Why Clause 10.1 Is More Than a Checkbox
Every ISO management system standard built on the harmonised structure includes a clause on continual improvement. For most practitioners, it sits quietly in Clause 10, gets a brief mention in the management review, and then disappears until the next audit cycle. ISO 42001 is different. Continual improvement in an AI Management System (AIMS) is not a background obligation. It is an active, ongoing response to a technology that changes faster than any audit cycle can track.
On this page
Clause 10.1 of ISO 42001 states that the organisation shall continually improve the suitability, adequacy, and effectiveness of the AIMS. That sentence is identical to what you will find in ISO 9001, ISO 14001, and ISO 27001. But the context around it, the AI system impact assessments, the rapidly shifting risk landscape, the ethical obligations, and the regulatory environment, makes the practical demands of this clause far more intense than in any other standard.
This article unpacks what Clause 10.1 actually requires, why AI-specific factors make it harder to satisfy, and what genuine improvement looks like in an AIMS audit. Whether you are managing an AIMS, building one, or auditing one, this is where the system either earns its credibility or exposes its weaknesses.
What the Clause Actually Requires
The text of Clause 10.1 is brief. It requires the organisation to continually improve the suitability, adequacy, and effectiveness of the AIMS. Those three words carry real weight and are worth separating out.
Suitability
Suitability asks whether the AIMS is still the right system for the organisation and its AI activities. As AI tools are adopted, retired, or upgraded, the system that was designed twelve months ago may no longer fit what the organisation is actually doing. A suitability question is: does the scope still reflect reality? Are the policies still relevant to the AI systems in use? Has the organisation taken on AI activities that the current AIMS was not designed to govern?
Adequacy
Adequacy asks whether the AIMS has enough in it. Are the controls sufficient? Are the resources appropriate? Is the documented information complete enough to support consistent operation? An adequate AIMS does not just exist on paper. It has enough substance to actually govern AI development, procurement, and deployment in practice.
Effectiveness
Effectiveness asks whether the AIMS is achieving what it is supposed to achieve. Are the AI objectives being met? Are risks being treated as planned? Are incidents being investigated and resolved? Are impact assessments leading to real decisions rather than filed reports?
Improvement under Clause 10.1 means the organisation is actively working to make the system more suitable, more adequate, and more effective over time. It is not about maintaining the status quo. It is about forward movement.
Exemplar Global Recognised Training ProviderRTP No. 310970What Makes AI Improvement Different
If you have worked with ISO 9001 or ISO 14001, you already understand the mechanics of continual improvement. You use data from monitoring, internal audits, management reviews, and corrective actions to identify gaps and drive change. The same inputs apply in ISO 42001. But several factors specific to AI make the improvement obligation harder to satisfy in practice.
The Technology Moves Faster Than the System
In a quality management system, the processes being governed tend to be relatively stable. A manufacturing line does not fundamentally change every six months. AI systems do. A large language model that was assessed as low risk in January may be operating at a different capability level by July. New versions are released. New use cases emerge. New integrations are built. The AIMS must be responsive enough to keep pace with that rate of change, which means improvement cannot wait for the annual management review.
Risk Profiles Shift Without Warning
Under ISO 42001, the organisation is required to conduct AI risk assessments and AI system impact assessments. These assessments are not one-off exercises. Clause 8.4 requires impact assessments to be repeated at planned intervals and whenever significant changes occur. Improvement under Clause 10.1 is partly about using the outputs of those repeated assessments to update controls, revise policies, and adjust objectives. If the risk profile of an AI system changes and the AIMS does not respond, that is a failure of continual improvement.
The Regulatory Environment Is Actively Developing
AI governance is one of the most active areas of regulatory development globally. The EU AI Act, Australia's voluntary AI Ethics Framework, and sector-specific guidance from bodies like ASIC and the ACCC are all evolving. An AIMS that was adequate against last year's compliance obligations may not be adequate against this year's. Continual improvement in ISO 42001 requires the organisation to monitor the external environment and update the system in response. This connects directly back to Clause 4.1 and 4.2, where the organisation identifies its context and interested parties.
Ethical Obligations Are Not Static
ISO 42001 is built on principles of responsible AI, including fairness, transparency, accountability, and human oversight. Community expectations around these principles are shifting. What was considered an acceptable level of algorithmic transparency two years ago may now be seen as insufficient. Improvement under Clause 10.1 includes revisiting whether the organisation's approach to responsible AI still meets the expectations of its stakeholders.
