Skip to content

Latest commit

 

History

History
133 lines (95 loc) · 5.67 KB

File metadata and controls

133 lines (95 loc) · 5.67 KB

ISO 42001 Reference Card: Clause 5 — Leadership


Purpose

Clause 5 turns the AIMS from an idea into an organisational commitment. It requires top management to actively lead AI governance, set direction through an AI policy, and make sure responsibilities and authorities are clear.

This clause is about accountability. ISO 42001 does not treat AI governance as something that can be delegated entirely to technical teams, compliance teams or individual model owners. Leadership must own the management system and create the conditions for it to work.


Sub-clauses

5.1 Leadership and commitment

Top management must demonstrate leadership and commitment to the AIMS.

This means leaders must do more than approve documents. They must show that AI governance is integrated into business processes, aligned with organisational strategy, resourced appropriately and continually improved.

Leadership commitment includes:

  • Ensuring the AI policy and AI objectives are established
  • Ensuring the AIMS is compatible with the organisation's strategic direction
  • Integrating AIMS requirements into business processes
  • Making resources available
  • Communicating the importance of effective AI management
  • Ensuring the AIMS achieves its intended outcomes
  • Directing and supporting people who contribute to the AIMS
  • Promoting continual improvement
  • Supporting relevant management roles

What this means in practice:

  • AI governance has a visible executive sponsor
  • AI risks are discussed at appropriate governance forums
  • AI objectives are linked to business priorities and risk appetite
  • AI governance decisions are documented and traceable
  • Teams are not expected to manage AI risk without authority or resources

Leadership is especially important because AI risks often cross organisational boundaries: technology, legal, ethics, data protection, product, operations, HR, procurement and customer impact can all be involved.


5.2 AI policy

The organisation must establish an AI policy.

The AI policy sets the direction for responsible AI management. It should be appropriate to the organisation's purpose, context and AI activities, and it should provide a framework for setting AI objectives.

An effective AI policy should:

  • Be aligned with the organisation's context and strategic direction
  • Include commitments relevant to responsible AI development, deployment and use
  • Support compliance with applicable requirements
  • Provide a framework for setting AI objectives
  • Commit to continual improvement of the AIMS
  • Be available as documented information
  • Be communicated within the organisation
  • Be available to interested parties where appropriate

Typical policy themes:

  • Human oversight and accountability
  • Fairness and avoidance of harmful bias
  • Transparency and explainability where appropriate
  • Privacy, security and data governance
  • Safety, robustness and reliability
  • Responsible procurement and third-party AI use
  • Monitoring, review and escalation

The policy should not be a slogan. Auditors will look for evidence that the policy is understood, used and reflected in operational decisions.


5.3 Roles, responsibilities and authorities

Top management must ensure that responsibilities and authorities for relevant roles are assigned, communicated and understood.

This clause answers a practical question: who is accountable for what?

Responsibilities should cover:

  • Maintaining the AIMS
  • Reporting on AIMS performance
  • Managing AI risk assessment and treatment
  • Approving AI systems for development, deployment or use
  • Managing AI system impact assessments
  • Maintaining documented information
  • Monitoring legal, regulatory and stakeholder requirements
  • Escalating issues, incidents and nonconformities

Common roles involved:

Role Possible responsibility
Top management Overall accountability and direction
AI governance lead Coordination of the AIMS
System owner Accountability for a specific AI system
Data owner Data quality, lineage and permitted use
Risk/compliance Risk methodology, controls and assurance
Legal/privacy Regulatory, contractual and privacy obligations
Security Security controls and threat management
Product/operations Business use, user impact and operational monitoring

Roles do not need to be new job titles. In smaller organisations, one person may hold multiple responsibilities. The key point is that responsibilities must be clear, communicated and actually workable.


Common audit questions

  • How does top management demonstrate active commitment to the AIMS?
  • Where is AI governance discussed at leadership level?
  • How are AI policy commitments translated into practical objectives and controls?
  • Who owns the AIMS, and who reports on its performance?
  • Who has authority to approve, pause or stop AI system development, deployment or use?
  • Can staff explain their AI governance responsibilities?

Connections to other clauses

Clause 5 output Used by
Leadership commitment Clause 7 (resources), Clause 9 (management review), Clause 10 (improvement)
AI policy Clause 6 (risk assessment, objectives), Clause 8 (operational controls)
Roles and authorities Clause 7 (competence and awareness), Clause 8 (operation), Clause 9 (audit and review)
Accountability structure Annex A controls and Statement of Applicability

Key message

Clause 5 is where AI governance becomes leadership-owned. A strong AIMS needs visible sponsorship, a clear policy and people who know what decisions they are responsible for.


Reference catalogue entry — use this as source material for matching funny and professional infographic cards.