Why Documented Information Trips Up AI Management Systems
Clause 7.5 is one of those requirements that looks straightforward on paper. Maintain documented information. Control it. Keep it current. But when you are building or auditing an AI Management System under ISO 42001, the documented information requirements carry a weight that goes well beyond a folder of procedures and a document register.
On this page
The reason is simple. AI systems introduce risks and accountability questions that other management systems do not face to the same degree. Who approved the AI risk assessment? What version of the impact assessment was in place when the system was deployed? Can you demonstrate that the AI policy was communicated to the people responsible for operating the system? These are not hypothetical questions. They are exactly what an auditor will ask, and if your documented information is not in order, you will not be able to answer them.
This article walks through what Clause 7.5 of ISO 42001 actually requires, what documented information an AIMS genuinely needs, and how to control it in a way that holds up under scrutiny.
What Clause 7.5 Says and What It Means
ISO 42001 follows the harmonised structure shared by ISO 9001, ISO 14001, ISO 27001, and other modern management system standards. That means Clause 7.5 is structured the same way across all of them, with three subclauses.
Clause 7.5.1: General
The AIMS must include documented information required by the standard itself, plus any additional documented information that the organisation determines is necessary for the effectiveness of the AIMS. That second part is important. ISO 42001 does not prescribe a fixed document set. It requires you to think about what your system actually needs to function and be accountable, and then document accordingly.
For an AI Management System, this means considering the nature and complexity of your AI systems, the roles involved in operating them, the risks you have identified, and the decisions you need to be able to reconstruct after the fact.
Clause 7.5.2: Creating and Updating
When you create or update documented information, you must ensure appropriate identification and description, format and media, and review and approval for suitability and adequacy. This is not bureaucratic box ticking. It is the mechanism that gives your documents credibility. A risk assessment with no version number, no author, and no approval signature is not evidence of a controlled process. It is a draft.
Clause 7.5.3: Control of Documented Information
Documented information must be available and suitable for use where and when it is needed. It must be adequately protected. You must address distribution, access, retrieval, use, storage, preservation, change control, retention, and disposal. For AI systems, this is particularly relevant when documented information includes sensitive data about system design, training data sources, or impact assessment results.
Exemplar Global Recognised Training ProviderRTP No. 310970What Documented Information ISO 42001 Explicitly Requires
ISO 42001 specifies a number of documents and records throughout its clauses. If you are implementing or auditing an AIMS, these are the non negotiable items you need to be able to produce.
The AI Policy
Clause 5.2 requires an AI policy to be established. The policy must be available as documented information. It also needs to be communicated within the organisation and, where appropriate, to interested parties. During an audit, you should be able to show the current version of the policy, evidence that it was approved by top management, and evidence that relevant people are aware of it.
AI Roles and Responsibilities
Clause 5.3 requires that roles, responsibilities, and authorities relevant to the AIMS are assigned and communicated. While ISO 42001 does not mandate a specific document format, you need documented information that demonstrates who is responsible for what. This might be a responsibility matrix, position descriptions, or a dedicated roles and responsibilities document.
The AI Risk Assessment
Clause 6.1.2 requires the organisation to carry out an AI risk assessment. The results of the risk assessment must be retained as documented information. This is one of the most scrutinised documents in an AIMS audit. It needs to show the methodology, the AI systems assessed, the risks identified, their likelihood and consequence, and the evaluation criteria used. Critically, it must be repeatable and comparable, meaning another person following the same process should reach similar conclusions.
The AI Risk Treatment Plan
Clause 6.1.3 requires documented information on the risk treatment plan and the results of the risk treatment. The treatment plan should connect directly to the controls selected, including those from Annex A. If you have selected a control, you should be able to trace it back to a specific risk. If you have excluded a control, you need a documented justification.
The Statement of Applicability
The Statement of Applicability is the document that lists all controls from Annex A of ISO 42001, indicates whether each is applicable, and provides justification for inclusions and exclusions. It is one of the most important documents in the system. An auditor will use it as a map to verify that your risk treatment decisions are reflected in your operational controls. If the SoA says a control applies but there is no evidence of implementation, that is a nonconformity waiting to happen.
