Checklist for Clause 5.3 of ISO/IEC 42001 (AIMS): Roles and Responsibilities
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 5.2 of ISO/IEC 42001 - AI Policy, developed directly from the PECB auditing slide provided and expanded into clear, evidence-based audit criteria that align with how PECB / IAS-accredited auditors evaluate AI policy maturity, communication, and effectiveness.
This checklist ensures the AI Policy is not symbolic, but operational, communicated, and effective.
2. ISO/IEC 42001 - Clause 5.2: AI Policy
Audit Checklist (Policy Design, Communication & Effectiveness)
# |
Clause 5.2 Requirement Area |
Audit Objective |
Audit Questions (Checklist) |
Expected Evidence |
Conformance (Y/N/Partial) |
Findings / Gaps |
Risk Rating |
Improvement Actions |
5.2-1 |
Policy Existence |
Confirm formal policy |
Has the organization developed and documented an AI Policy? |
Approved AI Policy document |
||||
5.2-2 |
Purpose Alignment |
Verify organizational fit |
Is the AI Policy appropriate to the organization's purpose, size, context, and AI usage? |
Policy rationale; context mapping |
||||
5.2-3 |
Strategic Alignment |
Confirm leadership intent |
Is the AI Policy aligned with the organization's strategic direction and AI strategy? |
Strategic plan; AI roadmap |
||||
5.2-4 |
Policy Content Completeness |
Verify ISO requirements |
Does the AI Policy include all required elements of ISO/IEC 42001 Clause 5.2, including principles, commitments, and governance intent? |
Clause mapping matrix |
||||
5.2-5 |
Commitment to Requirements |
Confirm compliance intent |
Does the policy include a commitment to meet applicable legal, regulatory, contractual, and ethical AI requirements? |
Legal register; compliance commitments |
||||
5.2-6 |
Commitment to Improvement |
Validate improvement pledge |
Does the policy include a commitment to continual improvement of the AIMS? |
Policy statements; improvement framework |
||||
5.2-7 |
Framework for Objectives |
Confirm objective linkage |
Does the AI Policy provide a framework for establishing AI objectives? |
Objectives framework; KPIs |
||||
5.2-8 |
Approval & Ownership |
Verify leadership accountability |
Has top management approved and taken ownership of the AI Policy? |
Signed policy; approval records |
||||
5.2-9 |
Document Control |
Confirm controlled information |
Is the AI Policy controlled as documented information (versioning, approval, access)? |
DMS records; version history |
||||
5.2-10 |
Internal Communication |
Assess awareness |
Is the AI Policy communicated within the organization to relevant roles and functions? |
Training records; intranet postings |
||||
5.2-11 |
External Availability |
Confirm stakeholder access |
Is the AI Policy available to relevant interested parties, where appropriate? |
Website publication; shared communications |
||||
5.2-12 |
Understanding & Awareness |
Validate comprehension |
Is there evidence that relevant personnel understand the AI Policy and their responsibilities? |
Interviews; awareness assessments |
||||
5.2-13 |
Implementation Evidence |
Confirm operationalisation |
Is the AI Policy implemented in practice, influencing decisions, controls, and behaviours? |
Operational decisions; control mappings |
||||
5.2-14 |
Consistency of Practice |
Prevent paper compliance |
Are AI-related activities consistent with the AI Policy, without contradictions? |
Audit results; incident reviews |
||||
5.2-15 |
Objective Alignment |
Verify effectiveness |
Are AI objectives aligned with and derived from the AI Policy? |
Objectives register; performance metrics |
||||
5.2-16 |
Effectiveness Review |
Assess results |
Has the organization reviewed the effectiveness of the AI Policy in achieving intended outcomes? |
Management review minutes |
||||
5.2-17 |
Policy Review & Update |
Confirm currency |
Is the AI Policy reviewed and updated when context, risks, or AI usage changes? |
Review logs; revision history |
||||
5.2-18 |
Policy Enforcement |
Confirm accountability |
Are breaches of the AI Policy identified, addressed, and corrected? |
NCRs; disciplinary records |
3. Auditor's Conclusion - Clause 5.2
Assessment Area |
Conclusion |
Overall Conformance Status |
☠Conform ☠Minor NC ☠Major NC |
AI Policy Maturity |
☠Basic ☠Defined ☠Embedded ☠Optimised |
Communication Effectiveness |
☠Effective ☠Partially Effective ☠Ineffective |
Risk of Policy Failure |
☠Low ☠Medium ☠High |
4. Common Auditor Findings (AI Policy)
Auditors frequently raise nonconformities where:
- Policy exists but staff are unaware or misunderstand it
- Policy commitments are not reflected in objectives or controls
- Policy is generic and not tailored to AI use cases
- No evidence of effectiveness review or improvement
- Policy contradicts actual AI practices
This checklist explicitly prevents those failures.
5. ISOLTX Enablement Mapping
Clause 5.2 is operationalised via:
- DMS → Controlled AI Policy
- PERFORMANCE → Policy-driven objectives & KPIs
- CMS / CAS-CAL → Policy-to-requirement mapping
- AUDIT → Policy effectiveness testing
- I²MAS → Policy breach incidents
It transforms the AI Policy from a statement of intent into an enforceable governance instrument.
6. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!