IT Governance

Quality, Risk and Assurance

Comprehensive ISO/IEC 42001 AI Management System

Hub, spoke plugins, and AI system inventory - implementing ISO/IEC 42001:2023 clauses 4-10 and Annex A with certification-ready evidence.

Overview

This platform turns ISO/IEC 42001 into a living management system: structured records, PDCA-gated workflows, spoke registers for operational clauses, and automatic evidence roll-up to a central AIMS hub.

It is a modular plugin suite designed for organisations preparing for certification, governing high-impact AI systems, or aligning AIMS operation with the EU AI Act and related harmonised standards - from one data foundation.

Architecture: Hub, Spokes, and Inventory Spine

  • AIMS Hub - PDCA-aligned management domains with phase gates, clause guidance, Annex A evidence tabs, completeness scoring, and certification-readiness views. Phases advance only when prior work meets completeness thresholds.
  • Operational spoke plugins - clause-specific registers (context, risk, operation, data, design, support, audit, management review, CAPA, suppliers, change, controls) that sync structured evidence upward to the hub.
  • AI System Inventory spine - every record stays linked to system ID, version, and intended purpose so audits can follow a control back to a real system.
  • Navigation Hub and KPI Dashboard - suite tiles and top-management KPIs for audits, CAPA, competence, change latency, strategic goals, and management review.

What the Suite Covers

Leadership, context and planning

  • Context (Clause 4) - 4.1 context, 4.2 interested parties, and 4.3 scope.
  • Accountability - role catalogue, clause assignments, lifecycle RACI, and decision authority.
  • Policy, objectives, and regulatory register - controlled AI policy set; 6.2 objectives and KRIs; obligations such as GDPR, EU AI Act, NIS2, DORA, and CRA.

Risk, operation, data and lifecycle

  • AI risk and controls - risk management file and control system with system-level traceability (aligned with prEN 18228 practice).
  • Clause 8 operation - operational planning, risk treatment, and impact-assessment registers.
  • Design, data, and human oversight - Annex A.6 / ISO/IEC 5338 lifecycle, Annex A.7 / ISO/IEC 5259 data quality, and oversight measures aligned with AI Act Article 14 themes.
  • Supplier control - due diligence, acceptance, and monitoring for external providers and GPAI/LLM vendors.

Evaluation and improvement

  • Internal audit (Clause 9.2) - programme, impartiality, multi-stage engagement, CAPA spawn.
  • Management review (Clause 9.3) - dedicated register with a structured sub-process workflow.
  • CAPA and continual improvement (Clause 10) - nonconformity and improvement registers with multi-step workflows.
  • Performance monitoring (Clause 9.1) - measurement results, KRIs, optional analyzer bridge.

Key Platform Capabilities

  • PDCA phase gates and management-domain completeness on the AIMS hub
  • Clause- and Annex A-aligned spoke workflows with automatic hub evidence sync
  • Statement of Applicability / Annex A catalogue support
  • Integrity-oriented evidence (versioning, approval, Merkle/signing options where configured)
  • Dual use: ISO/IEC 42001 certification and EU AI Act QMS themes from one data foundation

Who It Is For

  • Organisations implementing or certifying an ISO/IEC 42001 AIMS
  • Providers and deployers needing system-level evidence for high-impact AI
  • GRC teams that want operational registers, not only policy manuals

Related Pages

Availability

The ISO/IEC 42001 AI Management System suite is available for demonstration and pilot deployment. Request a walkthrough of the hub and priority spokes for your AI portfolio, or download the comprehensive AIMS brochure.