ISO/IEC 42001 AI Management System
Operational AIMS software suite—hub, spoke plugins, and AI system inventory—implementing ISO/IEC 42001:2023 clauses 4–10 and Annex A with certification-ready evidence.
Overview
This platform turns ISO/IEC 42001 into a living management system: structured records, PDCA-gated workflows, spoke registers for operational clauses, and automatic evidence roll-up to a central AIMS hub.
It is delivered as a modular plugin suite (Redmine-based AIMS stack) designed for organisations preparing for certification, governing high-impact AI systems, or aligning AIMS operation with the EU AI Act and related harmonised standards.
Architecture: hub, spokes, and inventory spine
- AIMS Hub (ISO 42001 AIMS — Management Domains) — PDCA-aligned management domains with phase gates, clause/implementation guidance, Annex A evidence tabs, completeness scoring, and certification readiness views. Phases advance only when prior work meets completeness thresholds.
- ISO 42001 Core library — Shared Annex A catalogue, Statement of Applicability helpers, spoke registry, traceability, and evidence packaging used by the hub and all spokes.
- Operational spoke plugins — Clause-specific registers (context, risk, operation, data, design, support, audit, management review, CAPA, suppliers, change, controls, and more) that sync structured evidence upward to the hub.
- AI System Inventory spine — Records stay linked to AI system identity (system ID, version, intended purpose / CF references) so audits can follow every control and decision back to a real system.
- Navigation Hub & KPI Dashboard — Suite navigation tiles and top-management KPIs (audits, CAPA, competence, change latency, strategic goals, management review).
What the plugin suite covers
Each module below is a dedicated ISO/IEC 42001 (or closely allied) plugin in the suite. Enable the spokes you need; evidence remains coherent through the hub and core registry.
Leadership, context & planning
- Context (Clause 4) — Structured records for 4.1 context, 4.2 interested parties, and 4.3 scope with clause guidance.
- Accountability (roles & authorities) — Role catalogue, clause assignments, lifecycle RACI, outsourcing and decision authority evidence.
- Policy Register — Controlled AI policy set with review, approve, sign, and PDF export; implementation tracking.
- Strategic Goals & AI objectives — QMS/AIMS strategic goals mapped to plugins, KPIs, owners, and project-level ISO 42001 6.2 objectives linked to monitoring KRIs.
- Regulatory Register — Obligations register (e.g. GDPR, EU AI Act, NIS2, DORA, CRA) with compliance scoring for interested-party and legal context.
Risk, controls & change
- AI Risk Management — Risk management file and cybersecurity framework components (aligned with prEN 18228 / prEN 18282 practice) with system-level traceability.
- AI Controls Management — Internal control system and agentic AI controls, linked to AI system identity for operational and QMS alignment.
- Change Management — Planned changes (clause 6.3) with approval chains and pervasive control footer on governed records.
- Component Register (CMDB) — Models, systems, and supporting components for technical documentation and configuration control.
Operation, data & lifecycle
- Clause 8 Operation — Operational planning, AI risk assessment and treatment, and AI system impact assessment registers with sub-process workflows.
- Operation Control — Runtime-oriented Annex A controls (operation & monitoring, event logs, computing resources, responsible use themes).
- Design & Development — Annex A.6 / ISO/IEC 5338 life-cycle processes and trustworthiness guidance with hub evidence sync.
- Data Management — Annex A.7 data for AI systems: ISO/IEC 8183 lifecycle, ISO/IEC 5259 data quality measures, labelling, DQ governance, and DQ reports.
- Human Oversight — Registration and monitoring of oversight measures aligned with AI Act Article 14 / Annex IV themes and ISO 42001 A.9.
Support, evaluation & improvement
- Support (Clause 7) — Resources, competence, awareness, and communication (including authority communications).
- Documented Information & Competence — Controlled documented-information register and competence-linked workflows (clause 7.5).
- Evidence & Document Control — Controlled objective evidence library: folders, versioning, approval, archive, system/version traceability.
- AIMS Management Record Register — Document and evidence register with file upload for AIMS artefacts.
- Performance Monitoring (Clause 9.1) — Measurement results, method validity, AIMS effectiveness, KRI panels, incident communications, optional analyzer bridge.
- Internal Audit (Clause 9.2) — Audit programme, impartiality, multi-stage engagement workflow, CAPA/improvement spawn, hub Tab 4 sync.
- Management Review (Clause 9.3) — Dedicated review register with structured sub-process workflow and hub evidence sync.
- Continual Improvement & CAPA (Clause 10) — Improvement and nonconformity/CAPA registers with multi-step workflows.
- Supplier Control — Supply-chain assurance: due diligence, acceptance, monitoring, and signed evidence for external providers and GPAI/LLM vendors.
Visibility & integration
- ISO 42001 Navigation Hub — Top-menu tiles for each enabled suite destination, with suite user guide.
- AIMS KPI Dashboard — Leadership view of CAPA, audits, competence, change latency, management review, and strategic goals.
- Assurance Core & Assurance Dashboard — Shared assurance contracts and aggregated execution summaries across assurance plugins.
- AI Integration layer — Shared view hooks and safe menu handling across the AI Act / risk ecosystem plugins.
Key platform capabilities
- PDCA phase gates and management-domain completeness on the AIMS hub
- Clause- and Annex A–aligned spoke workflows with automatic hub evidence sync
- AI-system-scoped traceability across risk, controls, change, data, and operation records
- Statement of Applicability / Annex A catalogue support via the core library
- Internal audit, management review, CAPA, and performance monitoring as first-class modules
- Integrity-oriented evidence (versioning, approval, Merkle/signing options where configured)
- Dual use: ISO/IEC 42001 certification programmes and practical alignment with EU AI Act QMS themes from one data foundation
Who it is for
- Organisations implementing or certifying an ISO/IEC 42001 AIMS
- Providers and deployers needing system-level evidence for high-risk or high-impact AI
- Governance, risk, and compliance teams wanting operational registers—not only policy manuals
- Teams that must keep inventory, risk, impact assessment, and operational controls connected
Related solution pages
- AIMS system overview
- Implementation with confidence
- AIMS for agentic AI
- Unlocking value from ISO/IEC 42001
- AI Risk Management System · AI Log Analyzer
Availability
The ISO/IEC 42001 AI Management System suite is available for demonstration and pilot deployment. Request a walkthrough of the hub and priority spokes for your AI portfolio, or download the comprehensive AIMS brochure.
Module availability depends on enabled plugins, project modules, and configuration. Map controls to your certification scope and legal obligations with competent advisors.