ISO 42001 (AIMS) Statement of Applicability Template
Introduction
As artificial intelligence becomes part of everyday business operations, organizations need a structured way to manage AI-related risks, responsibilities, and controls. ISO/IEC 42001, the international standard for an Artificial Intelligence Management System (AIMS), provides that framework. One important document organizations may use when implementing an AIMS is the ISO 42001 Statement of Applicability (SoA) template. It helps organizations document which applicable controls have been selected, why they are relevant, and how they are being implemented.

What Is an ISO 42001 Statement of Applicability?
An ISO 42001 Statement of Applicability is a documented record that explains the organization's selection and applicability of relevant AI management controls.
The document provides a clear connection between an organization's identified AI risks, its management objectives, and the controls it has selected to address those risks.
A well-prepared SoA can help organizations:
-
Document applicable AI controls
-
Explain why particular controls are included or excluded
-
Track the implementation status of controls
-
Support internal and external audits
-
Demonstrate a structured approach to AI risk management
-
Provide evidence of accountability within the AIMS
The SoA should reflect the organization's actual AI environment rather than being treated as a generic checklist.
Why Is the ISO 42001 SoA Important?
Implementing an AI management system involves more than creating policies. Organizations need to understand how AI is being developed, purchased, deployed, monitored, and eventually retired.
The Statement of Applicability helps bring this information together in one structured document.
For example, an organization using AI for customer service may face risks involving inaccurate outputs, privacy, transparency, bias, or unauthorized use. Its selected controls should therefore reflect its particular AI use cases and risk profile.
The SoA can also make audits easier because it provides auditors with a documented explanation of the organization's control decisions.
What Should an ISO 42001 SoA Template Include?
There is no single universal format that every organization must use. However, a practical template can include the following fields.
1. Control or Requirement Reference
Start by identifying the relevant ISO 42001 control, requirement, or control area.
This gives the document a clear reference point and makes it easier to trace each control back to the applicable part of the AIMS framework.
2. Control Description
Briefly describe what the control addresses.
The description should be understandable to the people responsible for implementing and maintaining the AIMS. Avoid copying large sections of the standard into the SoA.
3. Applicability
Indicate whether the control is applicable to the organization.
A simple Applicable / Not Applicable field can work well, although organizations may use more detailed classifications where necessary.
4. Justification
This is one of the most important parts of the SoA.
If a control is applicable, explain why it is relevant to the organization's AI activities. If it is excluded, document the reason for that decision.
The justification should be based on the organization's context, AI risks, legal and regulatory requirements, objectives, and operational activities.
5. Implementation Status
The template should show whether the selected control has been implemented.
Common status options include:
-
Implemented
-
Partially implemented
-
Planned
-
Not implemented
-
Not applicable
Organizations can customize these categories to fit their internal processes.
6. Supporting Documentation
Include references to policies, procedures, risk assessments, records, or other evidence that demonstrate how the control is being addressed.
For example, a control could reference an AI risk assessment, model documentation, data governance procedure, incident management process, or AI usage policy.
7. Responsible Owner
Assign responsibility for each applicable control.
Depending on the organization, ownership may sit with teams such as information security, compliance, legal, data governance, AI development, IT, or senior management.
Clearly assigned ownership reduces ambiguity and makes ongoing monitoring easier.
Sample ISO 42001 Statement of Applicability Template
A basic SoA can be structured as follows:
|
Reference |
Control / Requirement |
Applicable? |
Justification |
Implementation Status |
Evidence |
Owner |
|
AIMS Reference |
Control description |
Yes/No |
Reason for inclusion/exclusion |
Implemented/Planned |
Supporting document |
Responsible team |
|
AIMS Reference |
Control description |
Yes/No |
Reason for inclusion/exclusion |
Implemented/Planned |
Supporting document |
Responsible team |
This format can be expanded with additional fields such as risk reference, implementation date, review date, and residual risk.
How to Prepare an ISO 42001 Statement of Applicability
Creating the SoA should be connected to the organization's wider AIMS implementation process.
Step 1: Define the AIMS Scope
Determine which AI systems, business units, processes, locations, and activities fall within the management system.
Step 2: Identify AI-Related Risks
Assess the risks associated with the organization's AI systems and their lifecycle.
Consider areas such as data, security, privacy, reliability, transparency, human oversight, legal obligations, and potential impacts on individuals or groups.
Step 3: Review Applicable Controls
Review the relevant ISO 42001 requirements and controls against the organization's AI risks and operational context.
Step 4: Determine Applicability
For each relevant control, decide whether it applies to the organization.
Avoid automatically selecting every control without considering actual business circumstances.
Step 5: Document the Rationale
Record a clear justification for each inclusion or exclusion.
This creates an audit trail showing how control decisions were made.
Step 6: Link Controls to Evidence
Connect each implemented control to supporting documentation or other evidence.
This makes the SoA more useful during audits and management reviews.
Step 7: Review and Update Regularly
An SoA should not be considered a one-time document. Changes to AI systems, business processes, regulations, suppliers, risks, or the AIMS scope may require the organization to review its control decisions.
Common Mistakes to Avoid
Organizations sometimes treat the Statement of Applicability as a simple compliance spreadsheet. That can reduce its value.
Common mistakes include:
-
Using a generic template without adapting it to the organization
-
Providing weak or unclear justifications
-
Marking controls as implemented without supporting evidence
-
Failing to assign control ownership
-
Not linking controls to identified AI risks
-
Treating the SoA as a static document
-
Failing to update it when AI systems or processes change
A useful SoA should tell a coherent story: what risks the organization faces, which controls address those risks, who is responsible, and what evidence demonstrates implementation.
Benefits of Using an ISO 42001 SoA Template
A structured template can save time and create consistency across the AIMS.
It can help organizations maintain better documentation, improve accountability, identify implementation gaps, and prepare more efficiently for audits.
More importantly, it provides management with a practical overview of how AI-related controls are being addressed across the organization.
Conclusion
An ISO 42001 Statement of Applicability template provides a practical way to document control applicability and implementation within an Artificial Intelligence Management System. When properly prepared, it connects AI risks and organizational requirements with specific controls, responsibilities, and supporting evidence.Rather than simply filling out a checklist, organizations should tailor the SoA to their actual AI systems, processes, risks, and objectives. Regular reviews are also important because an organization's AI landscape can change quickly.
Implement ISO Faster with a Complete Documentation System
ISO Toolkit for Your Standard
Pick your toolkit from 8 ready-to-use ISO toolkits available: ISO 27001, 9001, 14001, 45001, 22301, 20000, and 42001 (AI Governance).
✔ Complete ISO documentation framework
✔ Policies, procedures, templates, and records
✔ Risk management & internal audit templates
✔ Management Review and Nonconformance
✔ ISO Standard Mapped Implementation Plan
💡 All toolkits come with instant download, one-time payment, and unlimited email & chat support.
ISO PowerPack Bundle
Designed for teams, organizations, and consultants managing multiple ISO implementations across projects and clients.
✔ Unlimited internal and client use
✔ Deliver ISO services from day one
✔ Impress clients and auditors
✔ Skip months of document creation
✔ Grow your consulting business
💡All the benefits of our ISO toolkits combined in one powerful bundle — save over $1,000 compared to buying the toolkits individually.
