ISO 42001 (AIMS) Statement of Applicability Template

by Poorva Dange

Introduction

As artificial intelligence becomes part of everyday business operations, organizations need a structured way to manage AI-related risks, responsibilities, and controls. ISO/IEC 42001, the international standard for an Artificial Intelligence Management System (AIMS), provides that framework. One important document organizations may use when implementing an AIMS is the ISO 42001 Statement of Applicability (SoA) template. It helps organizations document which applicable controls have been selected, why they are relevant, and how they are being implemented.

ISO 42001 (AIMS) Statement of Applicability Template

What Is an ISO 42001 Statement of Applicability?

An ISO 42001 Statement of Applicability is a documented record that explains the organization's selection and applicability of relevant AI management controls.

The document provides a clear connection between an organization's identified AI risks, its management objectives, and the controls it has selected to address those risks.

A well-prepared SoA can help organizations:

  • Document applicable AI controls

  • Explain why particular controls are included or excluded

  • Track the implementation status of controls

  • Support internal and external audits

  • Demonstrate a structured approach to AI risk management

  • Provide evidence of accountability within the AIMS

The SoA should reflect the organization's actual AI environment rather than being treated as a generic checklist.

Why Is the ISO 42001 SoA Important?

Implementing an AI management system involves more than creating policies. Organizations need to understand how AI is being developed, purchased, deployed, monitored, and eventually retired.

The Statement of Applicability helps bring this information together in one structured document.

For example, an organization using AI for customer service may face risks involving inaccurate outputs, privacy, transparency, bias, or unauthorized use. Its selected controls should therefore reflect its particular AI use cases and risk profile.

The SoA can also make audits easier because it provides auditors with a documented explanation of the organization's control decisions.

What Should an ISO 42001 SoA Template Include?

There is no single universal format that every organization must use. However, a practical template can include the following fields.

1. Control or Requirement Reference

Start by identifying the relevant ISO 42001 control, requirement, or control area.

This gives the document a clear reference point and makes it easier to trace each control back to the applicable part of the AIMS framework.

2. Control Description

Briefly describe what the control addresses.

The description should be understandable to the people responsible for implementing and maintaining the AIMS. Avoid copying large sections of the standard into the SoA.

3. Applicability

Indicate whether the control is applicable to the organization.

A simple Applicable / Not Applicable field can work well, although organizations may use more detailed classifications where necessary.

4. Justification

This is one of the most important parts of the SoA.

If a control is applicable, explain why it is relevant to the organization's AI activities. If it is excluded, document the reason for that decision.

The justification should be based on the organization's context, AI risks, legal and regulatory requirements, objectives, and operational activities.

5. Implementation Status

The template should show whether the selected control has been implemented.

Common status options include:

  • Implemented

  • Partially implemented

  • Planned

  • Not implemented

  • Not applicable

Organizations can customize these categories to fit their internal processes.

6. Supporting Documentation

Include references to policies, procedures, risk assessments, records, or other evidence that demonstrate how the control is being addressed.

For example, a control could reference an AI risk assessment, model documentation, data governance procedure, incident management process, or AI usage policy.

7. Responsible Owner

Assign responsibility for each applicable control.

Depending on the organization, ownership may sit with teams such as information security, compliance, legal, data governance, AI development, IT, or senior management.

Clearly assigned ownership reduces ambiguity and makes ongoing monitoring easier.

ISO 42001 AI Governance Framework

Sample ISO 42001 Statement of Applicability Template

A basic SoA can be structured as follows:

Reference

Control / Requirement

Applicable?

Justification

Implementation Status

Evidence

Owner

AIMS Reference

Control description

Yes/No

Reason for inclusion/exclusion

Implemented/Planned

Supporting document

Responsible team

AIMS Reference

Control description

Yes/No

Reason for inclusion/exclusion

Implemented/Planned

Supporting document

Responsible team

This format can be expanded with additional fields such as risk reference, implementation date, review date, and residual risk.

