IT Governance

Quality, Risk and Assurance

Comprehensive ISO/IEC 42001 AI Management System

A working AI management system for everyday conformity with ISO/IEC 42001

A Working AI Management System

ISO/IEC 42001 is the management system for the everyday running of AI in the organisation. It is how issues are worked through against the requirements of the standard: establish, implement, maintain and continually improve an AI management system. It is not a form to complete.

This AIMS is built to operate that standard. It is a working system. Conformity with ISO/IEC 42001 is the result of running it.

Templates, checklists and downloads can sit inside the system. They record work. They are not the AIMS.

What the Standard Requires

ISO/IEC 42001 asks the organisation to have an AI management system with defined scope, leadership, planning, support, operation, performance evaluation and improvement. Roles are assigned. Risks and opportunities related to AI are treated. The AI system lifecycle is controlled. Performance is measured. The system is reviewed and improved.

The standard states what must be achieved. It does not hand over the operating model. A pack of completed templates is not that model. An assessor looks at whether the system runs, who owns which duty, and what evidence the processes left.

What This Solution Is

The ISO/IEC 42001 AIMS is a single environment in which those processes are assigned, run, reviewed and evidenced.

It uses the criteria of the standard so the organisation can work toward certification. The same work is a self-assessment. Done properly, that self-assessment is able to meet the standard for a second-party or third-party assessment. It is not a tick-box exercise.

The system is for everyday management: intake, scope, roles, risk, the AI lifecycle, suppliers, performance, nonconformity and improvement. Issues are worked through against the clause, not parked in a register until audit week.

This suite is how that system is operated: named processes, evidence, and gates that follow the work. It is delivered as a modular plugin suite - hub, spoke plugins, and AI system inventory - implementing ISO/IEC 42001:2023 clauses 4-10 and Annex A from one data foundation.

The Process Approach

At its core, ISO/IEC 42001 uses a disciplined process approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organisation's AIMS. Every activity that consumes resources and turns inputs into outputs is a process. The output of one process is the input to the next. When those processes are identified, connected and managed, the organisation has a coherent process approach.

ISO/IEC 42001 places particular emphasis on four priorities:

  • Understanding organisational AI requirements and establishing clear policies and objectives for responsible AI governance.
  • Implementing and operating processes that manage AI-specific data and lifecycle risks within the broader context of enterprise business risks.
  • Monitoring and reviewing the performance and effectiveness of the AIMS through objective metrics.
  • Driving continual improvement grounded in measurable data and evidence.

The standard structures AIMS processes around the Plan-Do-Check-Act (PDCA) model, creating a cyclical, improvement-oriented rhythm that aligns with other international management system standards.

Architecture: Hub, Spokes, and Inventory Spine

  • AIMS Hub - PDCA-aligned management domains with phase gates, clause guidance, Annex A evidence tabs, completeness scoring, and certification-readiness views. Phases advance only when prior work meets completeness thresholds.
  • Operational spoke plugins - clause-specific registers (context, risk, operation, data, design, support, audit, management review, CAPA, suppliers, change, controls) that sync structured evidence upward to the hub.
  • AI System Inventory spine - every record stays linked to system ID, version, and intended purpose so audits can follow a control back to a real system.
  • Navigation Hub and KPI Dashboard - suite tiles and top-management KPIs for audits, CAPA, competence, change latency, strategic goals, and management review.

What the Suite Covers

Leadership, context and planning

  • Context (Clause 4) - 4.1 context, 4.2 interested parties, and 4.3 scope.
  • Accountability - role catalogue, clause assignments, lifecycle RACI, and decision authority.
  • Policy, objectives, and regulatory register - controlled AI policy set; 6.2 objectives and KRIs; obligations such as GDPR, EU AI Act, NIS2, DORA, and CRA.

Risk, operation, data and lifecycle

  • AI risk and controls - risk management file and control system with system-level traceability (aligned with prEN 18228 practice).
  • Clause 8 operation - operational planning, risk treatment, and impact-assessment registers.
  • Design, data, and human oversight - Annex A.6 / ISO/IEC 5338 lifecycle, Annex A.7 / ISO/IEC 5259 data quality, and oversight measures aligned with AI Act Article 14 themes.
  • Supplier control - due diligence, acceptance, and monitoring for external providers and GPAI/LLM vendors.

Evaluation and improvement

  • Internal audit (Clause 9.2) - programme, impartiality, multi-stage engagement, CAPA spawn.
  • Management review (Clause 9.3) - dedicated register with a structured sub-process workflow.
  • CAPA and continual improvement (Clause 10) - nonconformity and improvement registers with multi-step workflows.
  • Performance monitoring (Clause 9.1) - measurement results, KRIs, optional analyzer bridge.

Key Platform Capabilities

  • PDCA phase gates and management-domain completeness on the AIMS hub
  • Clause- and Annex A-aligned spoke workflows with automatic hub evidence sync
  • Statement of Applicability / Annex A catalogue support
  • Integrity-oriented evidence (versioning, approval, Merkle/signing options where configured)
  • Dual use: ISO/IEC 42001 certification and EU AI Act QMS themes from one data foundation
  • Traceability from operational records back to individual AI systems
  • Automated evidence aggregation for management review and certification-readiness scoring

Who It Is For

  • Organisations implementing or certifying an ISO/IEC 42001 AIMS
  • Providers and deployers needing system-level evidence for high-impact AI
  • GRC teams that want operational registers, not only policy manuals
  • Teams that have to show an assessor how work was assigned, how it ran, and what evidence it left

Related Pages

Availability

The ISO/IEC 42001 AI Management System suite is available for demonstration and pilot deployment. Request a walkthrough of the hub and priority spokes for your AI portfolio, or download the comprehensive AIMS brochure.