The question comes up in almost every first conversation about ISO/IEC 42001: what do we actually have to write?
It is a fair question with an awkward answer, because the standard does not hand you a numbered list of file names. It states requirements, and the documents follow from them. Which is why you will find articles online confidently listing a specific number of mandatory documents, and why those numbers do not always agree with each other.
This guide takes a different approach. It works through the clauses of ISO/IEC 42001:2023, shows what documented information each one generates, and describes what an auditor will ask to see. It is written for organisations in Iraq preparing for certification.
What documented information means in ISO/IEC 42001
Clause 7.5 of the standard is titled Documented information. It is the clause that governs everything else in this article: how information is created, how it is identified and reviewed, how it is controlled, and how it is kept available to the people who need it.
Two consequences follow, and both catch people out.
The first is that a document nobody controls is not documented information. A policy that exists as an untitled file on someone's laptop, with no version, no owner and no approval date, will be treated as absent. The content can be excellent and it will still be a finding.
The second is that documented information includes the evidence, not just the policies. Meeting minutes, assessment records, training records and audit reports are all in scope. Most organisations under-prepare here. They arrive with a beautiful set of policies and very little proof that anything described in them ever happened.
The documents each clause generates
ISO/IEC 42001:2023 follows the standard management system structure, so the clauses run from context through to improvement. Here is what each part of the standard tends to produce.
Clause 4, Context of the organization
- A record of the internal and external issues relevant to your use of AI, and of the interested parties and their expectations, from clauses 4.1 and 4.2.
- The scope of the AI management system, from clause 4.3. This is the single most important document you will write. It states which AI systems, activities, sites and functions are covered, and it is what appears on the certificate.
Clause 5, Leadership
- The AI policy, from clause 5.2, which the standard names explicitly. It sets out top management's commitments and gives the objectives something to hang from.
- A record of roles, responsibilities and authorities, from clause 5.3. An organisation chart alone rarely satisfies this. Auditors look for who decides, not just who reports to whom.
Clause 6, Planning
- Your approach to actions addressing risks and opportunities, from clause 6.1.
- AI objectives and the plans to achieve them, from clause 6.2. Objectives that cannot be measured are the most common weak point in this clause.
- A record of how planned changes are handled, from clause 6.3.
Clause 7, Support
- Resources, from clause 7.1.
- Competence records, from clause 7.2. Who needs which skills for AI related roles, and the evidence that they have them.
- Awareness, from clause 7.3, and communication arrangements, from clause 7.4.
- The controls over documented information itself, from clause 7.5.
Clause 8, Operation
- Operational planning and control records, from clause 8.1, including how you keep control of anything outsourced.
- The AI risk assessment, from clause 8.2, and the AI risk treatment, from clause 8.3.
- The AI system impact assessment, from clause 8.4. This one has no equivalent in ISO 9001 or ISO/IEC 27001 and is where most organisations have the least to show. We cover it in detail in AI impact assessment requirements under ISO/IEC 42001.
Clause 9, Performance evaluation
- Monitoring and measurement results, from clause 9.1.
- The internal audit programme and its reports, from clause 9.2.
- Management review minutes, from clause 9.3, showing inputs, decisions and actions.
Clause 10, Improvement
- Records of nonconformities and corrective actions, from clause 10.2, including what caused each one and what you did so it does not recur.
Notice how much of that list is evidence rather than policy. That balance is the point.
Annex A, and showing which controls apply
ISO/IEC 42001 carries Annex A, Reference control objectives and controls, with implementation guidance in Annex B covering areas such as policies related to AI, internal organization, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third party and customer relationships.
Your management system has to show which of those controls apply to you, which do not, and why. That record is commonly called a Statement of Applicability, borrowing the name from ISO/IEC 27001, and whatever you call it, an auditor will ask for it.
Write the justifications properly. "Not applicable" with no reasoning is one of the fastest ways to turn a short audit conversation into a long one.
Documents and records are not the same thing
Worth being precise about, because the distinction shapes how you keep them.
| Documents | Records | |
|---|---|---|
| Answer | What we intend to do | What we actually did |
| Examples | AI policy, scope, procedures | Impact assessments, audit reports, training records, review minutes |
| Change over time | Revised and reissued under version control | Not edited after the fact; a new record is created |
| Audit question | Is it current and approved? | Is it complete, dated, and does it match what people describe? |
Editing a record after the event to make it read better is worse than leaving the gap. Auditors notice, and it changes the conversation from a documentation gap to a question about integrity.
What UCS reviews at Stage 1
Our ISO certification process page describes Stage 1 as a thorough review of your documentation, processes and overall readiness against the applicable standard. In practice the Stage 1 review is where documentation problems surface, which is exactly what it is for.
Expect attention on:
- Whether the scope statement is clear, and whether it matches the AI systems you actually run.
- Whether the AI policy exists, is approved, and says something specific to your organisation.
- Whether risk assessment, risk treatment and impact assessment records exist for the systems in scope.
- Whether internal audits have been carried out and a management review has been held. A system that has never been reviewed by its own management is not ready.
- Whether documented information is under control, with versions, owners and approval dates.
A Stage 1 audit report follows. Anything raised there is far cheaper to deal with at that point than at Stage 2.