How to Prepare an ISO 42001 Statement of Applicability

Creating the SoA should be connected to the organization's wider AIMS implementation process.

Step 1: Define the AIMS Scope

Determine which AI systems, business units, processes, locations, and activities fall within the management system.

Step 2: Identify AI-Related Risks

Assess the risks associated with the organization's AI systems and their lifecycle.

Consider areas such as data, security, privacy, reliability, transparency, human oversight, legal obligations, and potential impacts on individuals or groups.

Step 3: Review Applicable Controls

Review the relevant ISO 42001 requirements and controls against the organization's AI risks and operational context.

Step 4: Determine Applicability

For each relevant control, decide whether it applies to the organization.

Avoid automatically selecting every control without considering actual business circumstances.

Step 5: Document the Rationale

Record a clear justification for each inclusion or exclusion.

This creates an audit trail showing how control decisions were made.

Step 6: Link Controls to Evidence

Connect each implemented control to supporting documentation or other evidence.

This makes the SoA more useful during audits and management reviews.

Step 7: Review and Update Regularly

An SoA should not be considered a one-time document. Changes to AI systems, business processes, regulations, suppliers, risks, or the AIMS scope may require the organization to review its control decisions.

ISO 42001 AI Governance Framework

Common Mistakes to Avoid

Organizations sometimes treat the Statement of Applicability as a simple compliance spreadsheet. That can reduce its value.

Common mistakes include:

  • Using a generic template without adapting it to the organization

  • Providing weak or unclear justifications

  • Marking controls as implemented without supporting evidence

  • Failing to assign control ownership

  • Not linking controls to identified AI risks

  • Treating the SoA as a static document

  • Failing to update it when AI systems or processes change

A useful SoA should tell a coherent story: what risks the organization faces, which controls address those risks, who is responsible, and what evidence demonstrates implementation.

Benefits of Using an ISO 42001 SoA Template

A structured template can save time and create consistency across the AIMS.

It can help organizations maintain better documentation, improve accountability, identify implementation gaps, and prepare more efficiently for audits.

More importantly, it provides management with a practical overview of how AI-related controls are being addressed across the organization.

Conclusion

An ISO 42001 Statement of Applicability template provides a practical way to document control applicability and implementation within an Artificial Intelligence Management System. When properly prepared, it connects AI risks and organizational requirements with specific controls, responsibilities, and supporting evidence.Rather than simply filling out a checklist, organizations should tailor the SoA to their actual AI systems, processes, risks, and objectives. Regular reviews are also important because an organization's AI landscape can change quickly.


Implement ISO Faster with a Complete Documentation System

You're currently viewing a single template. Most ISO implementations require a complete set of policies, procedures, and records. Choose what fits your needs.
BEST FOR single ISO STANDARD

ISO Toolkit for Your Standard

Audit ReadyToolkits

Pick your toolkit from 8 ready-to-use ISO toolkits available: ISO 27001, 9001, 14001, 45001, 22301, 20000, and 42001 (AI Governance).

✔ Complete ISO documentation framework
✔ Policies, procedures, templates, and records
✔ Risk management & internal audit templates
✔ Management Review and Nonconformance
✔ ISO Standard Mapped Implementation Plan

💡 All toolkits come with instant download, one-time payment, and unlimited email & chat support.

View ISO Toolkits Collection →
BEST FOR MULTIPLE ISO STANDARDS

ISO PowerPack Bundle

All 8 ISO Toolkits in One Power Pack

Designed for teams, organizations, and consultants managing multiple ISO implementations across projects and clients.

✔ Unlimited internal and client use
✔ Deliver ISO services from day one
✔ Impress clients and auditors
✔ Skip months of document creation
✔ Grow your consulting business

💡All the benefits of our ISO toolkits combined in one powerful bundle — save over $1,000 compared to buying the toolkits individually.

View ISO PowerPack →