Chapter 5

Clause 5: Leadership

Top management commitment, AI policy establishment, and defining roles, responsibilities, and authorities for AI governance.

20 min read

Chapter Overview

Clause 5 establishes leadership requirements for the AIMS. Top management must demonstrate commitment, establish an AI policy, and ensure roles and responsibilities are defined. This clause is critical because without leadership support, AIMS implementation will fail.

Clause Structure

Sub-clauseTitleFocus
5.1Leadership and commitmentTop management accountability
5.2AI policyPolicy establishment and communication
5.3Organizational roles, responsibilities and authoritiesAccountability structure

5.1 Leadership and Commitment

Requirement

Top management shall demonstrate leadership and commitment with respect to the AI management system by:

  • Ensuring AI policy and objectives are established and compatible with strategic direction
  • Ensuring integration of AIMS requirements into business processes
  • Ensuring resources needed for AIMS are available
  • Communicating the importance of effective AI management
  • Ensuring AIMS achieves its intended outcomes
  • Directing and supporting persons to contribute to AIMS effectiveness
  • Promoting continual improvement
  • Supporting other relevant management roles to demonstrate leadership
Who is Top Management?

Top management refers to the person or group of people who direct and control an organization at the highest level. This typically includes CEO, Board, Executive Committee, or equivalent leadership body.

Evidence of Leadership Commitment

RequirementEvidence Examples
Policy and objectives establishedSigned AI policy, documented objectives
Integration into businessAI governance in business processes, job descriptions
Resources availableBudget allocation, staffing, tools procurement
CommunicationTown halls, emails, training, internal comms
Achieving outcomesKPIs, dashboards, performance reports
Supporting personsTraining, recognition, empowerment
Continual improvementImprovement initiatives, feedback mechanisms

Implementation Steps

  1. Brief top management on ISO 42001 requirements
  2. Obtain formal commitment (board resolution, executive sign-off)
  3. Allocate budget and resources
  4. Integrate AI governance into business planning
  5. Establish communication channels
  6. Include AI governance in management reviews

5.2 AI Policy

Requirement

Top management shall establish an AI policy that:

  • Is appropriate to the purpose of the organization
  • Provides a framework for setting AI objectives
  • Includes a commitment to satisfy applicable requirements
  • Includes a commitment to continual improvement of the AIMS

The AI policy shall:

  • Be available as documented information
  • Be communicated within the organization
  • Be available to interested parties, as appropriate
Policy vs Procedure

Policy: High-level statement of intent and direction (WHAT and WHY)
Procedure: Detailed steps for implementation (HOW)

The AI policy should be strategic, not operational. It sets direction without prescribing detailed processes.

AI Policy Content

ElementDescriptionExample Statement
Purpose alignmentLinks to organization mission"AI supports our mission to deliver innovative financial services"
Scope referenceWhat the policy covers"This policy applies to all AI systems within our AIMS scope"
PrinciplesCore AI governance principles"We commit to responsible, ethical, and transparent AI"
Compliance commitmentMeeting requirements"We comply with all applicable AI regulations and standards"
Risk managementApproach to AI risks"AI risks are systematically identified, assessed, and treated"
Continual improvementEnhancement commitment"We continually improve our AI governance practices"
AccountabilityResponsibility statement"All personnel are responsible for AI governance within their roles"

Template: AI Policy

AI Policy Template

[ORGANIZATION NAME] AI POLICY

Purpose: This policy establishes [Organization]'s commitment to the responsible development, deployment, and use of artificial intelligence systems.

Scope: This policy applies to all AI systems within the scope of our AI Management System, including [specify scope].

