ISO Standards
ISO/IEC 42001 and the standards stack, from terminology to certification
- The AI Standards Landscape and Core Terminology (ISO/IEC 22989) — Who writes AI standards and why they matter, how to read IS/TS/TR labels and shall/should language, the Harmonized Structure behind every management system standard, and the ISO/IEC 22989 vocabulary the whole ecosystem is built on. (5 lessons, 50 min)
- ISO/IEC 42001 Clause by Clause: Building the AI Management System — The world’s first certifiable AI management system standard, taken apart clause by clause: context and role determination, leadership and the AI policy, risk and impact assessment planning, support and operation, performance evaluation, and improvement — mapped onto the PDCA cycle. (5 lessons, 55 min)
- Annex A Controls and Annexes B, C, D: The Control Framework — The 38 controls in nine groupings that give ISO/IEC 42001 its teeth: what each control grouping demands, how Annex B guidance turns requirements into practice, how Annex C objectives and risk sources seed your risk assessment, and how to build a defensible Statement of Applicability. (4 lessons, 55 min)
- AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005 — How ISO 31000’s risk architecture becomes AI-specific through ISO/IEC 23894, how ISO/IEC 42005:2025 turns impact assessment into a repeatable method, and how the two disciplines — organisational-risk lens and affected-party lens — interlock inside the AIMS and alongside DPIAs and FRIAs. (5 lessons, 60 min)
- Trustworthiness, Bias, and AI Quality: The TR Series and 25059 — The informative layer of the SC 42 ecosystem: ISO/IEC TR 24028’s trustworthiness attributes and threat catalogue, TR 24027’s bias taxonomy, TR 24368’s ethics themes, and the ISO/IEC 25059 quality model — and how non-certifiable guidance becomes concrete AIMS objectives, controls, and metrics. (5 lessons, 55 min)
- Board-Level AI Governance: ISO/IEC 38507 and Organizational Accountability — What governing bodies — not engineers — must do about AI: the ISO/IEC 38500 Evaluate–Direct–Monitor model, how ISO/IEC 38507 adapts it for AI, risk appetite and policy cascades, three lines of defense, board reporting, and the accountability that no board can delegate to a vendor or an algorithm. (4 lessons, 50 min)
- Certification, Audit, and Integrated Management Systems: ISO/IEC 42006 — How a 42001 certificate actually gets made: the accreditation chain from IAF to your auditor, what ISO/IEC 42006:2025 demands of certification bodies, the Stage 1/Stage 2 journey and the three-year cycle, how findings are classified and closed, and how to run one integrated management system across 42001, 27001, 27701, and 9001. (5 lessons, 60 min)
- The EU AI Act Interface: Harmonized Standards and the 42001 Playbook — Where voluntary standards meet binding law: how the New Legislative Framework turns harmonised standards into a presumption of conformity, what CEN-CLC/JTC 21 is actually delivering (and how late), what the 2026 AI Omnibus did to the high-risk clock, how 42001 maps — and fails to map — onto Articles 9–15 and 17, and a 12-step playbook for building an AIMS that is ready for both regimes. (5 lessons, 60 min)
- Lead Implementer Track: Building an AIMS from Mandate to Certificate — The practitioner playbook for taking an organisation from “we should govern AI” to an accredited ISO/IEC 42001 certificate: winning the mandate, scoping and gap analysis, planning artifacts that survive audit, operating the system without drowning in paper, internal audit and management review as steering instruments, and running the certification project itself. (5 lessons, 55 min)
- Lead Auditor Track: Auditing an AIMS with ISO 19011 Discipline — The other side of the audit table: what a Lead Auditor credential actually attests, the ISO 19011 principles that make findings defensible, how to plan and staff an AI audit, interview and sample like a professional, write nonconformities that survive challenge, and evaluate corrective action without crossing the consultancy line. (5 lessons, 55 min)