ISO/IEC 42001:2023
Planning – ISO/IEC 42001:2023

ISO/IEC 42001:2023 6.2: AI objectives and planning to achieve them

Set AI objectives for the relevant functions and levels that are consistent with the AI policy, measurable where practicable, take account of applicable requirements, are monitored, communicated, updated as appropriate and documented. When planning them, decide what will be done, with what resources, by whom, by when and how results will be evaluated; Annex C lists example objectives and A.9.3 and A.6.1 cover responsible development and use objectives.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 27 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated

ISO 22301:2019 · 3 controls

  • 6.2 Business continuity objectives and planning to achieve them
  • 6.2.1 Establishing business continuity objectives
  • 6.2.2 Determining business continuity objectives

SOC 2 · 3 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

ISO 56002 · 2 controls

  • ISO-56002-6.2 Innovation objectives and planning to achieve them
  • ISO56002-6.2 Innovation objectives and planning to achieve them

PCI DSS 4.0 · 2 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • AS9100D-6.2 Quality Objectives and Planning to Achieve Them

ISO 14001:2015 · 1 control

  • 6.2 Environmental objectives and planning to achieve them

ISO 14004:2016 · 1 control

  • 6.2 Environmental objectives and planning to achieve them

ISO 22000:2018 · 1 control

  • 6.2 Objectives of the food safety management system and planning to achieve them

ISO 27001:2022 · 1 control

  • 6.2 Terms and conditions of employment

ISO 27701:2019 · 1 control

  • 6.2 Information security policies

ISO 37001:2016 · 1 control

  • 6.2 6.2 Anti-bribery objectives and planning to achieve them

ISO 37301:2021 · 1 control

  • 6.2 Compliance objectives and planning to achieve them
  • ISO-39001-6.3 RTS objectives and planning to achieve them

ISO 45001:2018 · 1 control

  • 6.2 OH&S objectives and planning to achieve them

ISO 55001:2014 · 1 control

  • 6.2 Asset management objectives and planning to achieve them

ISO 9001:2015 · 1 control

  • 6.2 Quality objectives and planning to achieve them

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Planning – ISO/IEC 42001:2023

You are reading one control. How much of ISO/IEC 42001:2023 have you already done?

ISO/IEC 42001:2023 6.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO/IEC 42001:2023 your existing evidence covers. Hold NIST AI Risk Management Framework (AI RMF 1.0) and 30 of 38 ISO/IEC 42001:2023 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST AI Risk Management Framework (AI RMF 1.0) pair alone.

Query this from an agent

The graph holds this control, the 27 it maps to, and the evidence behind each claim, over MCP and REST.