain actual operational evidence generated by human review and daily operations.

Does DoAIRight issue ISO 42001 compliance certificates?

No. DoAIRight provides tools and gap assessments to prepare organizations for certification. Official ISO/IEC 42001 certificates are granted exclusively by independent, accredited certification bodies.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score