Continuing our multi-part blog series, today we will explore Clauses 5 and 6. Both of these clauses fall under the Plan section of the PDCA cycle. If you haven’t yet checked out Part 1, you can find it here.
Alright, let’s get right into it. If you remember from the last blog, the outcome of the exercise in Clause 4 was a documented scope statement. That scope statement will guide us through the rest of the clauses and controls. For the most part, the requirements of Clauses 5 and 6 are quite similar to those in other standards, but with some specific nuances. Let’s look at what Clauses 5 and 6 require.
Clause 5 — Leadership -
Clause 5.1 — Leadership and commitment
This clause does not require any documented information; however, an auditor can ask for evidence of its implementation. This clause guides “Top management” in ensuring the management system receives the necessary importance. Top management is defined here as someone who directs or controls an organization at the highest level. Who is considered top management can vary by company and also depends on the scope of the management system. Generally speaking, the Board of Directors, the CEO, and the CISO may be considered top management.
This clause highlights the need for top management to set the culture and direction for the organization to ensure the successful implementation of a management system. Specific to the AI management system, the clause requires top management to demonstrate leadership and commitment in various ways, such as:
- Ensuring the establishment of AI policy and objectives that are compatible with the strategic direction of the organization.
- Ensuring the integration of the AI management system with the organization’s business processes.
- Providing adequate resources, direction, and support to ensure the AI management system achieves its intended purpose.
- Communicating the importance of the AI management system and promoting continual improvement. This is stressed as an important tool to ensure the success of the AI management system.
5.2 — AI Policy
This clause has very specific needs. It requires a documented policy statement from top management establishing an AI policy that is appropriate and provides a framework for setting objectives. It also needs commitment from top management to meet the requirements and continually improve. The organization needs to communicate this policy internally and to relevant external interested parties as needed.
Going back to our fictitious company providing an AI-powered medical diagnosis support system, here is a sample policy statement:
AI Policy Statement
At XYZ Corp, we are committed to the responsible and ethical use of AI in our medical diagnosis support system. Our AI Management System (AIMS) ensures that our solutions support clinicians with accurate, transparent, and fair decision support while upholding patient privacy, safety, and regulatory compliance.
We commit to:
-Meeting all applicable legal, regulatory, and organizational requirements.
-Setting and reviewing objectives that drive the responsible development, deployment, and continual improvement of our AI systems.
-Managing AI risks throughout the system lifecycle and maintaining effective oversight and accountability.
-Allocating resources and providing training to ensure the ongoing effectiveness of the AIMS.
-Communicating this policy to all employees and relevant external stakeholders, and reviewing it regularly to ensure its continued relevance.
Through this policy, we aim to build trust, enhance patient outcomes, and continuously improve the way we manage and govern AI.
Signed,
[CEO/Top Management Name]
[Title]
[Date]
Clause 5.3 — Roles, responsibility, and authority
This last subclause also falls under top management’s responsibility. As the name suggests, they are responsible for defining and communicating the roles, responsibilities, and authorities for the AI management system throughout the organization.
Interestingly, the standard explicitly calls out that defining the responsibility for reporting on the performance of the AI management system to top management is also required. This ensures top management remains actively involved, not just at the beginning but continuously, emphasizing that this isn’t a “set it and forget it” system. It underscores the continual improvement aspect of this standard.
Another interesting point to note is that Annex A control A.3.2 — AI Roles and Responsibilities also covers the same information.
Here is a sample roles and responsibilities document for our fictitious company providing an AI-powered medical diagnosis support system.

Clause 6 — Planning
Clause 6.1 — Actions to address risk and opportunities
As the name suggests, this clause focuses on planning how the organization will identify and address AI-related risks and opportunities to ensure trustworthy and responsible AI. Since this is a planning clause, the output of this exercise will be documents explaining processes and procedures, rather than the actual assessment, which Clause 8 — Operations covers. This clause has 4 subclauses:
Clause 6.1.1 — General
This sets the direction for planning and requires using the results of previous clauses, such as organizational context, AI scope and applicability, and its intended use of AI. This clause requires producing an “AI Risk Criteria” document. Think of risk criteria as rules for judging risk. It defines the ‘how’ of evaluating risk, e.g., likelihood, Severity/Impact, Risk Levels, and Risk Acceptance Criteria. It also requires documented information on actions taken to identify AI risks and opportunities.
Note 1: If more than one AI system is in scope, this exercise needs to be performed for each system or a group of systems.
Note 2: Detailed guidance on how to implement AI risk management can be found in ISO/IEC 23894.
