Checklist for Clause 5.3 of ISO/IEC 42001 (AIMS): Roles and Responsibilities

1. Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 5.2 of ISO/IEC 42001 - AI Policy, developed directly from the PECB auditing slide provided and expanded into clear, evidence-based audit criteria that align with how PECB / IAS-accredited auditors evaluate AI policy maturity, communication, and effectiveness.

This checklist ensures the AI Policy is not symbolic, but operational, communicated, and effective.

2. ISO/IEC 42001 - Clause 5.2: AI Policy

Audit Checklist (Policy Design, Communication & Effectiveness)


#

Clause 5.2 Requirement Area

Audit Objective

Audit Questions (Checklist)

Expected Evidence

Conformance (Y/N/Partial)

Findings / Gaps

Risk Rating

Improvement Actions

5.2-1

Policy Existence

Confirm formal policy

Has the organization developed and documented an AI Policy?

Approved AI Policy document

5.2-2

Purpose Alignment

Verify organizational fit

Is the AI Policy appropriate to the organization's purpose, size, context, and AI usage?

Policy rationale; context mapping

5.2-3

Strategic Alignment

Confirm leadership intent

Is the AI Policy aligned with the organization's strategic direction and AI strategy?

Strategic plan; AI roadmap

5.2-4

Policy Content Completeness

Verify ISO requirements

Does the AI Policy include all required elements of ISO/IEC 42001 Clause 5.2, including principles, commitments, and governance intent?

Clause mapping matrix

5.2-5

Commitment to Requirements

Confirm compliance intent

Does the policy include a commitment to meet applicable legal, regulatory, contractual, and ethical AI requirements?

Legal register; compliance commitments

5.2-6

Commitment to Improvement

Validate improvement pledge

Does the policy include a commitment to continual improvement of the AIMS?

Policy statements; improvement framework

5.2-7

Framework for Objectives

Confirm objective linkage

Does the AI Policy provide a framework for establishing AI objectives?

Objectives framework; KPIs

5.2-8

Approval & Ownership

Verify leadership accountability

Has top management approved and taken ownership of the AI Policy?

Signed policy; approval records

5.2-9

Document Control

Confirm controlled information

Is the AI Policy controlled as documented information (versioning, approval, access)?

DMS records; version history

5.2-10

Internal Communication

Assess awareness

Is the AI Policy communicated within the organization to relevant roles and functions?

Training records; intranet postings

5.2-11

External Availability

Confirm stakeholder access

Is the AI Policy available to relevant interested parties, where appropriate?

Website publication; shared communications

5.2-12

Understanding & Awareness

Validate comprehension

Is there evidence that relevant personnel understand the AI Policy and their responsibilities?

Interviews; awareness assessments

5.2-13

Implementation Evidence

Confirm operationalisation

Is the AI Policy implemented in practice, influencing decisions, controls, and behaviours?

Operational decisions; control mappings

5.2-14

Consistency of Practice

Prevent paper compliance

Are AI-related activities consistent with the AI Policy, without contradictions?

Audit results; incident reviews

5.2-15

Objective Alignment

Verify effectiveness

Are AI objectives aligned with and derived from the AI Policy?

Objectives register; performance metrics

5.2-16

Effectiveness Review

Assess results

Has the organization reviewed the effectiveness of the AI Policy in achieving intended outcomes?

Management review minutes

5.2-17

Policy Review & Update

Confirm currency

Is the AI Policy reviewed and updated when context, risks, or AI usage changes?

Review logs; revision history

5.2-18

Policy Enforcement

Confirm accountability

Are breaches of the AI Policy identified, addressed, and corrected?

NCRs; disciplinary records


3. Auditor's Conclusion - Clause 5.2

Assessment Area

Conclusion

Overall Conformance Status

☐ Conform ☐ Minor NC ☐ Major NC

AI Policy Maturity

☐ Basic ☐ Defined ☐ Embedded ☐ Optimised

Communication Effectiveness

☐ Effective ☐ Partially Effective ☐ Ineffective

Risk of Policy Failure

☐ Low ☐ Medium ☐ High

4. Common Auditor Findings (AI Policy)

Auditors frequently raise nonconformities where:

  • Policy exists but staff are unaware or misunderstand it
  • Policy commitments are not reflected in objectives or controls
  • Policy is generic and not tailored to AI use cases
  • No evidence of effectiveness review or improvement
  • Policy contradicts actual AI practices

This checklist explicitly prevents those failures.

5. ISOLTX Enablement Mapping

Clause 5.2 is operationalised via:

  • DMS → Controlled AI Policy
  • PERFORMANCE → Policy-driven objectives & KPIs
  • CMS / CAS-CAL → Policy-to-requirement mapping
  • AUDIT → Policy effectiveness testing
  • I²MAS → Policy breach incidents

It transforms the AI Policy from a statement of intent into an enforceable governance instrument.

6. Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!