Clause 5 turns the AIMS from an idea into an organisational commitment. It requires top management to actively lead AI governance, set direction through an AI policy, and make sure responsibilities and authorities are clear.
This clause is about accountability. ISO 42001 does not treat AI governance as something that can be delegated entirely to technical teams, compliance teams or individual model owners. Leadership must own the management system and create the conditions for it to work.
Top management must demonstrate leadership and commitment to the AIMS.
This means leaders must do more than approve documents. They must show that AI governance is integrated into business processes, aligned with organisational strategy, resourced appropriately and continually improved.
Leadership commitment includes:
- Ensuring the AI policy and AI objectives are established
- Ensuring the AIMS is compatible with the organisation's strategic direction
- Integrating AIMS requirements into business processes
- Making resources available
- Communicating the importance of effective AI management
- Ensuring the AIMS achieves its intended outcomes
- Directing and supporting people who contribute to the AIMS
- Promoting continual improvement
- Supporting relevant management roles
What this means in practice:
- AI governance has a visible executive sponsor
- AI risks are discussed at appropriate governance forums
- AI objectives are linked to business priorities and risk appetite
- AI governance decisions are documented and traceable
- Teams are not expected to manage AI risk without authority or resources
Leadership is especially important because AI risks often cross organisational boundaries: technology, legal, ethics, data protection, product, operations, HR, procurement and customer impact can all be involved.
The organisation must establish an AI policy.
The AI policy sets the direction for responsible AI management. It should be appropriate to the organisation's purpose, context and AI activities, and it should provide a framework for setting AI objectives.
An effective AI policy should:
- Be aligned with the organisation's context and strategic direction
- Include commitments relevant to responsible AI development, deployment and use
- Support compliance with applicable requirements
- Provide a framework for setting AI objectives
- Commit to continual improvement of the AIMS
- Be available as documented information
- Be communicated within the organisation
- Be available to interested parties where appropriate
Typical policy themes:
- Human oversight and accountability
- Fairness and avoidance of harmful bias
- Transparency and explainability where appropriate
- Privacy, security and data governance
- Safety, robustness and reliability
- Responsible procurement and third-party AI use
- Monitoring, review and escalation
The policy should not be a slogan. Auditors will look for evidence that the policy is understood, used and reflected in operational decisions.
Top management must ensure that responsibilities and authorities for relevant roles are assigned, communicated and understood.
This clause answers a practical question: who is accountable for what?
Responsibilities should cover:
- Maintaining the AIMS
- Reporting on AIMS performance
- Managing AI risk assessment and treatment
- Approving AI systems for development, deployment or use
- Managing AI system impact assessments
- Maintaining documented information
- Monitoring legal, regulatory and stakeholder requirements
- Escalating issues, incidents and nonconformities
Common roles involved:
| Role | Possible responsibility |
|---|---|
| Top management | Overall accountability and direction |
| AI governance lead | Coordination of the AIMS |
| System owner | Accountability for a specific AI system |
| Data owner | Data quality, lineage and permitted use |
| Risk/compliance | Risk methodology, controls and assurance |
| Legal/privacy | Regulatory, contractual and privacy obligations |
| Security | Security controls and threat management |
| Product/operations | Business use, user impact and operational monitoring |
Roles do not need to be new job titles. In smaller organisations, one person may hold multiple responsibilities. The key point is that responsibilities must be clear, communicated and actually workable.
- How does top management demonstrate active commitment to the AIMS?
- Where is AI governance discussed at leadership level?
- How are AI policy commitments translated into practical objectives and controls?
- Who owns the AIMS, and who reports on its performance?
- Who has authority to approve, pause or stop AI system development, deployment or use?
- Can staff explain their AI governance responsibilities?
| Clause 5 output | Used by |
|---|---|
| Leadership commitment | Clause 7 (resources), Clause 9 (management review), Clause 10 (improvement) |
| AI policy | Clause 6 (risk assessment, objectives), Clause 8 (operational controls) |
| Roles and authorities | Clause 7 (competence and awareness), Clause 8 (operation), Clause 9 (audit and review) |
| Accountability structure | Annex A controls and Statement of Applicability |
Clause 5 is where AI governance becomes leadership-owned. A strong AIMS needs visible sponsorship, a clear policy and people who know what decisions they are responsible for.
Reference catalogue entry — use this as source material for matching funny and professional infographic cards.