Aguardic logoAguardic

ISO 42001 AI Risk Management

by AguardicOfficial·v1.0.0

Enforce AI risk assessment and treatment requirements per ISO 42001 Annex A.2 controls.

About This Policy Template

Policy for organizations pursuing ISO/IEC 42001:2023 certification for AI management systems. Enforces Annex A.2 controls requiring systematic AI risk identification, assessment, and treatment. Detects AI deployments lacking documented risk assessments, flags high-risk AI decisions made without risk treatment plans, identifies residual risks accepted without proper authority, and ensures AI entries exist in organizational risk registers. Covers A.2.2 (AI risk assessment), A.2.3 (AI risk treatment), and A.2.4 (residual risk acceptance). Essential for demonstrating AIMS conformity to auditors.

Policy Rules(6)

Critical Severity

(1)

High-Risk AI Without Treatment Plan

Flag high-risk AI decisions or outputs lacking risk treatment documentation (A.2.3)

AI

High Severity

(3)

AI Deployment Without Risk Assessment

Detect AI system deployments or changes lacking a documented risk assessment (A.2.2)

AI

AI Risk Not Reviewed After System Change

Detect AI system changes that proceed without risk reassessment (A.2.2)

AI

Residual Risk Accepted Without Authority

Detect residual AI risk acceptance without proper management authority (A.2.4)

AI

Medium Severity

(2)

Missing AI Risk Communication to Stakeholders

Detect AI risk information not communicated to relevant stakeholders (A.2.3)

AI

Risk Register Missing AI System Entries

Detect risk register or risk management content that omits AI-specific risk entries (A.2.2)

Rule

Enforcement by Integration

What happens when a violation is detected, based on the enforcement mode and integration type.

IntegrationBlockApprovalWarnMonitor
Version Control
GitHub, GitLab, Bitbucket
Fail check run / merge request statusPending check run — held for reviewNeutral check run / comment on PRPass check run (silent)
Email — Gmail
Gmail
Quarantine label; + violation label (outbound)Quarantine label — held for reviewAdd warning labelLog only
Email — Outlook
Outlook
Move to quarantine folder; + flag (outbound)Move to quarantine — held for reviewFlag + categorizeLog only
Messaging
Slack, Teams
Post violation warning in channelPost 'held for review' warningPost warning in channelLog only
Storage
Google Drive, Dropbox, OneDrive
Move file to quarantine folderQuarantine file — held for reviewLog onlyLog only
AI Proxy
OpenAI, Anthropic, Gemini, MCP, Agent
Block request (return 403)Hold request — return review IDAllow request + audit trailLog only
API
REST API
Return BLOCK outcome (client decides)Return APPROVAL_REQUIRED + poll URLReturn WARN outcomeLog only

Version History

1 version published

v1.0.0Active3/26/2026

Initial release

ISO 42001 questionnaire?

Answer ISO 42001 AIMS questions with controls Aguardic enforces

Try the tool

Ready to Install ISO 42001 AI Risk Management?

Get started with pre-built governance policies in minutes.