0% found this document useful (0 votes)
54 views27 pages

AIMS Checklist

ISO/IEC 42001:2023 is the first international standard for establishing and managing an Artificial Intelligence Management System (AIMS), ensuring AI systems are trustworthy, transparent, and compliant with legal and ethical standards. The standard outlines a structured governance framework applicable to any organization involved with AI, emphasizing risk management, accountability, and stakeholder trust. It includes a detailed implementation process, covering planning, internal audits, management reviews, and continual improvement to enhance AI governance throughout its lifecycle.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
54 views27 pages

AIMS Checklist

ISO/IEC 42001:2023 is the first international standard for establishing and managing an Artificial Intelligence Management System (AIMS), ensuring AI systems are trustworthy, transparent, and compliant with legal and ethical standards. The standard outlines a structured governance framework applicable to any organization involved with AI, emphasizing risk management, accountability, and stakeholder trust. It includes a detailed implementation process, covering planning, internal audits, management reviews, and continual improvement to enhance AI governance throughout its lifecycle.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ISO/IEC 42001:2023

AIMS CLAUSE-WiSE IMPLEMENTATiON

Checklist
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the world’s first international standard for
establishing, implementing, maintaining, and continually improving an
Artificial Intelligence Management System (AIMS). It provides a structured
governance framework that enables organizations to responsibly design,
develop, deploy, operate, monitor, and decommission AI systems across
their lifecycle. An AIMS integrates people, processes, and technology to
ensure AI systems remain:

- Trustworthy
- Transparent
- Fair
- Secure
- Compliant with legal, regulatory, and ethical obligations

This standard is applicable to any organization that develops, provides, or


uses AI-enabled products or services, regardless of size, sector, or
geographic presence.

Why an ISO/IEC 42001 AI Management System?


Implementing ISO/IEC 42001 demonstrates that an organization:

- Applies risk-based governance to AI systems


- Identifies and mitigates societal, legal, ethical, and operational risks
- Maintains accountability and transparency
- Aligns AI operations with regulatory frameworks such as:

>EU AI Act
>Data Protection and Privacy Laws (GDPR, DPDP Act)
>Industry AI governance requirements
>Builds stakeholder trust and enhances brand credibility

It provides assurance to clients, regulators, partners, and governing bodies


that AI systems are managed responsibly throughout their full lifecycle.

[Link] | 01
Format / Process for Achieving ISO/IEC 42001
Certification
1. Planning and Scope Definition

Define the boundaries of the AI Management System, AI roles, and


applicable AI systems.

2. AIMS Implementation

Establish AI policies, governance structure, risk assessment, AI impact


assessment, lifecycle controls, documentation, and awareness programs.

3. Internal Audit

Verify AIMS conformity with ISO/IEC 42001 and organizational


requirements.

4. Management Review

Top management evaluates AIMS performance, risks, and improvement


opportunities.

5. Certification Audit (Stage 1 & Stage 2)

External certification body validates documentation and operational


effectiveness.

6. Continual Improvement

Ongoing risk reassessment, governance enhancement, and AI system


optimization.

[Link] | 02
Clause-Wise Checklist for AI Management System
(AIMS) Implementation
Clause 1: Scope

ISO/IEC 42001 specifies the requirements for establishing and maintaining


an AI Management System within the context of an organization.

This clause defines:

- Applicability to organizations that develop, provide, or use AI systems

> Coverage of AI lifecycle stages:


> Design
> Development
> Deployment
> Operation
> Monitoring
> Modification
> Decommissioning

- Alignment with organizational objectives, legal obligations, and


interested party expectations

The standard applies regardless of organizational size, sector, or AI


maturity level.

[Link] | 03
Clause 2: Normative References

ISO/IEC 42001 relies on:

- ISO/IEC 22989:2022 — Artificial Intelligence Concepts and


Terminology
This reference ensures:

> Consistent interpretation of AI-related terms


> Alignment between governance, technical, legal, and operational teams
> Audit-ready documentation using internationally accepted definitions

Clause 3: Terms and Definitions

This clause establishes a common language for AI governance, including


key concepts such as:

> AI Management System


> Interested Parties
> AI Risk
> AI System Impact Assessment
> Governing Body
> Data Quality
> Statement of Applicability

Auditors validate not just documentation, but also organizational


understanding and correct usage of these terms across policies,
procedures, and operational practices.

