1The AIMS and the PDCA loop
ISO/IEC 42001 defines an AIMS — an AI management system. It is a management standard (like ISO 27001 for security): it does not mandate technical solutions, but an organizational framework that works and improves.
It rests on the PDCA loop: Plan (policy, objectives, risk and impact assessment), Do (implementation, Annex A controls), Check (internal audit, management review, monitoring and measurement of the management system's performance), Act (corrective actions, continual improvement).
2The certification audit
A certification audit takes place in two stages: stage 1 (documentation review, preparation) then stage 2 (on-site audit of actual operation). It bases its findings on objective evidence — documents, records, interviews, observation — never on intuition or reputation. The auditor records nonconformities:
- Major — a requirement is not met (missing mechanism, systemic failure): blocks certification until corrected.
- Minor — an isolated deviation that doesn't bring down the system: an action plan is expected.
3Building and running an AIMS
Frame it, then steer it
You start with the scope and the AI policy. The mechanism rests on top management leadership (commitment, resources, policy) — without it, everything stays theoretical. It then requires: objectives, a risk and impact assessment, defined roles and responsibilities, and controls (Annex A) selected via the Statement of Applicability (where exclusions are justified).
Two audits, two nonconformities
The internal audit is a self-check (a requirement of the system); the certification audit is carried out by an independent third party. It records nonconformities: major (requirement not met, blocking) or minor (isolated deviation → corrective action plan).