AI Assurance Logo
AI Assurance aiassurance.co.za
Get In Touch

ISO/IEC 42001 AIMS

A working AI management system for everyday conformity with ISO/IEC 42001.

ISO/IEC 42001 is the management system for the everyday running of AI in the organisation. It is how issues are worked through against the requirements of the standard: establish, implement, maintain and continually improve an AI management system. It is not a form to complete.

This AIMS is built to operate that standard. It is a working system. Conformity with ISO/IEC 42001 is the result of running it. Templates, checklists and downloads can sit inside the system. They record work. They are not the AIMS.

For a South African organisation this page is the certification-facing suite used when the board wants an assessable AI management system, including where Union-market work sits on the same data. POPIA still governs personal information processed by those systems. The AIMS does not replace a PIIA or an operator contract.

What the standard requires

ISO/IEC 42001 asks the organisation to have an AI management system with defined scope, leadership, planning, support, operation, performance evaluation and improvement. Roles are assigned. Risks and opportunities related to AI are treated. The AI system lifecycle is controlled. Performance is measured. The system is reviewed and improved.

The standard states what must be achieved. It does not hand over the operating model. A pack of completed templates is not that model. An assessor looks at whether the system runs, who owns which duty, and what evidence the processes left.

What this solution is

The ISO/IEC 42001 AIMS is a single environment in which those processes are assigned, run, reviewed and evidenced. It uses the criteria of the standard so the organisation can work toward certification. The same work is a self-assessment. Done properly, that self-assessment is able to meet the standard for a second-party or third-party assessment. It is not a tick-box exercise.

The system is for everyday management: intake, scope, roles, risk, the AI lifecycle, suppliers, performance, nonconformity and improvement. Issues are worked through against the clause, not parked in a register until audit week. This suite is how that system is operated: named processes, evidence, and gates that follow the work.

The process approach

ISO/IEC 42001 uses a process approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an AIMS. Every activity that consumes resources and turns inputs into outputs is a process. The output of one process is the input to the next. When those processes are identified, connected and managed, the organisation has a coherent system rather than a set of isolated tasks.

The standard places particular weight on four priorities:

  • Understanding organisational AI requirements and setting policy and objectives for responsible AI governance.
  • Implementing and operating processes that manage AI-specific data and lifecycle risks inside enterprise business risk.
  • Monitoring and reviewing the performance and effectiveness of the AIMS against objective metrics.
  • Continual improvement grounded in measurable data and evidence.

Those processes are structured around Plan-Do-Check-Act, the same cycle used in other international management-system standards.

From requirements to an operating system

The suite converts the standard's requirements into a production system that can be run and audited. It is not a pack of isolated templates or a generic dashboard. The architecture:

  • Addresses the major clauses and Annex A controls through structured workflows and automated evidence capture.
  • Aggregates evidence for management review and certification-readiness scoring, so leadership and an assessor can see the state of the system.
  • Enforces governance gates and phase-gated progression aligned with PDCA.
  • Keeps traceability from operational records back to individual AI systems.
  • Can support more than one regulatory framework from a single data foundation, including DORA, the CRA and AI-specific mandates where those apply.

The result is not a completed checklist. It is a foundation for operational management of core AI processes, ready for internal management review, external certification and ongoing scrutiny.

Who it is for

Organisations that must show conformity with ISO/IEC 42001, whether they are preparing for certification or running the system after it. Teams that need one working AIMS, not a checklist library. People who have to show an assessor how work was assigned, how it ran, and what it left behind.