[Link] | 04
Clause 4: Context of the Organization

4.1: Understanding the Organization and its Context


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Has the organization formally


identified internal issues that impact Initial /
Low /
Identify internal AI governance AI governance (e.g., AI maturity, Defined /
Yes/No Medium /
factors internal policies, technical Managed /
High
capability, organizational Optimized
culture, risk appetite)?

Have external issues been


documented (e.g., AI regulations,
Identify external AI environment privacy laws, sectoral compliance,
ethical guidelines, market trends,
geopolitical or societal risks)?

Has the organization identified its


role(s) in the AI lifecycle (developer,
Determine AI lifecycle role
deployer, operator, provider, user,
integrator, partner)?

Is the intended purpose and scope


Define AI system purpose of use for each AI system formally
documented and approved?

Has the organization assessed


Identify climate and societal whether climate, sustainability, or
relevance societal impact is relevant to AI
system use?

Are AI systems mapped to


applicable legal and regulatory
Regulatory alignment requirements by jurisdiction (e.g.,
EU AI Act, DPDP Act, GDPR, sector
regulators)?

Is there a documented process to


review and update AI context after
Context review mechanism
major business, regulatory, or
system changes?

[Link] | 05
4.2: Understanding the Needs and Expectations of Interested Parties
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Have all relevant interested parties


Initial /
been identified (e.g., regulators, AI Low /
Defined /
Identify interested parties users, customers, employees, Yes/No Medium /
Managed /
suppliers, data subjects, governing High
Optimized
body, auditors)?

Are AI-related legal, ethical,


contractual, and operational
Capture AI-related requirements
requirements documented for each
stakeholder group?

Have data subjects’ rights,


transparency requirements, and
Data subject expectations
consent obligations been mapped to
AI system usage?

Are formal communication channels


established with regulators and
Regulatory communication
authorities for AI disclosures and
incident reporting?

Are stakeholder requirements


reflected in AI policy, risk
Stakeholder integration
assessments, system design, and
operational controls?

Is there a defined process to


periodically review changes in
Review of expectations
stakeholder needs and legal
obligations?

[Link] | 06
4.3: Determining the Scope of the AI Management System
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Is the scope of the AI Management Initial /


Low /
System clearly defined (AI systems, Defined /
Define AIMS boundaries Yes/No Medium /
locations, business units, lifecycle Managed /
High
stages, data flows)? Optimized

Is the scope derived from


Context-based scoping internal/external context (4.1)
and stakeholder needs (4.2)?

Are exclusions formally


Exclusion justification documented, risk-assessed, and
approved by top management?

Has top management formally


Management approval
approved the AIMS scope?

Is the scope communicated


internally and externally where
Scope communication
required (partners, auditors,
regulators)?

4.4: AI Management System (AIMS)


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Has the organization formally Low /
Defined /
Establish AIMS framework established an AI Management Yes/No Medium /
Managed /
System aligned to ISO/IEC 42001? High
Optimized

Are AI governance processes


integrated with enterprise risk
Process integration
management, privacy, security,
and quality systems?

Are AI lifecycle processes defined


Lifecycle governance (design, development, deployment,
operation, monitoring, retirement)?

Are roles, responsibilities, and


Accountability structure escalation paths clearly defined
for AI risks and incidents?

Is there a documented mechanism


Continuous improvement to feed audit results, impact
linkage assessments, and risk reviews into
AIMS improvement?

[Link] | 07
Clause 5: Leadership

5.1: Leadership and Commitment


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Does top management demonstrate


Initial /
active leadership and accountability Low /
Establish leadership Defined /
for the AIMS (e.g., governance Yes/No Medium /
accountability Managed /
sponsorship, approval of AI risk High
Optimized
posture, review of AI performance)?

