ISO/IEC 42001 · ISO/IEC 22989

What is your role when you use AI?

If your organisation uses Claude, Copilot, or AI features inside a SaaS product, ISO/IEC 42001 still applies to you. It just applies differently. Work out which role you hold, and which controls follow.

Why this matters

This is not optional, and it is the first thing an auditor will ask.

ISO/IEC 42001, Clause 4.1

“The organization shall consider the intended purpose of the AI systems that are developed, provided or used by the organization. The organization shall determine its roles with respect to these AI systems.

And then the sentence most organisations miss:

ISO/IEC 42001, Clause 4.1, Note 1

The organization’s roles can determine the applicability and extent of applicability of the requirements and controls in this document.

In other words, your role decides which controls you have to implement. Get the role wrong and your Statement of Applicability is wrong, which is a finding.

The most common misunderstanding we see. Organisations that only use AI assume ISO/IEC 42001 is for the companies that build it, so nothing applies to them. That is not correct. Being a user changes which controls apply. It does not remove them. Annex A.9, “Use of AI systems”, exists specifically for you.

The six roles, in plain English

These come from ISO/IEC 22989 clause 5.19, which ISO/IEC 42001 points to by name.

RoleYou are this if22989
AI providerYou supply a product or service that uses AI, to someone else. Includes running a platform others build AI on.5.19.2
AI producerYou design, develop, train, test or deploy AI systems. This is the builder.5.19.3
AI customerYou use an AI product or service, either yourself or by giving it to your own users. AI user is the sub-role.5.19.4
AI partnerYou provide a service around someone else’s AI: integrating it, supplying data, evaluating or auditing it.5.19.5
AI subjectYou are affected by an AI system rather than operating it. Usually your staff and your customers, not your organisation.5.19.6
Relevant authorityYou set or enforce policy or law. Regulators and policy makers.5.19.7
You can hold more than one role, and most organisations do. ISO/IEC 22989 says so explicitly. A company that uses Copilot internally and ships an AI feature to its own customers is a customer and a producer and a provider, all at once.

Work out your role

Tick everything your organisation actually does today. Be honest rather than aspirational, and answer for the AI systems in your intended scope.

AI role self-assessmentSix questions. Nothing is sent anywhere, this runs in your browser.

Shared responsibility for the tools you actually use

Knowing you are an AI user is the start. The next question is what that leaves you responsible for, tool by tool. Tick what your organisation uses.

Shared responsibility matrixSelect your tools to see what stays yours
Read this before you rely on the matrix. It shows the typical split for each kind of tool, so you have somewhere to start. It is not a statement of any vendor’s contractual commitments. Your agreement, your data processing terms and your tenant configuration govern, and they differ between plans. Checking the split against your actual contract is precisely what A.10.2 and A.10.3 require of you.

Three worked examples

1. You use Claude or Copilot for internal work

Your staff use a general AI assistant for drafting, analysis or code. You did not build it and you do not resell it.

Your role: AI customer, specifically AI user. Your staff are also AI subjects, and so is anyone whose data goes into your prompts.

What applies: A.9.2A.9.3A.9.4 for responsible use, A.10.3 for your supplier, A.2.2 for an AI policy, A.3.2 for who owns it internally, A.5.2 to A.5.5 if it touches people, and A.7.x for what data you put in. The development controls in A.6.1 largely do not.

2. You use an AI feature inside a SaaS product

Your CRM, HR platform or service desk has added AI scoring, summarising or routing. You switched it on.

Your role: still AI customer and AI user. The vendor is the AI provider and producer.

The trap here is A.9.4, intended use. You must show you checked what the vendor says the feature is for, and that your use matches it. If you are using a summariser to make decisions about people, you have gone beyond intended use and you own that.

3. You build an assistant on top of a model and give it to customers

You wrap an API, add your own prompts, data or retrieval, and ship it inside your product.

Your role: AI producer and AI provider, as well as an AI customer of the model vendor. This is the biggest step up in obligations, and it catches organisations by surprise.

Now A.6.1.2A.6.2.2 to A.6.2.8 apply, along with A.8.2 to inform your users and A.10.4 for your customers. You cannot point at the model vendor for these.

What to have ready for an audit

  • A written statement of the roles your organisation holds, for each AI system in scope, with the reasoning
  • Your Statement of Applicability, with control inclusions and exclusions justified by reference to those roles
  • Evidence for A.10.2: who outside your organisation has agreed to be responsible for what
  • For anything you only use: the vendor’s documented intended use, and your check that your use matches it
Prepared by Cianaa Technologies, an independent certification and assessment body operating across New Zealand, Australia and the wider Asia Pacific region. Role definitions are from ISO/IEC 22989:2022 clause 5.19; the requirement to determine roles is ISO/IEC 42001:2023 clause 4.1; control references are to ISO/IEC 42001:2023 Annex A. This guide is a starting point and is not a substitute for reading the standards or for an audit.