Where Improvement Inputs Come From in an AIMS
Genuine continual improvement requires genuine inputs. In an AIMS, those inputs come from several interconnected sources.
AI Objectives and Performance Data
Clause 6.2 requires the organisation to set measurable AI objectives. Clause 9.1 requires monitoring and measurement of AIMS performance. The data produced by that monitoring is a primary input for improvement. If an objective is consistently not being met, the organisation needs to understand why and act. If an objective is consistently exceeded, it may be time to set a more ambitious target. Either way, the data should be driving decisions.
Internal Audit Findings
The internal audit programme under Clause 9.2 should be generating findings that identify gaps between what the AIMS requires and what is actually happening. Those findings feed into corrective actions under Clause 10.2 and, at a higher level, into the improvement agenda under Clause 10.1. An internal audit that finds the same issues cycle after cycle is evidence that continual improvement is not working. For a deeper look at how the internal audit process works in an AIMS, the article on internal audit requirements in ISO 42001 covers the Clause 9.2 requirements in detail.
AI System Impact Assessments
Impact assessments are one of the distinctive features of ISO 42001. When an impact assessment identifies new or changed impacts, including effects on fairness, privacy, safety, or human rights, the organisation needs to respond. That response is an improvement action. The assessment itself is not the improvement. What the organisation does with the findings is what counts.
Management Review Outputs
Clause 9.3 requires top management to review the AIMS at planned intervals. The outputs of that review must include decisions and actions related to improvement opportunities. A management review that produces no improvement actions is not meeting the standard. For a practical look at what the management review covers in an AIMS, the article on management review of an AIMS explains what Clause 9.3 expects.
Nonconformities and Corrective Actions
Clause 10.2 addresses nonconformity and corrective action. Every corrective action that eliminates a root cause is itself an improvement. When corrective actions are effective and sustained, they contribute to the overall improvement of the AIMS. When they are superficial or not verified for effectiveness, they do not.
External Developments
Regulatory changes, new guidance from standards bodies, incidents at other organisations, and shifts in stakeholder expectations are all legitimate inputs for AIMS improvement. The organisation should have a process for monitoring the external environment and feeding relevant developments into the system.
What Auditors Look for Under Clause 10.1
When an auditor examines Clause 10.1 in an ISO 42001 audit, they are not looking for a policy statement that says the organisation is committed to continual improvement. Every organisation has one of those. They are looking for evidence that improvement is actually happening.
A Trend of Improvement Over Time
The most convincing evidence of continual improvement is a demonstrable trend. Objectives that have been progressively tightened. Risk ratings that have reduced as controls have matured. Audit findings that have decreased in severity or frequency. Internal processes that have been simplified or made more reliable. If the system looks exactly the same as it did two years ago, that is a concern.
Decisions Linked to Data
Auditors will ask how improvement decisions are made. If the answer is that someone had an idea in a meeting, that is not a system. If the answer is that monitoring data showed a gap, a root cause analysis was conducted, and a specific action was taken and verified, that is a system. The linkage between data, decision, action, and verification is what distinguishes genuine improvement from activity that happens to be called improvement.
Responsiveness to Change
Given how quickly AI technology and the surrounding environment change, auditors will be interested in whether the AIMS has demonstrated responsiveness. Has the system been updated in response to a new AI tool being deployed? Has a policy been revised in response to a regulatory development? Has an impact assessment triggered a change to how a system is used? Responsiveness is evidence of a living system.
Improvement Actions That Are Tracked and Closed
Improvement opportunities identified in management reviews, internal audits, and impact assessments should be tracked. Auditors will want to see that improvement actions are assigned, have target dates, and are followed up. An improvement register or equivalent mechanism is useful here. Open improvement actions that have been sitting without progress for extended periods are a red flag.
Common Weaknesses Auditors Find in AIMS Improvement
Having conducted audits across a range of management systems, the patterns of weakness in Clause 10 are consistent. In an AIMS context, a few specific patterns are worth calling out.
