Why AI Objectives Are Different From Quality or Safety Objectives
If you have spent time setting quality objectives under ISO 9001 or environmental objectives under ISO 14001, you already understand the basic discipline. Objectives need to be measurable, assigned to someone, tracked over time, and connected to what the organisation is trying to achieve. Clause 6.2 of ISO 42001 follows the same structural logic, so the framework will feel familiar.
On this page
What makes AI objectives genuinely different is the subject matter. Artificial intelligence systems introduce risks and performance considerations that simply do not appear in traditional management systems. Fairness, transparency, explainability, bias, and societal impact are not abstract ethics concepts under ISO 42001. They are operational concerns that need to be translated into specific, trackable targets. That translation is exactly what Clause 6.2 demands of you.
This article walks through what the clause actually requires, what good AI objectives look like in practice, and the mistakes organisations commonly make when setting them for the first time.
What Clause 6.2 of ISO 42001 Actually Requires
Clause 6.2 sits within the Planning section of the standard, alongside the risk and opportunity work covered in Clause 6.1. Once you have identified your AI risks, assessed them, and decided how to treat them, Clause 6.2 asks you to establish objectives for the AI management system and plan how to achieve them.
The standard sets out a clear list of criteria that each objective must satisfy. Your AI objectives must:
- Be consistent with the AI policy established under Clause 5.2
- Be measurable, where practicable
- Take into account applicable requirements, including legal and regulatory obligations
- Be relevant to AI risk and the results of risk assessments
- Be monitored and reviewed
- Be communicated to relevant people in the organisation
- Be updated as appropriate
The standard also requires that for each objective you retain documented information on what the objective is, what resources are needed, who is responsible, when it will be completed, and how results will be evaluated. This mirrors the approach in other ISO standards, but the content of the objectives themselves requires considerably more thought when AI is involved.
Exemplar Global Recognised Training ProviderRTP No. 310970Connecting Objectives to the AI Policy and Risk Assessment
One of the most common gaps auditors find when reviewing AI management systems is a disconnect between the AI policy, the risk assessment, and the objectives. The three elements are supposed to form a coherent chain. The policy sets the direction. The risk assessment identifies what needs attention. The objectives translate both into specific, time-bound commitments.
If your AI policy commits the organisation to responsible and transparent use of AI, but your objectives make no reference to transparency or explainability, there is a disconnect. An auditor reviewing your system will ask how the objectives reflect the policy commitments, and if they cannot trace a clear line, that gap becomes a finding.
Similarly, if your risk assessment identified significant risks around data bias in a recruitment AI tool, your objectives should include something that directly addresses that risk. An objective about improving model accuracy is not a substitute for an objective about reducing bias in candidate shortlisting outcomes. The specificity matters.
Before drafting objectives, go back to your AI policy and your risk assessment output. List the key commitments in the policy. List the significant risks identified in the assessment. Your objectives should map to both. If you have a commitment or a significant risk that no objective addresses, you have a gap.
What Measurable Looks Like for AI Systems
The phrase where practicable in the measurability requirement gives organisations some flexibility, but it should not be used as an excuse to avoid measurement. In practice, almost every meaningful AI objective can be made measurable if you invest the effort in defining the right indicators.
The challenge is that some AI performance dimensions are harder to quantify than others. Accuracy and processing speed are relatively straightforward. Fairness, bias, and explainability require more deliberate measurement design. Here are some practical examples of how organisations translate AI objectives into measurable targets.
Accuracy and Reliability Objectives
An organisation using an AI system to classify customer complaints might set an objective such as: maintain complaint classification accuracy at or above 92 per cent, measured monthly against a sample of 200 manually reviewed cases. This is clear, measurable, time-bound, and assigned to whoever manages the AI system.
Bias and Fairness Objectives
An organisation using AI in recruitment might set an objective such as: ensure that shortlisting rates for candidates from any demographic group do not differ by more than 5 percentage points from the overall shortlisting rate, reviewed quarterly. This requires a defined measurement methodology, but it is entirely achievable. The organisation needs to collect demographic data, define the comparison groups, and run the analysis at each review point.
Transparency and Explainability Objectives
An organisation using AI to support credit decisions might set an objective such as: ensure that 100 per cent of declined credit applications receive a plain-language explanation of the contributing factors within 24 hours of the decision, measured through a monthly audit of 50 declined applications. This is measurable and directly addresses the transparency commitment in the AI policy.
Human Oversight Objectives
An organisation using AI to triage maintenance work orders might set an objective such as: ensure that all high-priority work orders generated by the AI triage system are reviewed by a qualified technician before despatch, with zero exceptions, measured through monthly sampling of 30 high-priority orders. This addresses the human oversight risk identified in the risk assessment and is entirely auditable.
Common Mistakes When Setting AI Objectives
Having reviewed AI management systems across various industries, certain patterns of poor objective-setting appear consistently. Understanding these mistakes helps you avoid them from the outset.
Objectives That Are Actually Policies
A statement such as we will use AI responsibly is a policy commitment, not an objective. An objective needs a target, a timeframe, a measurement method, and an owner. If you cannot answer the question how will we know when we have achieved this?, it is not an objective.
Objectives Disconnected From Actual AI Systems
Some organisations set generic AI objectives that bear no relationship to the specific AI systems they operate. If your organisation uses AI for demand forecasting and document classification, your objectives should address the risks and performance requirements of those specific systems. Generic objectives about AI ethics that do not reference any actual system are difficult to monitor and even harder to audit.
