Last updated:
A document that identifies which ISO 42001 Annex A controls are relevant to an organization's AI Management System and explains why others were excluded.
The SoA is the roadmap for an auditor. It lists all 38 controls (A.2 to A.10), specifies their current implementation status, and provides a risk-based justification for any control deemed unnecessary. For organizations with diverse AI portfolios, it allows for tiered governance, where strict controls are applied to high-risk systems while lighter ones apply to low-risk tools.
Real world example:
A healthcare provider's SoA includes strict human oversight controls for its diagnostic AI but excludes data lineage requirements for a basic internal meeting-transcription bot.




