IT Governance — AI assurance and compliance

Services

ISO/IEC 42001 Internal Audit Service

Independent internal audit of the AIMS (ISO/IEC 42001 Clause 9.2) and of high-risk AI systems against the AI Act — rotational programme, impartial fieldwork, CAPA, and reports to management.

The service

Independent internal audit covering two layers: the AI management system under ISO/IEC 42001 Clause 9.2, and the high-risk AI systems themselves against EU AI Act obligations. We work to an agreed Audit Plan on a rotational basis and report to management — we are not the team that designed the controls we then audit.

Fieldwork can run in the AIMS internal-audit module (multi-stage engagement, impartiality record, CAPA spawn, hub sync) and, where needed, on the AI Audit Solution used for Act-level verification of high-risk systems.

What we audit

How an engagement runs

  1. Plan — agree scope, systems, impartiality, and the rotational programme with management.
  2. Fieldwork — four-stage AIMS audit workflow and/or Act-level tasks with auditor, reviewer, and approver roles; providers and suppliers can contribute technical description where needed.
  3. Findings and CAPA — nonconformities spawn corrective actions in the AIMS CAPA register; we track them to closure.
  4. Report — management report, audit findings, and, where in scope, Annex IV-oriented technical-documentation and audit-report packs for later conformity assessment.

Who uses it

The audit platform is described in the AI Audit Solution brochure. AIMS Clause 9.2 sits inside AIMS as a Service.

← Back to Services