Why Clause 7 of ISO 42001 Matters More Than Most People Realise
When organisations begin implementing ISO 42001, the artificial intelligence management system standard, most of the early attention lands on Clause 6 planning, risk assessment, and the AI impact assessment process. Clause 7 tends to get treated as administrative housekeeping. That is a mistake.
On this page
Clause 7 covers the support requirements of your AI management system (AIMS): resources, competence, awareness, communication, and documented information. These are the enablers that determine whether everything else in your system actually functions. A well designed AI policy and a thorough risk treatment plan are worth very little if your people do not have the skills to implement them, do not understand why they matter, and cannot communicate about them clearly.
This article walks through each subclause of Clause 7 in plain terms, explains what the standard actually requires, and gives you practical guidance on what good implementation looks like and what auditors will be checking.
Clause 7.1: Resources
The opening subclause is brief but foundational. ISO 42001 requires the organisation to determine and provide the resources needed to establish, implement, maintain, and continually improve the AIMS.
In practice, this means more than just budget. Resources in the context of an AI management system include people with the right skills, time allocated to AI governance activities, infrastructure for monitoring AI systems, access to external expertise where internal capability is limited, and tools for conducting AI impact assessments and risk assessments.
The challenge with Clause 7.1 is that it is principle based. The standard does not tell you how many people you need or what your budget should be. It asks you to make a considered determination based on the scope and complexity of your AIMS. If your organisation is deploying AI systems across multiple business functions, the resource requirements will be substantially different from an organisation using a single AI tool for a narrow purpose.
Auditors reviewing Clause 7.1 will typically look for evidence that resource decisions are deliberate and documented. They will ask questions like: How did you determine what resources were needed? What happens when resources fall short? Is there a process for escalating resource gaps to top management?
If your organisation has identified AI risks that require specialist expertise but has not allocated anyone to manage them, that is a gap worth raising. The resource provision has to be proportionate to what the system is actually trying to achieve.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 7.2: Competence
Competence is where Clause 7 gets substantive. ISO 42001 requires the organisation to determine the competence needed by people doing work under its control that affects AI performance and AI risk management. It then requires the organisation to ensure those people are competent, take action where they are not, and retain documented information as evidence.
This mirrors the structure you will find in ISO 9001, ISO 14001, and ISO 45001, but the content is specific to AI. Competence in an AIMS context spans several different domains.
Technical Competence
People working directly with AI systems need to understand how those systems function, what data they rely on, how outputs are generated, and what failure modes exist. This does not mean every employee needs to be a machine learning engineer. But the people responsible for procuring, deploying, and monitoring AI systems need enough technical literacy to make sound governance decisions.
Risk and Impact Assessment Competence
ISO 42001 places significant weight on AI risk assessment and AI system impact assessment. The people conducting these assessments need to understand the methodology, know how to identify AI specific harms (including bias, discrimination, privacy violations, and safety risks), and be able to evaluate the adequacy of controls. This is a specialised skill set that many organisations will need to develop deliberately.
Governance and Ethics Competence
Beyond technical skills, ISO 42001 requires organisations to manage AI responsibly. That includes understanding relevant legal obligations, ethical principles, and the organisation's own AI policy commitments. People in governance roles need competence in translating these principles into operational decisions.
The standard requires that where gaps exist, the organisation takes action to address them. That might mean training, hiring, engaging external specialists, or restructuring responsibilities. Crucially, the action taken needs to be evaluated for effectiveness. Sending someone to a one day workshop and never checking whether it made a difference does not satisfy the requirement.
Documented information is explicitly required. This typically takes the form of training records, competency matrices, job descriptions with competence requirements, assessment results, and records of external qualifications or certifications. If you cannot produce evidence that a person is competent for their role in the AIMS, you have a gap.
For a deeper look at exactly what Clause 7.2 expects from your people, see our article on Building AI Competence: What Clause 7.2 Expects From Your People.
Clause 7.3: Awareness
Competence and awareness are related but distinct. Competence is about having the skills and knowledge to do a job. Awareness is about understanding why it matters. ISO 42001 requires that people working under the organisation's control are aware of the AI policy, their contribution to the effectiveness of the AIMS, the implications of not conforming to AIMS requirements, and the benefits of improved AI performance.
This is a broader obligation than competence. It applies to anyone whose work touches the AIMS, not just the specialists. An employee who uses an AI tool to support customer decisions may not need deep technical competence, but they do need to understand the organisation's AI policy, what the tool is and is not designed to do, and what to do if something seems wrong.
Awareness programmes for an AIMS typically need to cover several things. People need to know that an AI management system exists and what it covers. They need to understand the AI policy at a level that is meaningful to their role. They need to know what behaviours are expected of them, including how to raise concerns about AI outputs or conduct.
