Digital Transformation & Artificial Intelligence

Implementing an AI Management System Based on ISO/IEC 42001

Learn to build and operate an AI management system aligned with ISO/IEC 42001:2023, from scope and risk assessment through internal audit to certification readiness.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

ISO/IEC 42001:2023 is the first international management system standard written specifically for organisations that develop, provide or use artificial intelligence, and it follows the same high-level structure as ISO 9001 and ISO/IEC 27001 while adding requirements distinct to AI, such as AI system impact assessment and data provenance controls. This course walks participants through building an AI management system, an AIMS, from a defined scope statement through the risk and impact assessment process the standard requires, into the control set drawn from its Annex A, and finally into internal audit and management review ready to support certification. Rather than treating the standard as a checklist, the course focuses on the judgement calls implementation actually requires: how to scope the AIMS realistically for an organisation with many AI systems at different maturity levels, how to conduct an AI system impact assessment that produces evidence rather than a generic statement, and how to integrate the AIMS with existing ISO 27001 or quality management systems instead of running parallel documentation. Participants leave with a scope statement, a completed impact assessment for one AI system and an internal audit checklist mapped to the standard's clauses.

Expected Learning Outcomes

01

Define an AI management system scope statement appropriate to the organisation's AI systems and roles.

02

Conduct an AI system impact assessment covering safety, fairness, security and societal effects.

03

Map organisational AI risks to the controls set out in ISO/IEC 42001's Annex A.

04

Integrate an AI management system with an existing ISO/IEC 27001 or ISO 9001 management system.

05

Establish data provenance and quality controls required for AI systems within the AIMS scope.

06

Plan and execute an internal audit of the AI management system against the standard's clauses.

07

Prepare a management review and evidence pack ready to support a certification audit.

Who Should Attend

01

Quality and compliance managers implementing ISO/IEC 42001

02

AI governance leads building or maturing an AI management system

03

Internal auditors extending audit scope to cover AI systems

04

Information security managers integrating AIMS with ISO 27001

05

Product and engineering leaders responsible for AI system controls

06

Consultants supporting organisations toward ISO/IEC 42001 certification

Course Modules

Select any module to see its sessions and points.

01

Scoping the AI Management System

2 sessions · 8 points

Session 1Understanding the Standard's Structure and Requirements

  • Map ISO/IEC 42001's high-level structure against familiar ISO 9001 and ISO/IEC 27001 clause numbering.
  • Identify the AI-specific requirements the standard adds, including impact assessment and system lifecycle controls.
  • Distinguish the roles of AI provider, developer and user as defined by the standard for scoping purposes.
  • Review Annex A's control objectives to understand the breadth of what implementation must eventually cover.

Session 2Writing a Realistic Scope Statement

  • List every AI system in the organisation and classify its maturity from experimental to production.
  • Decide which systems, business units and roles fall inside the AIMS boundary for a first certification cycle.
  • Justify exclusions from scope in terms an external auditor will accept rather than convenience alone.
  • Draft a scope statement reviewed by leadership before it is used to plan the rest of the implementation.
02

AI Risk and Impact Assessment

2 sessions · 8 points

Session 1Conducting the AI System Impact Assessment

  • Assess each in-scope AI system for potential safety, fairness, security and rights impacts on affected people.
  • Document data sources, training methods and known limitations as inputs to the impact assessment.
  • Involve technical, legal and business stakeholders so the assessment is not written by one function alone.
  • Translate assessment findings into specific risk treatment actions rather than a narrative summary alone.

Session 2Building the AI Risk Register

  • Establish a risk register that links each identified AI risk to a named owner and treatment action.
  • Score risks using criteria appropriate to AI harms, not only conventional operational risk categories.
  • Review the risk register at defined intervals as models, data or usage patterns change.
  • Escalate risks exceeding organisational appetite to the governance body defined in the AIMS.
03

Controls and Integration

2 sessions · 8 points

Session 1Implementing Annex A Controls

  • Select and implement controls covering AI system lifecycle management, from design through decommissioning.
  • Establish data provenance and quality controls so training and input data can be traced and verified.
  • Implement controls for third-party and supplier AI components used within in-scope systems.
  • Record justification for any control excluded from implementation, consistent with the standard's requirements.

Session 2Integrating with Existing Management Systems

  • Align AIMS documentation with an existing ISO/IEC 27001 information security management system where one exists.
  • Share risk assessment, internal audit and management review processes across systems rather than duplicating them.
  • Update existing policies, such as data protection and security policies, to reference AI-specific requirements.
  • Assign combined or coordinated ownership so AIMS and other management systems do not drift apart over time.
04

Internal Audit and Certification Readiness

2 sessions · 8 points

Session 1Planning and Running the Internal Audit

  • Build an internal audit checklist mapped to each clause and applicable Annex A control of the standard.
  • Select auditors independent of the AI systems they will assess to preserve audit objectivity.
  • Sample evidence such as impact assessments, risk registers and training records during the audit.
  • Record nonconformities with enough detail for owners to design an effective corrective action.

Session 2Management Review and Certification Preparation

  • Prepare a management review pack summarising audit results, risk status and improvement actions.
  • Track corrective actions to closure with evidence before scheduling a certification audit.
  • Brief staff likely to be interviewed by a certification auditor on the AIMS structure and their role in it.
  • Assemble a document set an external certification body can review efficiently during a stage one audit.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course