AI Objectives
Clause 6.2 requires documented information on AI objectives. These must be measurable, monitored, communicated, and updated as appropriate. The documented information should show what the objective is, how it will be measured, who is responsible, and what the timeframe is.
AI System Impact Assessments
Clause 6.1.2 and Clause 8.4 together require impact assessments for AI systems. The results of these assessments must be retained as documented information. This is one of the features that sets ISO 42001 apart from other management system standards. The impact assessment considers how an AI system affects people, including considerations of fairness, privacy, safety, and human rights. You need to be able to show that the assessment was done, who did it, when it was done, and what the outcomes were.
Competence Evidence
Clause 7.2 requires the organisation to retain documented information as evidence of competence. For an AIMS, this means evidence that people involved in AI system development, deployment, operation, and oversight have the knowledge and skills their roles require. Training records, qualifications, and competency assessments all count.
Internal Audit Results
Clause 9.2 requires documented information on the audit programme and the audit results. This includes the audit plan, audit report, and records of any nonconformities raised. The audit results feed into management review, so they need to be retained and accessible.
Management Review Results
Clause 9.3 requires documented information on the results of management review. This typically takes the form of meeting minutes or a management review report that captures the inputs reviewed, the decisions made, and the actions assigned.
Nonconformities and Corrective Actions
Clause 10.2 requires documented information on the nature of nonconformities, actions taken, the results of any corrective action, and the effectiveness of those actions. This is the evidence trail that shows your system responds to problems rather than just recording them.
Additional Documented Information Your AIMS Probably Needs
Beyond the explicitly required documents and records, most organisations implementing ISO 42001 will find they need additional documented information to make the system function and to demonstrate effectiveness during an audit.
AI System Inventory
You cannot manage risks you have not identified. An inventory of AI systems in scope, including their purpose, the data they use, the decisions they influence, and the people they affect, is foundational. ISO 42001 does not mandate this in a specific format, but without it, your risk assessment has no clear starting point and an auditor will struggle to verify coverage.
Data Governance Records
Annex A of ISO 42001 includes controls related to data for AI systems. If these controls apply to your organisation, you will need documented information about data sources, data quality checks, data lineage, and data handling procedures. These records are particularly important if your AI systems make consequential decisions affecting individuals.
Operational Procedures for AI Systems
Clause 8.1 requires operational planning and control. For AI systems, this often means documented procedures covering how systems are monitored in production, how anomalies are escalated, how models are retrained or updated, and how human oversight is maintained. The level of detail should match the risk. A low risk AI tool used internally needs less documentation than a system making credit or safety decisions.
Communication Records
Clause 7.4 covers communication requirements. If your organisation communicates with external parties about AI system use, you may need to retain records of those communications, particularly where you are disclosing AI involvement to customers or affected individuals as part of your responsible AI commitments.
Common Documented Information Failures in AIMS Audits
Having audited management systems across multiple standards and industries, certain patterns come up repeatedly when documented information is not well managed. The same problems appear in AIMS audits.
Documents That Exist But Are Not Controlled
The risk assessment exists as a spreadsheet on someone's desktop. The impact assessment is a Word document with no version number. The AI policy is in a shared folder with no access controls and no record of who approved it. These documents may contain good thinking, but they are not controlled documented information. An auditor cannot rely on them as evidence of a functioning system.
Records That Are Missing When Needed
Clause 7.5.3 requires that documented information is available where and when it is needed. If the person responsible for an AI system cannot access the current impact assessment or does not know where to find the risk treatment plan, that is a control failure, not just an inconvenience.
Outdated Documents Still in Circulation
This is one of the most common findings in any management system audit. An old version of the AI policy is still displayed on the intranet. The risk assessment has not been updated since a new AI system was deployed six months ago. The Statement of Applicability references controls that have since been changed. Obsolete documents need to be identified as such and prevented from unintended use.