The format of awareness activities matters less than their effectiveness. Induction training, team briefings, internal communications, and e-learning modules can all work. What auditors look for is evidence that awareness activities have actually reached the people they were intended for, and that there is some mechanism for checking whether awareness has been achieved. A poster on the wall that nobody has read does not constitute evidence of awareness.
One practical approach is to embed AI awareness into existing induction and refresher training programmes rather than treating it as a standalone exercise. This reduces the administrative burden and helps people connect AI governance to their existing understanding of the organisation's values and obligations.
Clause 7.4: Communication
ISO 42001 requires the organisation to determine the internal and external communications relevant to the AIMS. This includes what to communicate, when to communicate it, with whom, and how.
Communication under Clause 7.4 is not about general corporate communications. It is specifically about communications that support the functioning of the AI management system. This includes how AI risks and performance information flow within the organisation, how the organisation communicates with external parties about its AI systems, and how it handles enquiries or complaints about AI use.
Internal Communication
Internally, communication needs to ensure that people with responsibilities in the AIMS receive the information they need to carry out those responsibilities. This includes updates to the AI policy, changes to AI systems that affect risk profiles, results of AI impact assessments, and outcomes of internal audits and management reviews.
The challenge in many organisations is that AI governance sits between functions. The team that procures AI tools may not talk regularly to the team that manages data, and neither may have a strong connection to the legal or compliance function. Clause 7.4 requires the organisation to address these gaps deliberately rather than assuming information will flow naturally.
External Communication
External communication requirements under ISO 42001 are shaped by the organisation's AI context and the interests of affected parties. Organisations deploying AI systems that affect customers, workers, or other stakeholders need to think carefully about what those parties need to know, when they need to know it, and in what form.
This is not simply a public relations exercise. ISO 42001 connects external communication to the organisation's transparency commitments under its AI policy. If the policy commits to informing customers when AI is used to make decisions that affect them, the communication process needs to give effect to that commitment.
Documented information is not explicitly required for Clause 7.4 in the same way it is for Clause 7.2, but in practice organisations need some record of their communication decisions. An auditor will want to understand how the organisation determined what to communicate and to whom, and will look for evidence that those decisions have been implemented.
Clause 7.5: Documented Information
Clause 7.5 sets out the requirements for documented information in the AIMS. This subclause has three parts: general requirements, creating and updating documented information, and controlling documented information. The structure is identical to the equivalent clause in ISO 9001 and other high level structure standards, which makes it familiar territory for anyone who has worked with those systems.
The standard requires the AIMS to include documented information required by the standard itself, plus any additional documented information the organisation determines is necessary for the effectiveness of the system. This means the minimum documentation set is defined by what ISO 42001 explicitly requires, but organisations can and should add more where it helps the system work.
What Documented Information Does ISO 42001 Require?
Throughout the standard, specific clauses call for documented information. These include the scope of the AIMS, the AI policy, evidence of competence, results of AI risk assessments, results of AI system impact assessments, the statement of applicability, records of monitoring and measurement, internal audit results, and management review outputs. This is not an exhaustive list, but it gives you a sense of the documentation load.
The key discipline with documented information is that it needs to be controlled. That means it needs to be available and suitable for use where and when it is needed, adequately protected from loss or inappropriate use, and subject to a process for creation, review, approval, and update. Version control, access controls, and retention periods are the practical mechanisms that give effect to this requirement.
For organisations that already have a mature document control system under ISO 9001 or ISO 27001, extending it to cover AIMS documented information is usually straightforward. For organisations implementing ISO 42001 as their first management system standard, building document control from scratch takes more effort but is not complicated once the principles are understood.
Auditors checking Clause 7.5 will look at whether required documents exist, whether they are current and approved, whether they are accessible to the people who need them, and whether there is a consistent approach to version control and retention. Common gaps include outdated documents that have not been reviewed, documents that exist but are not known to the people who need them, and records that cannot be located when requested.
Our article on Documented Information for an AIMS: Getting Clause 7.5 Right covers the practical side of this requirement in more detail.
How Clause 7 Connects to the Rest of ISO 42001
Clause 7 does not operate in isolation. It is the support layer that enables everything else in the AIMS to function. Without adequate resources, the risk assessment process cannot be conducted properly. Without competent people, the AI impact assessment will produce unreliable results. Without awareness, the AI policy remains a document rather than a lived commitment. Without effective communication, information about AI risks and performance will not reach the people who need to act on it. Without controlled documented information, the organisation cannot demonstrate conformity or learn from its experience.
When auditors assess an AIMS, they routinely trace from Clause 7 requirements back into operational clauses. If an AI impact assessment (Clause 8.4) has been conducted but the person who conducted it cannot demonstrate competence in the methodology, that is a Clause 7.2 finding as much as a Clause 8 finding. If the organisation's AI policy has been updated but workers are unaware of the changes, that is a Clause 7.3 and 7.4 finding. The connections are direct and auditors know to look for them.
