Académie / ISO/IEC 42001 — Management & audit

ISO 42001 Annex · Audit · Cours

ISO/IEC 42001: management system & audit

The world of AI management and certification audits — the auditor's stance, which the core track doesn't cover.

3 sections

1The AIMS and the PDCA loop

ISO/IEC 42001 defines an AIMS — an AI management system. It is a management standard (like ISO 27001 for security): it does not mandate technical solutions, but an organizational framework that works and improves.

It rests on the PDCA loop: Plan (policy, objectives, risk and impact assessment), Do (implementation, Annex A controls), Check (internal audit, management review, monitoring and measurement of the management system's performance), Act (corrective actions, continual improvement).

Statement of Applicability. The organization selects, among the Annex A controls, those that apply, and justifies any exclusions — a key deliverable that an auditor examines, checking that the exclusions are consistent with the scope and the actual risks.

2The certification audit

A certification audit takes place in two stages: stage 1 (documentation review, preparation) then stage 2 (on-site audit of actual operation). It bases its findings on objective evidence — documents, records, interviews, observation — never on intuition or reputation. The auditor records nonconformities:

  • Major — a requirement is not met (missing mechanism, systemic failure): blocks certification until corrected.
  • Minor — an isolated deviation that doesn't bring down the system: an action plan is expected.
The stance. The auditor observes and ties findings back to the requirement; they do not design the solution (otherwise they'd be auditing their own work). Independence and evidence are the two pillars.

3Building and running an AIMS

Frame it, then steer it

You start with the scope and the AI policy. The mechanism rests on top management leadership (commitment, resources, policy) — without it, everything stays theoretical. It then requires: objectives, a risk and impact assessment, defined roles and responsibilities, and controls (Annex A) selected via the Statement of Applicability (where exclusions are justified).

Two audits, two nonconformities

The internal audit is a self-check (a requirement of the system); the certification audit is carried out by an independent third party. It records nonconformities: major (requirement not met, blocking) or minor (isolated deviation → corrective action plan).

A living system. Continual improvement (the "Act" of PDCA) is crucial for AI: data, models, uses and risks evolve; a frozen mechanism goes stale. You monitor, reassess risks, and correct — much like an Article 10 file gets re-certified when the context changes.