Are AIMS objectives aligned with


the organization’s strategic
Strategic alignment
direction, business model, and
innovation roadmap?

Are AIMS requirements integrated


into enterprise processes
Process integration (procurement, SDLC, vendor
management, privacy, security, risk,
HR)?

Has management ensured adequate


allocation of human, technical, and
Resource commitment financial resources for AI
governance, risk management, and
impact assessments?

Is the importance of responsible AI


use, compliance, and risk
Governance communication
management communicated across
all organizational levels?

Does top management regularly


review AIMS performance, risk
Performance oversight
exposure, audit outcomes, and
improvement initiatives?

Has leadership promoted an


organizational culture that supports
Culture of responsibility
ethical, transparent, and
accountable AI use?

[Link] | 08
5.2: AI Policy
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Is a formally documented, Low /
Defined /
Establish AI policy approved, and version-controlled Yes/No Medium /
Managed /
AI Policy in place? High
Optimized

Is the AI Policy appropriate to the


Policy relevance organization’s purpose, risk
appetite, and AI maturity level?

Does the policy explicitly commit to


compliance with applicable laws,
Regulatory commitment regulations, and contractual
obligations (e.g., EU AI Act, DPDP,
GDPR, sectoral laws)?

Does the policy include a


Continuous improvement commitment to continual
improvement of the AIMS?

Is the AI Policy communicated


internally and made available to
Policy communication
relevant interested parties (e.g.,
partners, customers, regulators)?

Is the AI Policy aligned with related


organizational policies (privacy,
Policy alignment
security, ethics, quality, and
supplier governance)?

Is the AI Policy reviewed at


planned intervals or after major
Policy review
regulatory, business, or technology
changes?

[Link] | 09
5.3: Roles, Responsibilities, and Authorities
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Are AI governance roles clearly


Initial /
defined (e.g., AI System Owner, AI Low /
Defined /
Define AI governance roles Risk Owner, AI Impact Assessor, Yes/No Medium /
Managed /
Compliance Officer, Data Protection High
Optimized
Officer)?

Are responsibilities allocated


across the AI lifecycle (design,
Responsibility allocation development, deployment,
operation, monitoring,
decommissioning)?

Has top management delegated


authority to responsible roles to
Authority delegation
manage AI risks, approve controls,
and escalate incidents?

Is there a formal mechanism for


Performance reporting reporting AIMS performance and AI
risk posture to top management?

Do personnel understand their AI


governance responsibilities (e.g.,
Awareness of roles
onboarding, training,
acknowledgments)?

Are there documented


consequences or remediation
Accountability enforcement processes for failure to comply
with AI governance
responsibilities?

[Link] | 10
Clause 6: Planning

6.1: Actions to Address Risks and Opportunities

6.1.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Has the organization defined and


documented AI risk criteria, Initial /
Low /
acceptance thresholds, and Defined /
Establish AI risk framework Yes/No Medium /
opportunity criteria aligned with Managed /
High
business strategy and legal Optimized
obligations?

Are risks and opportunities derived


from organizational context (Clause
Context integration
4) and stakeholder requirements
(Clause 4.2)?

Are risks and opportunities


identified across the entire AI
Lifecycle coverage lifecycle (design, development,
deployment, operation, monitoring,
retirement)?

Are actions to address risks and


Action planning opportunities documented,
assigned, and tracked?

Is the effectiveness of actions


Effectiveness evaluation reviewed and used as input for
continual improvement?

[Link] | 11
6.1.2: AI Risk Assessment
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Is a formal, documented AI risk


Initial /
assessment methodology Low /
Defined /
Methodology definition established (scope, criteria, scoring, Yes/No Medium /
Managed /
impact dimensions, review High
Optimized
frequency)?

Are AI risks systematically


identified (bias, explainability,
Risk identification privacy, security, safety,
regulatory, operational,
reputational, societal)?

Are risks evaluated for


Impact evaluation organizational, individual, and
societal impact?

Are risk evaluations consistent and


Consistency & traceability traceable to AI systems, controls,
and business objectives?

Are risk assessments repeated


after major changes, incidents,
Trigger-based reassessment
regulatory updates, or new AI
deployments?