Improvement Disconnected from AI-Specific Inputs
Some organisations treat AIMS improvement as if it were identical to QMS improvement. They run an internal audit, raise a corrective action, close it out, and call that continual improvement. That is necessary but not sufficient. Improvement in an AIMS needs to be driven by AI-specific inputs: impact assessment findings, AI objective performance, and changes in the AI system landscape. If none of those inputs are visible in the improvement process, the system is not functioning as intended.
Impact Assessments That Do Not Drive Change
Impact assessments are resource-intensive. Organisations sometimes conduct them thoroughly and then file the results without acting on them. An impact assessment that identifies a fairness concern or a privacy risk and produces no follow-up action is not contributing to improvement. Auditors will trace the path from assessment finding to action taken.
Objectives That Never Change
If the AI objectives set under Clause 6.2 have not changed in two years, either the organisation has achieved perfection or the objectives are not being used to drive improvement. Neither explanation is reassuring. Objectives should evolve as the system matures and as the AI environment changes.
No Mechanism for External Input
Many organisations have strong internal improvement loops but no formal mechanism for bringing in external developments. When a new piece of AI guidance is published, or when a significant AI incident occurs elsewhere in the industry, does it get reviewed? Does someone assess whether it has implications for the AIMS? If the answer is no, the system is not adequately monitoring its context.
Practical Steps to Make Clause 10.1 Real
If you are responsible for an AIMS and want to make sure Clause 10.1 is genuinely satisfied, rather than just documented, here are practical steps that work in practice.
Build an Improvement Register
Create a simple register that captures improvement opportunities from all sources: internal audits, management reviews, impact assessments, objective monitoring, and external inputs. Each entry should have an owner, a target date, and a status. Review it regularly, not just at the annual management review.
Set Objectives That Require Real Effort
AI objectives under Clause 6.2 should be challenging enough that achieving them requires deliberate action. If every objective is met comfortably every period, they are not driving improvement. Review them at least annually and ask whether they are still stretching the organisation in the right direction.
Connect Impact Assessment Findings to Actions
Every impact assessment should produce a documented outcome. Where findings indicate a concern, there should be a corresponding action. Where findings confirm that controls are working, that should also be documented. The assessment and the action register should be visibly connected.
Monitor the External Environment Formally
Assign responsibility for monitoring AI-related regulatory and guidance developments. This does not need to be a full-time role. It can be a standing agenda item in team meetings, a subscription to relevant publications, or a quarterly review of the compliance obligations register. The key is that it is assigned and actioned, not left to chance.
Use Management Review to Set Direction
The management review is the most powerful improvement mechanism in the system if it is run well. Top management should be reviewing performance data, hearing about impact assessment outcomes, and making decisions about where to invest improvement effort. If the management review is a reporting exercise rather than a decision-making forum, it is not fulfilling its role.
Exemplar Global Recognised Training ProviderRTP No. 310970Connecting Clause 10.1 to the Broader AIMS
Continual improvement does not sit in isolation. It is the output of a system that is monitoring its own performance, identifying gaps, and responding to change. In ISO 42001, the improvement loop runs through Clause 6 (planning and objectives), Clause 8 (operations and impact assessments), Clause 9 (performance evaluation), and Clause 10 (improvement and corrective action). If any part of that loop is weak, the improvement output will be weak.
For auditors working on ISO 42001, understanding how Clause 10.1 connects to the rest of the standard is essential. The article on auditing corrective action and continual improvement in ISO 42001 provides practical guidance on how to audit these clauses together.
For organisations building or maturing an AIMS, the message is straightforward. Clause 10.1 is not satisfied by having a policy that mentions improvement. It is satisfied by demonstrating that the system is actually getting better, that AI risks are being managed more effectively, that ethical obligations are being taken more seriously, and that the system is keeping pace with a technology that does not stand still.
Training for ISO 42001 Auditors and Practitioners
Understanding how to apply and audit Clause 10.1 in an AI management system context requires more than reading the standard. It requires understanding how the AIMS operates as a whole, how AI-specific requirements like impact assessments and risk treatment connect to the improvement cycle, and how to gather evidence that distinguishes genuine improvement from documented activity.
Audit Workshop offers training for ISO 42001 at Foundation, Internal Auditor, and Lead Auditor levels, delivered by a practitioner with direct experience conducting certification audits across complex management systems. If you are building your AIMS capability or preparing to audit one, the training is designed to give you the practical skills to work with this standard in the real world, not just pass an exam.













