AI Standards & Certification

Seven-section structure for an ISO/IEC 42001 AI risk management plan — document control, AI system overview, risk identification across nine AI-specific categories (bias, opacity, malfunction, data quality, security, oversight failure, supply chain, privacy, drift), likelihood-and-impact scoring, risk treatment plan, residual risk review with management approval, and monitoring with re-review triggers

How to Write an AI Risk Management Plan: A 7-Section Structure That Passes Audit

The seven sections every AI risk management plan needs — with a worked example and the five mistakes auditors flag most Among the documents ISO/IEC 42001 requires, one causes more hesitation than most: “How are we supposed to write the AI risk management plan? Is there a required format?” There isn’t — the standard specifies

How to Write an AI Risk Management Plan: A 7-Section Structure That Passes Audit Read More »

Seven-step roadmap for building an AI governance framework on ISO/IEC 42001 — diagnose the current state with a gap analysis, design the governance structure, establish the AI policy, run risk and impact assessments, build and document controls, train the organization, then verify with internal audit and management review before the certification audit

Building an AI Governance Framework: A Seven-Step Roadmap to ISO 42001

A seven-step roadmap from first diagnosis to certification-ready — with the deliverables each step should produce Every organization that has adopted AI hits the same moment sooner or later: “We’re already using AI — where does governance even start?” AI governance is not a project you complete in one push. It is built in stages,

Building an AI Governance Framework: A Seven-Step Roadmap to ISO 42001 Read More »

Five-level AI governance maturity model — Initial, Aware, Defined, Managed, Optimizing — with a six-dimension self-assessment covering leadership and governance structure, risk management, transparency and explainability, human oversight, competence and culture, and monitoring and improvement, scored 1 to 5 against ISO/IEC 42001 readiness

The AI Governance Maturity Model: Five Levels, Six Dimensions, and How to Score Yourself

Five maturity levels, six dimensions to score, and the imbalance patterns that predict audit findings Organizations setting out to build AI governance run into the same question before any other: “Where are we now, and what should we do first?” Without knowing the starting point, there is no way to design the route. An AI

The AI Governance Maturity Model: Five Levels, Six Dimensions, and How to Score Yourself Read More »

OFI vs nonconformity in ISO/IEC 42001 audits — three finding types (conformity, nonconformity, opportunity for improvement), the four judgment criteria auditors apply (explicit requirement, evidence sufficiency, systemic vs isolated failure, repetition), and the response each demands: mandatory four-step corrective action for nonconformities, review-decide-record for OFIs

OFI vs Nonconformity: How ISO 42001 Auditors Actually Draw the Line

The judgment criteria auditors actually apply — and the right way to respond to each type of finding Almost every organization that has been through an ISO certification audit asks some version of the same question afterwards: “The auditor kept distinguishing between ‘nonconformities’ and ‘OFIs’ — what exactly is the difference? And can we just

OFI vs Nonconformity: How ISO 42001 Auditors Actually Draw the Line Read More »

Four-phase ISO/IEC 42001 internal audit checklist under Clause 9.2 — plan the audit with scope, criteria, and team; prepare documents, questions, and sampling; audit clause by clause across Clauses 4 to 10; process results into nonconformities, OFIs, and conformity; then run the final pre-certification check

The ISO 42001 Internal Audit Checklist: From First Plan to Certification-Ready

A phase-by-phase checklist for Clause 9.2 — from audit planning to the final pre-certification check There is a moment every organization preparing for ISO/IEC 42001 certification gets nervous about: “We have to run an internal audit — where do we even start?” The internal audit is how an organization tests its own AI management system

The ISO 42001 Internal Audit Checklist: From First Plan to Certification-Ready Read More »

Five-step AI risk assessment methodology for ISO/IEC 42001 — build the AI system inventory, analyze context, identify risks, score likelihood and impact, treat risks — covering AI-intrinsic risk categories such as bias, opacity, malfunction, and supply chain

AI Risk Assessment: a Five-Step Methodology That Holds Up in an Audit

A five-step methodology you can apply as-is — built for ISO/IEC 42001, aligned with the EU AI Act Every organization that adopts AI eventually has to answer one question: “What risks can our AI systems actually create?” AI risk assessment is a core requirement of ISO/IEC 42001 and the starting point of EU AI Act

AI Risk Assessment: a Five-Step Methodology That Holds Up in an Audit Read More »

The 10 mandatory documents an ISO/IEC 42001 certification audit checks — AI policy, scope, risk assessment and SoA, impact assessment, objectives, competence records, internal audit, management review, corrective-action log, AI supplier records

ISO 42001 Documentation: the 10 Documents Your Certification Audit Will Check

The documented information certification auditors ask for — what each document must contain, and the order to build them in The first wall most organizations hit when preparing for ISO/IEC 42001 certification is a simple question: “What documents do we actually have to produce?” The standard requires extensive documented information, but reading the clause text

ISO 42001 Documentation: the 10 Documents Your Certification Audit Will Check Read More »

Diagram showing how to extend a certified ISO/IEC 27001 ISMS into an ISO/IEC 42001 AIMS, sorting Annex A controls into three groups: reuse and supplement from the ISMS (management-system structure Clauses 4-10, existing policies and roles A.2/A.3), extend to the AI context (AI asset classification A.4, AI system lifecycle A.6, AI supply chain A.10), and build new for AI (AI impact assessment A.5, AI data management A.7, information for stakeholders A.8, use of the system A.9), with audit points marking each transition.

Extending an ISO/IEC 27001 ISMS to ISO/IEC 42001

If you already run an ISO/IEC 27001 ISMS, here is the control-by-control path to an AI management system If your organization already runs an ISO/IEC 27001 ISMS, preparing for ISO/IEC 42001 is not a start-from-scratch exercise. Because both standards share the same Harmonized Structure, their controls fall cleanly into three groups: the ones you reuse

Extending an ISO/IEC 27001 ISMS to ISO/IEC 42001 Read More »

Comparison of ISO 42001 and ISO 27001 in four parts: what they share — common Clauses 4-10 under the ISO harmonized structure (Annex SL), shown as a Plan-Do-Check-Act flow between the two standards; where they differ — ISO 27001 as an ISMS aimed at the CIA triad against external threats, ISO 42001 as an AIMS aimed at responsible AI against bias, opacity, malfunction, and human-oversight risks; what ISO 42001 adds — AI policy, AI impact assessment, AI supply chain, and human oversight; and how to run them together as one integrated management system through shared documentation, extended risk assessment, and combined audits.

ISO 42001 vs ISO 27001: the differences, and how to run them together

Two different standards, two different purposes — and they are designed to run together As organizations adopt AI faster, one question comes up again and again: “We’re already certified to ISO 27001 — do we also need ISO 42001?” The short answer: they are two different standards with two different purposes, and they are designed

ISO 42001 vs ISO 27001: the differences, and how to run them together Read More »