What UCS reviews at Stage 2
Stage 2 asks you to document how the system complies with the standard by using objective evidence. Stage 1 largely asks whether the document exists; Stage 2 asks whether the organisation runs the way the document says it does.
That means auditors will trace things end to end. A risk identified in your assessment gets followed through to a treatment decision, to the control that implements it, and to a person who can describe doing it. An objective in clause 6.2 gets followed to the measurement in clause 9.1 and into the management review in clause 9.3.
Any nonconformities identified at Stage 2 must be addressed before certification is formally granted. After certification, surveillance audits are carried out annually, so the records have to keep accumulating rather than stopping the week the certificate arrives.
Who is allowed to write these documents
You are. Or an adviser you appoint. It cannot be your certification body.
UCS operates as an accredited certification body under ISO/IEC 17021-1:2015, and that standard requires certification bodies to be impartial towards the organisations they certify. We cannot design your AI management system, write your policy, produce your impact assessments, prepare your documents or close your gaps, and then audit our own work. Any body offering to do both is offering you a certificate that a serious client or regulator can pull apart.
The line is finer than it first looks, and it is worth being exact about, because the two halves get confused constantly. Reading your system and reporting what is missing is assessment, and it is permitted. That is what a Stage 1 audit does. Writing, correcting or designing the system is preparation, and it is not permitted for the body that will certify you.
So what we can properly do is assess your management system and tell you what we find, certify it when it meets the standard, and deliver training so your own people understand what the standard asks for. What we cannot do is hand you the answer and then mark your paper. It is worth knowing which side of that line anyone you engage is standing on.
Documentation problems that hold certification up
- A scope that does not match reality. The certificate covers what the scope says. If the scope names two AI systems and the auditor finds five in use, that gets resolved before anything else.
- Purchased template packs left generic. A policy that still refers to another organisation's business, or to controls you do not operate, is worse than a short policy that is true.
- Objectives that cannot be measured. "Use AI responsibly" is a sentiment. Clause 9.1 has nothing to monitor.
- No impact assessment, or a risk assessment relabelled as one. Clause 8.4 asks who is affected and how severely. If no category of person outside the organisation is named, the clause has not been met.
- Internal audit and management review missing. Both are requirements, and both have to have happened before certification, not be scheduled for later.
- No version control. Undated, unapproved documents are treated as absent regardless of quality.
- Third-party AI left out entirely. Licensed and embedded AI tools sit inside your scope when you use them, and they are usually the ones making decisions about real people.
ISO/IEC 42001 documentation for organisations in Iraq
Three things are worth knowing before you start building the file in Iraq.
Language. Your management system can be maintained in whichever language your people actually work in. What matters at audit is that the auditor can follow the evidence, so agree the working language and any translation arrangements at the application stage rather than discovering the problem on the morning of Stage 1.
Scope comes before paperwork. The most expensive documentation mistake is writing a full set of documents and only then deciding which AI systems, sites and activities the certificate covers. Fix the scope first. Every document afterwards inherits it.
Bought-in AI still counts. ISO/IEC 42001 applies to organisations that develop, provide or use AI-based products and services. An Iraqi organisation running a licensed AI tool has documentation obligations for its own use of that tool. The supplier's paperwork describes the supplier's context, not yours, and an auditor will ask for yours.
None of this is Iraqi law. ISO/IEC 42001 is a voluntary international standard, and holding the certificate does not settle any legal obligation that applies to you in Iraq. Keep the two conversations separate.
Frequently asked questions
How many documents does ISO/IEC 42001 require?
There is no single agreed number, and you should be cautious of any article that gives one with confidence. The standard states requirements rather than listing file names, and the documented information you need depends on your scope, your AI systems and which Annex A controls apply to you. Work from the clauses, as set out above, rather than from a checklist written for somebody else's organisation.
Can we use a template pack?
You can, and many organisations do. The risk is that templates are written to be general, and audits are specific. A template that has not been rewritten to describe your actual systems, decisions and people will be visible as such very early in Stage 2.
Does everything have to be on paper?
No. Documented information can be held in any medium, and most organisations keep it in their existing document management or governance tooling. What matters is control: identification, version, approval, availability and protection.
How long do we keep records?
Set your own retention periods, document them, and apply them consistently. Bear in mind the three year certification cycle with annual surveillance audits, so records need to remain retrievable across that period at minimum.
Can UCS look at our documents before the certification audit?
Yes, as an assessment, and no, as preparation. The distinction is what ISO/IEC 17021-1:2015 turns on.
A certification body may read your management system and report what is missing. That is assessment, and it is exactly what the Stage 1 audit does: your documentation is reviewed and the Stage 1 audit report tells you where you stand while there is still time to act.
What a certification body may not do is write, correct or design your documentation and then certify its own work. If you want a review earlier than Stage 1, talk to us about what is available in Iraq.
Do we need ISO/IEC 27001 as well?
Not as a prerequisite. They are separate certifications with separate scopes, and each can be held on its own.
Next steps
If you are preparing for ISO/IEC 42001 certification in Iraq, our ISO/IEC 42001 certification page covers the standard and how certification works, and the certification process page sets out each stage. To talk through your scope with an auditor, request a free assessment or contact UCS on +964 773 828 8889.