ISO 42001
An Overview of ISO 42001 Requirements
ISO 42001 Annexes (Annex A–D)

ISO 42001 Annexes (Annex A–D)

In addition to its main clauses, ISO/IEC 42001 includes several annexes that support and expand the core requirements of the standard. While the clauses define what an organization must do to achieve certification, the annexes help explain how those requirements can be interpreted and implemented in practice. Not all annexes are audited in the same way. Annex A is central to certification because it contains the reference AI controls used to build the Statement of Applicability (SoA). Annexes B, C, and D are primarily informative, meaning they are not audited clause-by-clause, but they strongly influence how organizations interpret requirements, assess AI risks, and implement effective governance mechanisms.
  • Annex A – Reference controls: A structured catalogue of AI governance controls that can be selected and justified in the Statement of Applicability (SoA); covers governance, risk, data, lifecycle, robustness, safety, transparency, and incidents.​
  • Annex B – Guidance and examples: Provides implementation guidance and illustrative examples on how to apply requirements and controls in practice (for example, how to run AI impact assessments or set AI metrics).​
  • Annex C – Risk sources and objectives: Lists typical AI risk sources (bias, security, misuse, explainability, data quality, etc.) and governance objectives, helping to design risk‑based controls and KPIs.​
  • Annex D – Integration and sector mapping: Shows how ISO 42001 can be aligned with other standards (for example, ISO 27001, 27701, 9001) and applied to sector‑specific AI use cases.​
Annexes B–D are generally informative (guidance) rather than strictly auditable, but they strongly influence how you design a practical AIMS.

Download the SOC 2 prepkit for free.

We’ve consolidated all the basics. Check where you stand, and access ready-made templates to kickstart your SOC 2 journey.
soc 2 light shadow

The Sprinto advantage

The SOC 2 certification process can feel overwhelming. Sprinto simplifies this journey by automating up to 80% of the work, making it up to 5X faster and saving up to 60% of costs. Beyond just passing the audit, it maintains continuous compliance through real-time monitoring of security controls with 200+ integrations.  

With Sprinto doing the heavy lifting, you can focus on growing your business with the confidence that your security and compliance are always one step ahead.
hub-soc-2-dark
Sprinto: Your ally for all things compliance, risk, governance
support-team