Microsoft Teams

The ISO 42001 Policy Pack — What You Actually Need

Most first attempts at an AI policy pack go one of two ways: a single vague page that says "we use AI responsibly," or twenty documents nobody's read since they were written. Neither survives an audit. ISO 42001 needs a small, coherent set of policies an auditor can trace from a statement straight to the evidence that it's actually followed.

  • Traceable to evidence
  • Built on your ISMS, not from scratch
  • Owned, not orphaned
Book a Scoping Call Back to resources

The core set

If you already hold ISO 27001, most of the policy hierarchy — document control, roles and responsibilities, management review — already exists and just needs to reference AI systems explicitly. What's genuinely new is a small, AI-specific set.

AI policy

The top-level statement of intent — what AI is used for, who's accountable, and the organisation's risk appetite for it. Short, board-approved, reviewed annually.

Acceptable use policy

What staff can and can't do with AI tools — including the ones IT didn't provision. This is the document that actually reduces shadow AI, if people know it exists.

AI risk assessment procedure

How a new AI system gets risk-tiered before it goes live, and who signs off — not a one-off exercise, a repeatable process triggered every time something new is added.

Human oversight policy

Where a human reviews or can override AI output before it affects a customer, and what happens when they do. ISO 42001 cares more about this working in practice than about the document itself.

Data governance for AI

How training and input data is sourced, labelled, and protected — usually extends your existing data classification and privacy policies rather than replacing them.

Third-party AI & supplier policy

What due diligence happens before an AI vendor or embedded model gets approved — and what evidence you keep on file to show it happened.

What good policy writing leaves out

Model-specific detail

Which specific model or vendor you use belongs in the AI system inventory, not the policy — policies should survive a vendor switch without a rewrite.

Duplicated ISMS content

If your information security policy already covers access control or incident response, reference it — don't restate it inside the AI policy pack.

Aspirational language with no owner

A policy that says what "should" happen with no named accountable person reads to an auditor as a document nobody's actually following.

Related

AI System Inventory What good actually looks like ISO 42001 Full AI governance certification Free AI Governance Checklist Score your readiness in 12 minutes

Writing an AI policy pack from a blank page?

If you already hold ISO 27001, most of this is faster than it looks. A 30-minute call will tell you how much.

Book a Scoping Call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.