Define an AI management system scope statement appropriate to the organisation's AI systems and roles.
Implementing an AI Management System Based on ISO/IEC 42001
Learn to build and operate an AI management system aligned with ISO/IEC 42001:2023, from scope and risk assessment through internal audit to certification readiness.
Course Overview
ISO/IEC 42001:2023 is the first international management system standard written specifically for organisations that develop, provide or use artificial intelligence, and it follows the same high-level structure as ISO 9001 and ISO/IEC 27001 while adding requirements distinct to AI, such as AI system impact assessment and data provenance controls. This course walks participants through building an AI management system, an AIMS, from a defined scope statement through the risk and impact assessment process the standard requires, into the control set drawn from its Annex A, and finally into internal audit and management review ready to support certification. Rather than treating the standard as a checklist, the course focuses on the judgement calls implementation actually requires: how to scope the AIMS realistically for an organisation with many AI systems at different maturity levels, how to conduct an AI system impact assessment that produces evidence rather than a generic statement, and how to integrate the AIMS with existing ISO 27001 or quality management systems instead of running parallel documentation. Participants leave with a scope statement, a completed impact assessment for one AI system and an internal audit checklist mapped to the standard's clauses.
Expected Learning Outcomes
Conduct an AI system impact assessment covering safety, fairness, security and societal effects.
Map organisational AI risks to the controls set out in ISO/IEC 42001's Annex A.
Integrate an AI management system with an existing ISO/IEC 27001 or ISO 9001 management system.
Establish data provenance and quality controls required for AI systems within the AIMS scope.
Plan and execute an internal audit of the AI management system against the standard's clauses.
Prepare a management review and evidence pack ready to support a certification audit.
Who Should Attend
Quality and compliance managers implementing ISO/IEC 42001
AI governance leads building or maturing an AI management system
Internal auditors extending audit scope to cover AI systems
Information security managers integrating AIMS with ISO 27001
Product and engineering leaders responsible for AI system controls
Consultants supporting organisations toward ISO/IEC 42001 certification
Course Modules
Select any module to see its sessions and points.
01Scoping the AI Management System
2 sessions · 8 points
Session 1Understanding the Standard's Structure and Requirements
- Map ISO/IEC 42001's high-level structure against familiar ISO 9001 and ISO/IEC 27001 clause numbering.
- Identify the AI-specific requirements the standard adds, including impact assessment and system lifecycle controls.
- Distinguish the roles of AI provider, developer and user as defined by the standard for scoping purposes.
- Review Annex A's control objectives to understand the breadth of what implementation must eventually cover.
Session 2Writing a Realistic Scope Statement
- List every AI system in the organisation and classify its maturity from experimental to production.
- Decide which systems, business units and roles fall inside the AIMS boundary for a first certification cycle.
- Justify exclusions from scope in terms an external auditor will accept rather than convenience alone.
- Draft a scope statement reviewed by leadership before it is used to plan the rest of the implementation.
02AI Risk and Impact Assessment
2 sessions · 8 points
Session 1Conducting the AI System Impact Assessment
- Assess each in-scope AI system for potential safety, fairness, security and rights impacts on affected people.
- Document data sources, training methods and known limitations as inputs to the impact assessment.
- Involve technical, legal and business stakeholders so the assessment is not written by one function alone.
- Translate assessment findings into specific risk treatment actions rather than a narrative summary alone.
Session 2Building the AI Risk Register
- Establish a risk register that links each identified AI risk to a named owner and treatment action.
- Score risks using criteria appropriate to AI harms, not only conventional operational risk categories.
- Review the risk register at defined intervals as models, data or usage patterns change.
- Escalate risks exceeding organisational appetite to the governance body defined in the AIMS.
03Controls and Integration
2 sessions · 8 points
Session 1Implementing Annex A Controls
- Select and implement controls covering AI system lifecycle management, from design through decommissioning.
- Establish data provenance and quality controls so training and input data can be traced and verified.
- Implement controls for third-party and supplier AI components used within in-scope systems.
- Record justification for any control excluded from implementation, consistent with the standard's requirements.
Session 2Integrating with Existing Management Systems
- Align AIMS documentation with an existing ISO/IEC 27001 information security management system where one exists.
- Share risk assessment, internal audit and management review processes across systems rather than duplicating them.
- Update existing policies, such as data protection and security policies, to reference AI-specific requirements.
- Assign combined or coordinated ownership so AIMS and other management systems do not drift apart over time.
04Internal Audit and Certification Readiness
2 sessions · 8 points
Session 1Planning and Running the Internal Audit
- Build an internal audit checklist mapped to each clause and applicable Annex A control of the standard.
- Select auditors independent of the AI systems they will assess to preserve audit objectivity.
- Sample evidence such as impact assessments, risk registers and training records during the audit.
- Record nonconformities with enough detail for owners to design an effective corrective action.
Session 2Management Review and Certification Preparation
- Prepare a management review pack summarising audit results, risk status and improvement actions.
- Track corrective actions to closure with evidence before scheduling a certification audit.
- Brief staff likely to be interviewed by a certification auditor on the AIMS structure and their role in it.
- Assemble a document set an external certification body can review efficiently during a stage one audit.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