This interconnection is also why Clause 7 is a good starting point when building or reviewing an AIMS. Getting the support requirements right creates the conditions for everything else to work. Getting them wrong creates systemic problems that are hard to trace back to their source.
Common Gaps Auditors Find in Clause 7 of ISO 42001
Based on audit experience across management system standards, the following gaps appear most frequently in Clause 7 implementations.
- Competence requirements not defined for AI specific roles. Many organisations have generic job descriptions but have not identified what AI governance competence looks like for each relevant role.
- Training records that do not demonstrate competence. Attendance records are not the same as competence evidence. The standard requires evidence that people are competent, not just that they attended training.
- Awareness activities that have not reached all relevant workers. Organisations often conduct awareness sessions for management and specialists but overlook operational staff who use AI tools day to day.
- Communication processes that are informal and undocumented. When communication about AI risks and performance happens ad hoc, there is no assurance that it is consistent or that it reaches the right people at the right time.
- Documented information that is not controlled. Documents without version numbers, approval records, or defined retention periods fail the Clause 7.5 requirements regardless of their content quality.
- Gaps between the AI policy and what workers actually know about it. If workers cannot articulate the key commitments of the AI policy in terms relevant to their role, awareness is not established.
Practical Steps for Implementing Clause 7
If you are building or reviewing your AIMS support requirements, a structured approach helps.
- Map your AI activities to roles. Start by identifying every role that has a function in the AIMS, from top management to operational users of AI tools. For each role, define what competence is required.
- Assess current competence against requirements. Use a competency matrix or similar tool to identify gaps. Be honest about what people actually know versus what they are assumed to know.
- Design targeted development activities. Address gaps with specific interventions. Not everyone needs the same training. A data scientist and a customer service manager who uses an AI scheduling tool have very different competence needs.
- Build awareness into existing channels. Use induction programmes, team meetings, and internal communications to embed AI awareness. Do not rely solely on standalone training events.
- Define your communication plan. Document who needs to receive what information, when, and how. Include both internal flows and any external communication obligations arising from your AI policy.
- Audit your documented information. Take stock of what documents exist, whether they are current, who has approved them, and whether they are accessible. Address gaps before your certification audit.
If you are also working through the competence and awareness requirements under other ISO standards, the approach is similar across the family. Our article on Audit Techniques for Clause 7: Verifying Competence, Awareness and Documents provides practical audit questions you can adapt for ISO 42001 contexts.
Exemplar Global Recognised Training ProviderRTP No. 310970How Auditors Approach Clause 7 in an ISO 42001 Audit
When conducting an audit against Clause 7 of ISO 42001, the approach combines document review, interviews, and observation. Auditors will typically start by reviewing the documented information that the standard explicitly requires: competence records, training records, and evidence of awareness activities. They will then conduct interviews to test whether the documented picture matches reality.
Interview questions for Clause 7 typically include: What is your role in relation to the organisation's AI systems? What training have you received on AI governance? Can you describe the key commitments in the AI policy? What would you do if you noticed an AI system producing unexpected or potentially harmful outputs? How do you receive updates about changes to AI systems or AI governance requirements?
The answers to these questions reveal quickly whether competence and awareness are genuine or merely documented. An auditor who hears that a person responsible for AI risk assessment has never received any training in the methodology, and cannot describe how assessments are conducted, will raise a nonconformity regardless of what the training records say.
Observation adds another dimension. An auditor visiting a site where AI tools are in use can observe whether workers appear to understand what the tools are doing and whether they apply the controls and judgements the organisation's procedures require. If the procedures say workers should escalate certain AI outputs for human review but nobody does this in practice, that is an awareness and communication gap that observation will surface.
For those looking to build a deeper understanding of how auditors evaluate these requirements, the Gathering Evidence of Competence and Awareness in an AIMS Audit article walks through the evidence gathering process in practical terms.
Building Clause 7 Capability Through Training
One of the most consistent findings from ISO 42001 implementation projects is that organisations underestimate the learning curve involved in AI governance. The technical, ethical, and regulatory dimensions of managing AI systems responsibly require a level of specialist knowledge that most organisations are still building.
This makes structured training particularly valuable. Whether you are a quality manager taking on AI governance responsibilities, an internal auditor who needs to assess AIMS conformity, or a lead auditor preparing to conduct certification audits against ISO 42001, the competence requirements are real and specific.
Audit Workshop offers training for internal auditors and lead auditors across ISO 42001 and other management system standards. If you are working to build your competence in AI management system auditing, or preparing your team to implement and maintain an AIMS, our courses provide practical grounding in what the standard requires and how to audit it effectively. Visit auditworkshop.com to explore the options available.