Is documented evidence of all AI


Documentation retention risk assessments maintained and
protected?

[Link] | 12
6.1.3: AI Risk Treatment
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Are AI risk treatment options Low /
Defined /
Treatment strategy defined (mitigate, avoid, transfer, Yes/No Medium /
Managed /
accept)? High
Optimized

Are controls selected and justified


Control selection (including Annex A mapping or
equivalent frameworks)?

Is a Statement of Applicability
Statement of Applicability (SoA) developed and maintained
for AI controls?

Is residual AI risk formally


Residual risk approval approved by top management
or risk owners?

Are risk treatments implemented,


Implementation tracking tracked, and validated for
effectiveness?

6.1.4: AI System Impact Assessment


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Is a formal AI System Impact Low /
Impact assessment Defined /
Assessment (AIIA/AI-IA) Yes/No Medium /
framework Managed /
framework established? High
Optimized

Are impacts on individual rights,


Individual impact fairness, transparency, and privacy
assessed?

Are broader societal, ethical, and


Societal impact environmental impacts
evaluated?

Are impact assessment results


Risk integration integrated into AI risk
assessment and treatment?

Are impact assessments reviewed


Review cycle periodically and after system
changes?

[Link] | 13
6.2: AI Objectives and Planning to Achieve Them
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Are measurable AI governance Low /
Defined /
Objective definition objectives established at relevant Yes/No Medium /
Managed /
levels? High
Optimized

Are objectives aligned with AI


Alignment Policy, legal obligations, and risk
posture?

Is there a documented plan


detailing responsibilities,
Action planning timelines, resources, and
success criteria?

Are AI objectives monitored,


Monitoring
measured, and reviewed?

6.3: Planning of Changes


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Are changes to AIMS and AI systems Low /
Defined /
Change governance planned, risk-assessed, approved, Yes/No Medium /
Managed /
and documented? High
Optimized

Are changes assessed for AI risk,


Impact analysis compliance impact, and
stakeholder impact?

Are changes implemented in a


Continuity control manner that maintains AIMS
integrity and continuity?

[Link] | 14
Clause 7: Support

7.1: Resources
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Has the organization identified and


documented human, technical, Initial /
Low /
financial, and infrastructure Defined /
Resource planning Yes/No Medium /
resources required to establish, Managed /
High
implement, maintain, and improve Optimized
the AIMS?

Are sufficient resources allocated


for AI lifecycle activities (design,
AI system resourcing
development, testing, deployment,
monitoring, decommissioning)?

Are resources assigned for AI risk


Risk & impact support assessment, impact assessment,
and compliance monitoring?

Are appropriate tools and platforms


in place for AI governance (risk
Tooling & infrastructure
tracking, audit logs, monitoring,
documentation control)?

Are AIMS resources reviewed


Resource review periodically and adjusted based on
risk, scale, or regulatory change?

7.2: Competence
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Has the organization defined


Initial /
competency requirements for Low /
Defined /
Competency framework AIMS-related roles (AI developers, Yes/No Medium /
Managed /
AI risk owners, auditors, compliance High
Optimized
staff, impact assessors)?

Are personnel assessed


against required AI
Skills assessment
governance, legal, ethical, and
technical competencies?

Is there a formal training and


awareness program for AI
Training program
governance, risk, compliance,
and ethical AI use?

Is training effectiveness measured


Effectiveness evaluation and documented (tests,
evaluations, certifications)?

Is documented evidence of
Competence evidence competence maintained and
controlled?

[Link] | 15
7.3: Awareness
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Low /
Are personnel aware of the AI Defined /
Policy awareness Yes/No Medium /
Policy and AIMS objectives? Managed /
High
Optimized

Do employees understand their


Role contribution role in responsible AI use and
governance?

Are personnel aware of the


consequences of nonconformity
Nonconformity impact with AI governance
requirements?

Are ethical AI principles and


trustworthiness concepts
Ethics & trust culture
embedded into organizational
culture?