Too Many Objectives
There is a temptation to set a long list of objectives to demonstrate comprehensive coverage. In practice, a short list of well-defined, actively monitored objectives is far more valuable than a long list of vaguely worded commitments that nobody tracks. Three to six objectives for a typical AI management system is usually sufficient. More than ten becomes unmanageable.
No Plan for How to Achieve Them
Clause 6.2 requires not just that you set objectives, but that you plan how to achieve them. The plan needs to specify resources, responsibilities, timelines, and evaluation methods. An objective without a plan is a wish. Auditors will ask to see the plan, and if it does not exist, that is a nonconformity.
Objectives That Are Never Reviewed
AI systems change. Models are retrained, data sources shift, and the risk profile of a system can change significantly over time. Objectives that were appropriate twelve months ago may no longer reflect the current state of the system. Clause 6.2 requires that objectives be updated as appropriate. Build a formal review of your AI objectives into your management review agenda and your internal audit programme.
Documenting AI Objectives Properly
The documented information requirement in Clause 6.2 is straightforward but important. You need a record that captures, for each objective: the objective itself, the relevant AI system or function it applies to, the measurement method, the target value or threshold, the responsible person or role, the timeframe, the resources required, and the current status.
A simple objectives register works well for this purpose. It does not need to be complex. A spreadsheet with clearly defined columns is entirely adequate. What matters is that the information is current, accessible to relevant people, and reviewed regularly.
If you are building an AI management system from scratch, consider creating a single register that links your AI policy commitments, your risk assessment findings, and your objectives in one document. This makes the traceability visible and makes life considerably easier when an auditor asks you to demonstrate the connection between the three elements.
For practical examples of how measurable objectives are structured in related management systems, the post on example quality objectives that pass an audit provides useful reference points that translate well into the AI context.
How Auditors Assess Clause 6.2
When an auditor reviews your AI objectives, they are looking for several things. First, they want to see that the objectives exist and are documented. Second, they want to trace the connection between the objectives and the AI policy. Third, they want to confirm that the objectives address the significant risks identified in the risk assessment. Fourth, they want to see evidence that the objectives are being monitored, that results are being recorded, and that the objectives are being reviewed and updated.
An auditor will typically ask to see the objectives register, then ask to see the most recent monitoring results. If the objective is to maintain complaint classification accuracy above 92 per cent, the auditor will ask to see the monthly measurement records. If those records do not exist, or if the measurement has not been performed, that is a nonconformity against Clause 6.2 regardless of how well-written the objective itself is.
Auditors will also probe whether the objectives are genuinely connected to the AI policy and risk assessment, or whether they were written in isolation. The question can you show me where this objective comes from in your risk assessment? is a standard line of enquiry. If the person responsible for the objective cannot answer that question, the auditor has cause to dig further.
The article on auditing quality objectives: evidence to look for under Clause 6.2 covers the auditor perspective on objectives in detail, and most of that guidance applies directly to AI objectives as well.
Practical Steps to Set Up Clause 6.2 Compliance
If you are building or reviewing your AI management system and need to get Clause 6.2 right, here is a practical sequence to follow.
- Review your AI policy. List every commitment the policy makes. Each commitment should be reflected in at least one objective or control.
- Review your risk assessment output. List the significant risks. Each significant risk should be addressed either by an objective or by a specific control in the risk treatment plan.
- Draft objectives for each AI system in scope. For each system, identify the key performance and risk dimensions that need to be tracked. Draft objectives that are specific, measurable, and time-bound.
- Assign ownership. Each objective needs a named owner. That person is responsible for monitoring progress and reporting results.
- Define the measurement method. For each objective, document exactly how it will be measured, how often, and using what data source.
- Build the monitoring schedule. Decide how often each objective will be measured and by whom. Build this into your operational calendar.
- Include objectives in management review. The results of objective monitoring should be a standing agenda item at management review. This ensures top management visibility and drives the update cycle.
- Review and update at least annually. As AI systems change, objectives need to change with them. Schedule a formal review at least once per year.
Exemplar Global Recognised Training ProviderRTP No. 310970Linking Objectives to the Broader AIMS
Clause 6.2 does not operate in isolation. The objectives you set here feed directly into the operational planning requirements of Clause 8, the monitoring and measurement requirements of Clause 9.1, and the management review requirements of Clause 9.3. An AI management system that treats objectives as a standalone compliance exercise will struggle at every one of those points.
Think of the objectives as the connective tissue of the system. They translate the policy and risk assessment into operational commitments. They provide the basis for monitoring. They give management review something concrete to evaluate. And they create the improvement cycle that Clause 10 depends on.
If you are working toward ISO 42001 certification and want to understand how the full system fits together, the article on addressing risks and opportunities under Clause 6.1.1 covers the planning foundation that Clause 6.2 builds on.
For those building auditor competence in this space, the guide on how to become an ISO 42001 AI management system auditor covers the skills and knowledge needed to audit AI systems effectively, including how to assess whether objectives are genuinely fit for purpose.
Audit Workshop and ISO 42001 Training
ISO 42001 is a relatively new standard, and the auditing community is still building practical experience with it. If you are a quality manager, risk professional, or auditor looking to develop competence in AI management system auditing, Audit Workshop offers training that covers the full structure of ISO 42001, including how to assess planning requirements like Clause 6.2 in a real audit context.
The training is built by practitioners with hands-on audit experience, not just standard readers. You will come away with the ability to assess whether an organisation's AI objectives are genuinely connected to their policy and risk profile, and whether the monitoring and review processes are actually functioning. That practical capability is what separates a useful auditor from one who is simply ticking boxes.