Clause 6.1.2 — AI Risk Assessment
This focuses on the process and procedure for identifying and analyzing risk. This process document outlines the systematic approach the organization will take to:
- Identify Risks: How will we identify potential risks associated with our AI systems? What methods should we use, e.g., brainstorming, checklists, etc.?
- Analyze Risks: For identified risks, how will we determine the likelihood, consequences, and risk level using the criteria defined in the AI Risk Criteria document?
- Note: The consequences (impact) should focus on the organization, individuals, and societies. It needs to utilize the output of the AI system impact assessment indicated in Clause 6.1.4.
- Evaluate Risks: Based on the analysis, what is the overall level of each risk (again, using the AI Risk Criteria document’s framework)?
- Document Risks: How will the identified, analyzed, and evaluated risks be recorded and maintained (e.g., in a risk register)?
The organization is required to maintain the Risk Assessment process document as documented information.
Clause 6.1.3 AI Risk Treatment
This clause requires defining the AI risk treatment process to select the right treatment options (accept, mitigate, transfer, or avoid), determine what controls are needed to mitigate the risk, compare and select ISO 42001 Annex A, and identify additional controls not provided in Annex A as needed. The required documented information is as follows:
- A documented risk treatment process.
- A statement of applicability that justifies including or excluding the Annex A controls.
- A risk treatment plan with approval from top management on the plan and acceptance of any residual risk. The organization also needs to communicate the risk treatment plan internally and to any relevant external interested parties.
There is an emphasis on proportionality in risk treatment, which suggests a pragmatic approach where the level of effort and resources invested in mitigating a risk should be commensurate with its potential impact.
6.1.4 — AI System Impact Assessment
This is a unique clause in ISO 42001, not present in ISO 27001. This clause requires organizations to consider how the AI system will impact not just their organization but also individuals and societies. This reflects the understanding that AI can have significant and far-reaching effects on individuals and society, requiring careful consideration of these impacts. Moreover, the directive to use the impact assessment results as an input for the risk assessment creates a crucial feedback loop, ensuring that potential societal consequences directly inform the organization’s risk management strategies.
To explain clause 6.1 better, here is a comparison of this clause with ISO 27001 Clause 6.1 to explain the key similarities and differences.

Clause 6.2 — AI Objectives and planning to achieve them
This clause is all about setting clear goals for your AI management system and figuring out how you’re going to reach them. Think of it like setting intentions and creating a roadmap. You can’t improve or manage what you haven’t defined as a target.
In essence, it’s about defining what you want to achieve with your AI management system. These objectives should be specific, measurable (where possible), achievable, relevant, and time-bound (SMART, or a variation thereof, is often a helpful framework here).
It also requires creating an action plan for each of your AI objectives — translating the “what” into a concrete “how,” with clear assignments, timelines, and resource considerations.
Clause 6.2 directly builds upon Clause 6.1 (Actions to address risks and opportunities). The risks and opportunities you identify in 6.1 will often inform the AI objectives you set in 6.2. For example:
Risk identified: Potential for bias in an AI-powered recruitment tool.
AI Objective: Reduce bias in the AI-powered recruitment tool by 15% within the next year.
Planning to achieve: Conduct bias testing, retrain the model with more diverse data, implement bias monitoring, and provide training to HR staff on interpreting the AI’s output.
Clause 6.3 — Planning for changes
Clause 6.3 of ISO 42001 emphasizes that when your organization considers making changes to its AI management system or any aspects affecting it, these changes must be planned. Essentially, it’s about thinking through changes proactively to minimize disruption and ensure the AI management system continues to function effectively.
This concludes Part 2 of this multi-series blog. I hope this was helpful. In the next part, we will focus on Clause 7: Support and Clause 8: Operations.
Leave a comment below and let me know what you think, and how you are using this information within your organization!
References
- **ISO 42001 — **Information technology — Artificial intelligence — Management system: https://www.iso.org/standard/81230.html
- NIST AI 600–1 : https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
- **ISO/IEC 22989 — **Information technology — Artificial intelligence — Artificial intelligence concepts and terminology: https://www.iso.org/standard/74296.html
- ISO/IEC 23894:2023 — Information technology — Artificial intelligence — Guidance on risk management: https://www.iso.org/standard/77304.html
Disclaimer
The content provided in this blog series is for informational purposes only and does not constitute legal, regulatory, or professional advice. While every effort has been made to ensure accuracy, readers are encouraged to consult the official ISO 42001 standard and relevant regulatory or industry experts for specific guidance. The views expressed are those of the author and do not necessarily reflect the opinions of any affiliated organizations.