7.4: Communication
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Is there a documented AIMS Initial /


Low /
communication strategy covering Defined /
Communication plan Yes/No Medium /
internal and external Managed /
High
communication? Optimized

Are communication channels


defined for regulators and
Regulatory communication
authorities regarding AI
disclosures and incidents?

Are mechanisms in place for


Stakeholder reporting users, customers, and partners to
report AI issues or concerns?

Is there a documented plan for


Incident communication communicating AI-related incidents
and impacts?

[Link] | 16
7.5: Documented Information

7.5.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Does the AIMS include all required Initial /


Low /
documented information and Defined /
Documentation framework Yes/No Medium /
organizationally determined Managed /
High
documentation? Optimized

Is there a documented plan for


Accessibility communicating AI-related
incidents and impacts?

7.5.2: Creating and Updating Documented Information


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Are documents properly Low /
Defined /
Document control identified, versioned, reviewed, Yes/No Medium /
Managed /
and approved? High
Optimized

Are standardized formats used for


Format consistency AI risk, impact, and governance
documents?

7.5.3: Control of Documented Information


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Are documents protected from Low /
Defined /
Access control unauthorized access, alteration, Yes/No Medium /
Managed /
or loss? High
Optimized

Are retention schedules and


Retention & disposal secure disposal procedures
defined and followed?

Are externally sourced


documents identified and
External documents controlled (regulations, standards,
vendor documentation)?

Is there traceability of document


Change traceability changes (audit trails, version
history)?

[Link] | 17
Clause 8: Operation

8.1: Operational Planning and Control


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Has the organization planned and


Initial /
documented AI lifecycle processes Low /
Defined /
Process planning (design, development, deployment, Yes/No Medium /
Managed /
operation, monitoring, High
Optimized
decommissioning)?

Are risk treatment controls (Clause


Control implementation 6.1.3) implemented across AI
operational processes?

Are operational criteria and


performance thresholds defined
Process criteria for AI systems (accuracy, fairness,
uptime, explainability,
compliance)?

Is the effectiveness of controls


Monitoring effectiveness and AI performance continuously
monitored?

Are planned and unplanned


Change control changes to AI systems reviewed,
approved, and documented?

Are externally provided AI


services, models, datasets, or
Third-party control
platforms governed and
controlled?

Is documented information
available to demonstrate
Documentation availability
processes are carried out as
planned?

[Link] | 18
8.2: AI Risk Assessment (Operational Execution)
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Low /
Are AI risk assessments Defined /
Periodic risk reviews Yes/No Medium /
conducted at planned intervals? Managed /
High
Optimized

Are risk assessments performed


after system changes, incidents,
Change-triggered assessments
regulatory updates, or new AI
deployments?

Are assessments aligned with


Methodology alignment Clause 6.1.2 methodology and
criteria?

Is documented evidence of all


Evidence retention operational risk assessments
retained and protected?

8.3: AI Risk Treatment (Operational Control)


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Low /
Are risk treatment plans Defined /
Treatment execution Yes/No Medium /
implemented as approved? Managed /
High
Optimized

Are implemented controls


Effectiveness validation
validated for effectiveness?

Are treatment options reviewed


Revalidation when controls fail or new risks
emerge?

Is evidence of risk treatment


Documentation execution maintained?

[Link] | 19
8.4: AI System Impact Assessment (Operational Execution)
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Low /
Are AI system impact assessments Defined /
Scheduled assessments Yes/No Medium /
conducted at planned intervals? Managed /
High
Optimized

Are assessments updated when


system functionality, deployment
Change-based reviews
context, or legal environment
changes?

Are results shared with relevant


Stakeholder transparency interested parties where
appropriate?

Are results fed back into AI risk


assessment and treatment
Risk integration
processes?

Is documented evidence of impact


Evidence management
assessments retained securely?

[Link] | 20
Clause 9: Performance Evaluation

9.1: Monitoring, Measurement, Analysis, and Evaluation


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Has the organization defined what


needs to be monitored and Initial /
Low /
measured to evaluate AIMS Defined /
Performance framework Yes/No Medium /
effectiveness (risk exposure, Managed /
High
control performance, compliance Optimized
status, AI system KPIs)?

