ISO 42001Clause 5

Writing an AI policy top management will actually sign

The AI policy is the first document an auditor opens, and the one teams most often get wrong — not because it's hard to write, but because it's written to impress rather than to commit. A good policy is short, specific, and genuinely owned at the top. Here's how to write one.

Why it matters more than its length suggests

In ISO 42001 the AI policy (Clause 5.2, control A.2) is the anchor the whole management system hangs off. It states your organisation's commitment to responsible AI, the scope it covers, and the objectives you'll be held to. Auditors read it first because it tells them one thing quickly: is leadership actually behind this, or is it a compliance exercise the AI team is running alone? An unsigned or generic policy is treated as a mandatory gap — full stop.

What actually belongs in it

Keep it to about two pages. It should state your commitment to lawful, safe and fair AI; define the scope (which systems, which parts of the business); reference your objectives and your commitment to meeting applicable requirements and continual improvement; and name who owns it. Resist the urge to bury it in technical detail — the policy sets direction; your procedures and the risk register carry the how. If a sentence could appear in any company's policy unchanged, it's probably filler.

The part teams skip: genuine sign-off

A policy signed by the AI lead is not a top-management policy. ISO 42001 expects sign-off from the level that can actually allocate resources and set direction — typically the CEO or an executive with delegated authority. The difference isn't bureaucratic: an auditor will ask how leadership stays involved (through the management review), and a policy signed at the wrong level exposes that the commitment is thinner than it looks.

Make it specific to your AI

The single biggest quality signal is specificity. A policy that names the kinds of AI you actually use — a customer chatbot, a CV-screening model, a forecasting tool — and the risks you take seriously reads as real. It also does practical work: it scopes what the rest of your system has to cover. Generic policies force generic controls; specific policies let you focus effort where your real exposure is.

The test. Read your draft and ask: could a competitor publish this unchanged? If yes, it's too generic to be useful. A policy that names your systems, your risks and your accountable owner — and is signed where it counts — does more in two pages than a twenty-page one ever will.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.