Policy Statements:
1. We develop and use AI systems that are safe, reliable, and aligned with our organizational values
2. We identify, assess, and manage AI-related risks throughout the AI system lifecycle
3. We ensure transparency and explainability appropriate to the context of AI system use
4. We maintain human oversight of AI systems commensurate with their risk level
5. We protect the rights and interests of individuals affected by AI decisions
6. We comply with all applicable laws, regulations, and standards
7. We continually improve our AI governance practices

Responsibilities: All personnel involved in AI activities are responsible for adhering to this policy. Specific responsibilities are defined in supporting procedures and role descriptions.

Review: This policy is reviewed annually or when significant changes occur.

Approval: [Signature, Name, Title, Date]

5.3 Organizational Roles, Responsibilities and Authorities

Requirement

Top management shall ensure that responsibilities and authorities for relevant roles are assigned, communicated, and understood within the organization. Top management shall assign responsibility and authority for:

  • Ensuring AIMS conforms to ISO 42001 requirements
  • Reporting on AIMS performance to top management
Key Roles for AIMS

AIMS Owner/Manager: Overall AIMS responsibility
AI Risk Owner: AI risk management oversight
AI System Owners: Accountability for specific AI systems
AI Ethics Lead: Responsible AI principles
Data Governance Lead: AI data quality and management
Internal Audit: AIMS audit function

RACI Matrix for AIMS

ActivityTop MgmtAIMS OwnerAI System OwnerAI Developer
AI Policy approvalARCI
Risk assessmentIARC
Control implementationIARR
Impact assessmentIARC
Internal auditICCI
Management reviewARCI
Incident responseIARR

R=Responsible, A=Accountable, C=Consulted, I=Informed

Implementation Steps

  1. Define AIMS roles and responsibilities
  2. Create or update job descriptions
  3. Assign specific individuals to roles
  4. Communicate assignments
  5. Document in AIMS documentation
  6. Review periodically

Documented Information Requirements

Mandatory Documents - Clause 5

Required:
• AI Policy (5.2)

Recommended:
• Roles and Responsibilities Document
• RACI Matrix
• Management Commitment Evidence (meeting minutes, budget approvals)
• Organization Chart showing AIMS roles

Sample Audit Questions

Auditor Questions - Clause 5

5.1 Leadership and Commitment:
• How does top management demonstrate commitment to AIMS?
• What resources have been allocated for AI governance?
• How is AI governance integrated into business processes?
• How does top management communicate the importance of AI governance?
• Show me evidence of management involvement in AIMS

5.2 AI Policy:
• May I see your AI policy?
• How was the policy approved and by whom?
• How is the policy communicated to employees?
• How do you make the policy available to interested parties?
• When was the policy last reviewed?

5.3 Roles and Responsibilities:
• Who is responsible for AIMS conformance?
• How are AIMS responsibilities communicated?
• Show me how roles are documented
• Who reports AIMS performance to top management?
• How do AI system owners know their responsibilities?

Common Nonconformities

TypeNonconformityHow to Avoid
MajorNo documented AI policyCreate and approve AI policy
MajorPolicy not approved by top managementObtain formal approval signature
MajorNo evidence of management commitmentDocument meetings, decisions, resources
MinorPolicy not communicated to all relevant staffImplement communication plan
MinorRoles not clearly definedDocument in RACI or responsibility matrix
MinorPolicy not available to interested partiesPublish on website or share on request
MinorNo evidence of policy reviewDocument annual review
Key Takeaways - Clause 5

1. Top management must actively demonstrate commitment, not just approve documents
2. AI policy is mandatory documented information
3. Policy must be communicated internally and available externally
4. Roles and responsibilities must be assigned, communicated, and understood
5. Someone must be responsible for AIMS conformance and reporting to management
6. Leadership sets the tone for AI governance culture

Exam Tips - Clause 5

• Know what "top management" means in ISO context
• Remember AI policy must be "available as documented information"
• Understand the difference between policy (strategic) and procedure (operational)
• Know the specific requirements for policy content
• Be able to explain how leadership commitment is evidenced
• Remember that someone must report AIMS performance to top management

AI Assistant
00:00