Insights

Seven-section structure for an ISO/IEC 42001 AI risk management plan — document control, AI system overview, risk identification across nine AI-specific categories (bias, opacity, malfunction, data quality, security, oversight failure, supply chain, privacy, drift), likelihood-and-impact scoring, risk treatment plan, residual risk review with management approval, and monitoring with re-review triggers

AI Standards & Certification

3 Aug 2026

How to Write an AI Risk Management Plan: A 7-Section Structure That Passes Audit

Seven-step roadmap for building an AI governance framework on ISO/IEC 42001 — diagnose the current state with a gap analysis, design the governance structure, establish the AI policy, run risk and impact assessments, build and document controls, train the organization, then verify with internal audit and management review before the certification audit

AI Standards & Certification

3 Aug 2026

Building an AI Governance Framework: A Seven-Step Roadmap to ISO 42001

Five-level AI governance maturity model — Initial, Aware, Defined, Managed, Optimizing — with a six-dimension self-assessment covering leadership and governance structure, risk management, transparency and explainability, human oversight, competence and culture, and monitoring and improvement, scored 1 to 5 against ISO/IEC 42001 readiness

AI Standards & Certification

2 Aug 2026

The AI Governance Maturity Model: Five Levels, Six Dimensions, and How to Score Yourself

OFI vs nonconformity in ISO/IEC 42001 audits — three finding types (conformity, nonconformity, opportunity for improvement), the four judgment criteria auditors apply (explicit requirement, evidence sufficiency, systemic vs isolated failure, repetition), and the response each demands: mandatory four-step corrective action for nonconformities, review-decide-record for OFIs

AI Standards & Certification

2 Aug 2026

OFI vs Nonconformity: How ISO 42001 Auditors Actually Draw the Line

Four-phase ISO/IEC 42001 internal audit checklist under Clause 9.2 — plan the audit with scope, criteria, and team; prepare documents, questions, and sampling; audit clause by clause across Clauses 4 to 10; process results into nonconformities, OFIs, and conformity; then run the final pre-certification check

AI Standards & Certification

31 Jul 2026

The ISO 42001 Internal Audit Checklist: From First Plan to Certification-Ready

Five-step AI risk assessment methodology for ISO/IEC 42001 — build the AI system inventory, analyze context, identify risks, score likelihood and impact, treat risks — covering AI-intrinsic risk categories such as bias, opacity, malfunction, and supply chain

AI Standards & Certification

28 Jul 2026

AI Risk Assessment: a Five-Step Methodology That Holds Up in an Audit

The 10 mandatory documents an ISO/IEC 42001 certification audit checks — AI policy, scope, risk assessment and SoA, impact assessment, objectives, competence records, internal audit, management review, corrective-action log, AI supplier records

AI Standards & Certification

28 Jul 2026

ISO 42001 Documentation: the 10 Documents Your Certification Audit Will Check

The five nonconformities most likely to appear in an ISO/IEC 42001 certification audit — missing AI-specific risks, uncommunicated AI policy, unmeasurable objectives, unmanaged AI suppliers, and audit results never reaching management review

AI Standards & Certification

16 Jul 2026

The 5 Nonconformities Most Likely to Appear in Your ISO 42001 Audit

Comparison diagram of ISO 42001, the EU AI Act, and NIST AI RMF — ISO/IEC 42001 as the certifiable AI management-system spine, the EU AI Act as binding law with four risk tiers (prohibited, high-risk, limited, minimal), and NIST AI RMF's Govern-Map-Measure-Manage cycle as the voluntary method, all converging on one integrated control set and evidence base.

Regulation & Developments

24 Jun 2026

ISO 42001, the EU AI Act, and NIST AI RMF: How the Three Fit Together