ISO 42001 Annex A: 38 controls, not 39

Annex A of ISO/IEC 42001:2023 contains 38 controls across nine control objectives, numbered A.2 through A.10. The count matters less than what it’s for: Annex A is a reference set an organisation selects from through its own risk assessment, not a checklist to complete in full.

The answer

38 controls, nine control objectives, running A.2 to A.10:

Objective Covers Controls
A.2 Policies related to AI 3
A.3 Internal organisation 2
A.4 Resources for AI systems 5
A.5 Assessing impacts of AI systems 4
A.6 AI system life cycle 9
A.7 Data for AI systems 5
A.8 Information for interested parties 4
A.9 Use of AI systems 3
A.10 Third-party and customer relationships 3

That totals 38. A.6 is the one objective worth extra care if you’re counting these yourself: it’s the only control objective with a nested, two-level structure — A.6.1’s management-guidance controls, then A.6.2’s system-lifecycle controls beneath it — rather than the flat A.X.Y pattern every other objective uses. It’s the easiest place to miscount by one.

Why the number is the least useful fact about Annex A

Under Clause 6.1.3 of ISO/IEC 42001:2023, organisations select which Annex A controls to implement through their own risk treatment process, document every inclusion and every exclusion with justification in a Statement of Applicability, and may design or implement additional controls beyond Annex A entirely where their risk assessment calls for it. Annex A is a reference set to select from, not an exhaustive checklist to complete.

The practical consequence cuts against the instinct to just implement everything. An organisation that has all 38 controls in place but no documented reasoning behind its selections fails an audit on the Statement of Applicability alone. An organisation with 30 controls implemented, and clear, risk-based justification on record for the eight it excluded, passes. The count of controls implemented was never the thing being tested.

Is Annex B normative?

Annex B gives implementation guidance for each Annex A control — practical detail on how to satisfy a control you’ve selected, not a further set of obligations sitting alongside it. What that means in an audit: an organisation doesn’t have to document or justify its use of Annex B guidance in the Statement of Applicability the way it must for the Annex A controls themselves. Whatever Annex B is formally classified as, it doesn’t carry the audit-tracked weight Annex A does, and that’s the fact worth building a compliance programme around.

On the formal classification itself, the honest position is that the full standard text sits behind ISO’s paywall, and the clearest secondary description available labels Annex B “(normative)” rather than informative. Treat that label as directional rather than fully confirmed, and build your programme around the practical distinction above regardless of how the annex is formally classified.

What the other annexes are for

Annex C sets out potential AI-related organisational objectives and common risk sources — bias, security, misuse, explainability, data quality — functioning as an idea bank when populating the standard’s planning clauses, rather than a set of controls in its own right. Annex D addresses using the AI management system across different domains and sectors, including how the AIMS integrates with ISO/IEC 27001, ISO/IEC 27701, ISO 9001, and sector-specific standards such as ISO 13485 for medical devices.

How this compares to ISO 27001

ISO/IEC 27001:2022‘s Annex A runs to 93 controls across four themes — considerably larger than ISO/IEC 42001:2023’s 38, and organised around a completely different risk object: information security generally, rather than AI specifically.

ISO/IEC 42001:2023 ISO/IEC 27001:2022
Annex A controls 38 93
Number of themes 9 4
Theme breakdown Policy, org, resources, impact assessment, lifecycle, data, information, use, third parties Organisational (37), people (8), physical (14), technological (34)
Risk object AI system behaviour and impact Information confidentiality, integrity, availability

The two annexes genuinely overlap on general governance ground — policy-setting, roles and responsibilities, supplier and third-party management, documented risk treatment discipline. Where ISO/IEC 42001:2023 adds something ISO/IEC 27001:2022 was never built to cover is the AI-specific territory: bias and fairness, transparency to affected people, human oversight of automated decisions, and structured AI impact assessment. An organisation already running an ISO/IEC 27001:2022 ISMS is extending familiar governance machinery into new subject matter, not starting from nothing.

Frequently asked questions

Are all 38 controls mandatory?

No. Annex A is a reference set selected against your own risk assessment, not a checklist every organisation implements in full.

Can we exclude a control?

Yes, provided the exclusion is documented and justified in the Statement of Applicability. An undocumented exclusion is the actual audit risk, not the exclusion itself.

Do we need to implement Annex B?

Not as a separate, SoA-tracked obligation — it’s guidance to help implement the Annex A controls already selected, not an additional layer of controls sitting alongside them.

Is the Statement of Applicability actually audited?

Yes, and it’s the document an auditor checks against far more closely than a raw control count. The SoA is where the risk-based reasoning is supposed to live; an auditor testing an AIMS is testing whether that reasoning holds up, not counting how many of the 38 boxes are ticked.

Does ISO 42001 certification make us compliant with the EU AI Act?

No — they’re separate instruments, and certification under a management-system standard isn’t the same thing as the AI Act’s own presumption-of-conformity mechanism, which attaches specifically to harmonised standards cited in the Official Journal. An ISO/IEC 42001:2023 certificate is strong evidence of AI governance maturity; it isn’t itself a legal finding of AI Act compliance.