Writing an AI policy that meets ISO 42001: step-by-step plan and checklist

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

Anyone starting with ISO 42001 quickly arrives at the AI policy. It is one of the first documents a certification auditor requests, and it is the anchor that the rest of the AI management system hangs on: the risk assessment, the controls, the training and the oversight. Yet in practice we remarkably often see a downloaded template that says nothing about the organization itself. That falls apart immediately during an audit, and worse: it steers nothing in daily practice. In this article: what the standard requires of an AI policy, a step-by-step plan for writing it, a checklist of topics and the mistakes you want to avoid.

## What ISO 42001 requires of the AI policy

Clause 5.2 of ISO 42001 places the responsibility with top management. It establishes an AI policy that is appropriate to the purpose and context of the organization, provides a framework for setting AI objectives, and includes a commitment to meeting applicable requirements and to continual improvement of the management system. The policy must be documented, communicated internally and available to interested parties where relevant. Annex A adds the expectation that the policy gives direction to the development and use of AI systems and is aligned with other policy documents, such as the information security policy and the privacy policy.

What the standard does not prescribe: how long, how detailed or how technical the policy should be. That is exactly where things go wrong in practice. We see two-page policies full of abstract values that nobody can act on, and thirty-page policies that nobody reads. Both fail on the same point: they do not change a single decision.

## Step 1: start with context, not with text

Writing an AI policy without an AI inventory is building without a foundation. First map which AI the organization uses and develops, and which role the organization plays: do you mainly buy AI, do you develop it yourself, and are you a provider or a deployer under the EU AI Act? Also capture top management's risk appetite: what does the organization want to achieve with AI, and what does it explicitly not want? A policy for a healthcare provider using AI in triage should look fundamentally different from one for a marketing agency generating copy. Without this step, every policy becomes generic.

## Step 2: choose principles with consequences

Limit yourself to four to six principles that actually steer. The test is simple: if a principle does not change a single decision, delete it. "We use AI responsibly" steers nothing. "Decisions with legal effect or similar impact on individuals are never made fully automatically" does steer: it means a fully automated rejection of job applicants is not allowed and that such applications always have a human reviewer in the process. The same applies to transparency: whoever chooses that as a principle must accept that customers are told when they are communicating with an AI system.

## Step 3: make rules workable with three categories

The most workable AI policy rules follow a three-way split. Allowed: approved tools and applications, used within the guidelines. Allowed under conditions: new applications after an assessment, for example through an intake process or the vendor assessment. Prohibited: for example entering confidential data or personal data into unapproved public AI tools, and fully automated decision-making with legal effect. The "under conditions" category is the most important of the three. Policy that only prohibits produces shadow AI: employees then use personal accounts outside the organization's view. Workable policy provides a route to get to yes for a legitimate request.

## Step 4: assign roles and the approval process

A policy without assigned roles is a statement of intent. Record who owns the policy, who assesses and approves new AI applications (and how that connects to procurement and vendor assessment), who monitors compliance and where employees can go with questions, reports and requests for exceptions. In smaller organizations several roles can sit with one person; what matters is that responsibility is explicit and that top management remains accountable for the whole.

## Step 5: approve, communicate and maintain

Formal approval by top management is a requirement of the standard, but communication is what brings the policy to life. A PDF on the intranet is not communication. Link the policy to the AI literacy training that Article 4 of the EU AI Act requires anyway, and use concrete examples from your own organization. Finally, set up a review cycle: at least annually, plus interim reviews triggered by an incident, new regulation or the introduction of an AI application with material impact.

## Checklist: what it should minimally cover

A mature AI policy covers at least: purpose and scope, definitions (what the organization considers AI), the chosen principles, acceptable use and prohibited applications, handling of business data and personal data in AI tools, procurement and vendor assessment, requirements for in-house development and testing (if the organization builds itself), transparency towards customers and employees, human oversight, reporting and handling of incidents, roles and responsibilities, training and literacy, the exception process and the review cycle.

## Common mistakes

The five mistakes we encounter most. Adopting a template without adaptation: the policy describes development processes while the organization develops nothing, and an auditor sees through that in the first conversation. A list of prohibitions without a route to yes: the direct recipe for shadow AI. No connection to the risk assessment: policy and risks live in separate worlds, while the controls in the policy should address precisely the most important risks. Too long and too detailed: keep the core concise and work out details in underlying guidelines per topic. And finally: approve and forget, without communication, training or review.

You do not recognize a good AI policy by its length or impressive terminology, but by whether employees can determine without help what is allowed, what is not, and where to go for everything in between.

Frequently asked questions

How long should an AI policy be?+

The standard sets no length requirement. In practice a core document of three to eight pages works best, with details in underlying guidelines, for example a generative AI guideline or an assessment procedure for new applications.

Is an AI policy legally required?+

The EU AI Act does not literally require "an AI policy", but obligations such as AI literacy, human oversight and the requirements for high-risk systems cannot be demonstrated without documented policy. ISO 42001 does explicitly require the policy, in clause 5.2.

What is the difference between an AI policy and an AI strategy?+

The strategy describes what the organization wants to achieve with AI; the policy sets the frameworks and rules within which that happens. The policy should enable the strategy within top management's risk appetite, not block it.

Can the AI policy be part of the information security policy?+

With very limited AI use it can, but a separate document is usually wiser. AI touches more than security: bias, transparency and human oversight belong in it too. Do ensure explicit alignment between the two documents.

How often should the AI policy be reviewed?+

At least annually, and in the interim when triggered by an AI incident, new regulation or the introduction of an application with material impact. Record the review cycle in the policy itself.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us