Records That Do Not Demonstrate Effectiveness
A training record that shows someone attended an AI ethics briefing is not the same as evidence that they are competent to perform their role. A management review agenda is not the same as evidence that the review actually happened and produced decisions. The documented information needs to demonstrate what actually occurred, not just that a process was scheduled.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Advice for Getting Clause 7.5 Right
Here is what works in practice, based on real audit experience rather than textbook theory.
Start With a Document Register
Build a simple register that lists every document and record required by ISO 42001, plus any additional ones your organisation has determined are necessary. For each item, record the document title, unique identifier, current version, owner, review date, and storage location. This register becomes your control mechanism and your audit preparation tool in one.
Assign Document Owners, Not Just Custodians
Every controlled document needs an owner who is responsible for keeping it current, not just someone who stores it. The owner of the AI risk assessment should be the person who understands it well enough to update it when a new system is deployed or when a risk materialises. If ownership is unclear, documents drift.
Build Review Triggers Into Your Processes
Documents should be reviewed when something changes, not just on a calendar schedule. For an AIMS, the triggers should include the deployment of a new AI system, a significant change to an existing system, the results of an impact assessment, a nonconformity or incident involving an AI system, and changes to relevant legislation or organisational context. A review schedule is a minimum. Triggered reviews are what actually keep documents current.
Keep the Statement of Applicability Connected to Reality
The SoA is only useful if it reflects actual decisions and actual implementations. Review it whenever the risk treatment plan changes. If a control is listed as applicable, make sure there is evidence of implementation. If a control is excluded, make sure the justification is documented and defensible. An auditor will cross reference the SoA against the risk treatment plan and against operational evidence. Gaps between them are findings.
Make Documented Information Accessible to the People Who Need It
This sounds obvious but it is regularly overlooked. The people operating AI systems need to be able to access the procedures that govern those systems. The people conducting impact assessments need access to the methodology and previous assessments. If your document management system requires three layers of approval to view a procedure, it is not meeting the intent of Clause 7.5.3.
How Auditors Approach Clause 7.5 in an AIMS Audit
When auditing Clause 7.5 of an AIMS, a competent auditor will not simply ask to see a list of documents. They will trace documented information through the system to verify that it is controlled, current, and connected to real activities.
Expect an auditor to ask for the current version of the AI risk assessment and then check whether it reflects the AI systems currently in scope. They will look at the Statement of Applicability and cross reference selected controls against operational evidence. They will ask to see the impact assessment for a specific AI system and check whether it was reviewed after the system was updated. They will look at competence records for people in AI related roles and assess whether those records demonstrate actual capability, not just attendance at a training session.
They will also check version control. If a document has been revised, is the previous version clearly superseded? Are there controls to prevent the old version from being used? These are the details that separate a functioning document control system from a folder of files.
If you are preparing for a Clause 7.5 audit, the most useful thing you can do is walk through your document register and ask yourself: if an auditor asked me to produce this document right now, could I find it, confirm it is current, and demonstrate that it is controlled? If the answer to any of those questions is no, that is where to focus your attention.
For auditors who want to build confidence in auditing documented information requirements across ISO standards, the approach to Clause 7.5 is consistent whether you are working with ISO 9001, ISO 27001, or ISO 42001. The principles covered in Auditing Documented Information: A Clause 7.5 Checklist Approach translate directly to the AIMS context. Similarly, understanding how documented information works in an ISMS gives useful context, as covered in Documented Information in an ISMS: What Clause 7.5 Requires.
If you are building your auditing skills across multiple standards, including ISO 42001, Clause 7 of ISO 42001: Resources, Competence, Awareness and Communication provides broader context for the support requirements that sit alongside documented information. And for those auditing the Statement of Applicability specifically, The Statement of Applicability in ISO 42001: Your Most Examined Document is worth reading before you walk into that audit room.
At Audit Workshop, our ISO 42001 auditor training covers documented information requirements in the context of real AI management system audits. If you are building or auditing an AIMS and want practical skills grounded in actual audit experience, our courses are designed for practitioners who need to get this right the first time.













