Glossary term
Glossary term
Governance and Compliance
The boundary of the AI Management System, including organizational units, AI systems, locations, activities, interfaces, and exclusions. A clear scope prevents certification and governance blind spots and should be defensible to auditors, especially where business units use AI outside central IT or vendors embed AI into existing services.
Anthropic's ISO 42001 certificate scopes the AIMS to AI research and development and AI services in the roles of AI producer, AI developer, and AI product and service provider.
AWS's ISO 42001 scope explicitly lists the AI services included such as Amazon Bedrock and Amazon Q Business, leaving other AWS services outside the certified boundary.
Statement of Applicability documents under ISO 42001 record which Annex A controls apply to the in-scope AIMS, with exclusions justified in writing.