Are methods and tools defined to


ensure valid, repeatable, and
Measurement methods
comparable results (dashboards,
audits, testing, surveys)?

Is there a defined monitoring and


Monitoring schedule reporting schedule (frequency,
roles, escalation paths)?

Are monitoring data and reports


Data integrity protected from unauthorized
change or loss?

Are performance results analyzed to


Effectiveness evaluation determine AIMS effectiveness and
achievement of AI objectives?

Are findings used as input for


Improvement linkage continual improvement and risk
treatment updates?

[Link] | 21
9.2: Internal Audit

9.2.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Has the organization established a Low /
Defined /
Audit framework formal AIMS internal audit Yes/No Medium /
Managed /
framework? High
Optimized

Do audits verify conformity with


Standard conformity ISO/IEC 42001 and internal AIMS
requirements?

Are Auditors independent and


Independence impartial from the activities
audited?

Is documented evidence of audit


Documentation
results maintained

9.2.2: Internal Audit Programme


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Is there a risk-based audit Initial /


Low /
programme defining scope, Defined /
Audit planning Yes/No Medium /
frequency, methods, and Managed /
High
responsibilities? Optimized

Does the programme consider risk


Prioritization level, impact, and results of
previous audits?

Are audit criteria and scope


Criteria definition
defined for each audit?

Are audit results reported to top


Reporting management and relevant
owners?

Are corrective actions tracked and


Follow-up
verified for closure?

[Link] | 22
9.3: Management Review

9.3.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Does top management conduct Low /
Defined /
Review governance formal AIMS management reviews Yes/No Medium /
Managed /
at planned intervals? High
Optimized

9.3.2: Management Review Inputs


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Low /
Are previous review actions Defined /
Action status Yes/No Medium /
tracked and reported for closure? Managed /
High
Optimized

Are changes in internal/external


Context changes issues and regulatory landscape
reviewed?

Are changes in stakeholder


expectations reviewed
Stakeholder needs
(regulators, customers, data
subjects, partners)?

Are trends in nonconformities,


Performance trends audits, KPIs, risk levels, and AI
system performance reviewed?

Are continual improvement


Improvement opportunities opportunities identified and
documented?

9.3.3 Management Review Results


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Low /
Are management decisions and Defined /
Decision recording Yes/No Medium /
action items documented? Managed /
High
Optimized

Are changes to AIMS, objectives,


Change approval policies, or controls approved and
communicated?

Are actions from reviews tracked


Follow-up to completion and verified?

[Link] | 23
Clause 10: Improvement

10.1: Continual Improvement


Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Has the organization established a Low /
Defined /
Improvement framework formal continual improvement Yes/No Medium /
Managed /
framework for the AIMS? High
Optimized

Are audit results, KPIs, AI risk


Performance-driven trends, and impact assessments
improvement used as formal inputs for
improvement planning?

Are improvements triggered by


regulatory changes, legal updates,
Regulatory adaptation and evolving AI governance
requirements?

Are AI lifecycle and governance


processes reviewed and optimized
Process optimization
for effectiveness, efficiency, and
trustworthiness?

Are improvement actions tracked,


Improvement tracking
prioritized, and verified for closure?

Are the benefits of improvements


measured (risk reduction,
Benefit measurement
compliance maturity, performance
gains, stakeholder trust)?

[Link] | 24
10.2: Nonconformity and Corrective Action
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action

Initial /
Does the organization identify and Low /
Defined /
Nonconformity identification record AI governance or AIMS Yes/No Medium /
Managed /
nonconformities? High
Optimized

Are actions taken to control and


Immediate response correct nonconformities when
they occur?

Are root causes of nonconformities


Root cause analysis
formally investigated?

Are corrective actions


Recurrence prevention implemented to prevent
recurrence of the issue?

Does the organization assess


Similar issue identification whether similar nonconformities
could occur elsewhere?

Is the effectiveness of
Corrective action effectiveness corrective actions verified after
implementation?

Are records maintained for


Documentation nonconformities, actions taken,
and corrective outcomes?

[Link] | 25

You might also like