Clauses 7 and 8 — support and operation: where paper meets practice

Lesson 4 of 5 in ISO/IEC 42001 Clause by Clause: Building the AI Management System.

Clause 7 — Support supplies the enablers without which every plan is theatre.

7.1 Resources — people, budget, tooling, data infrastructure for the AIMS itself. 7.2 Competence — determine what competence the work requires, ensure people have it (education, training, experience), act on gaps, and retain evidence. For an AIMS this means real AI literacy: the person signing off a risk assessment must understand drift, bias, and the difference between verification and validation — a governance-trained lawyer or an ML-trained engineer alone is usually half the required profile. 7.3 Awareness — everyone working under the AIMS must know the AI policy, their contribution, and what nonconformance means for them. 7.4 Communication — decide deliberately what gets communicated about the AIMS, when, to whom, and how — internally and externally. 7.5 Documented information — create it properly (identification, format, review and approval) and control it (available where needed, protected, versioned, retained, disposed).

The phrase documented information is Harmonized Structure vocabulary for what older standards split into "documents" (plans, policies — maintained) and "records" (evidence — retained). 42001 names specific artifacts you must have. Auditors carry this list; so should you:

Mandatory documented information in ISO/IEC 42001, by clause
ClauseWhat must exist in writing

4.3

The AIMS scope

5.2

The AI policy

6.1.2

The AI risk assessment process and its results

6.1.3

The AI risk treatment process, the Statement of Applicability, and the risk treatment plan

6.1.4

The AI system impact assessment process and its results

6.2

The AI objectives

7.2

Evidence of competence (training records, qualifications)

8.1

Whatever is needed for confidence that operational processes ran as planned

8.2 / 8.3 / 8.4

Results of operational risk assessments, risk treatment, and impact assessments

9.1

Evidence of monitoring and measurement results

9.2

The audit programme and audit results

9.3

Management review results

10.2

The nature of nonconformities, actions taken, and corrective action results

Clause 8 — Operation is deliberately short, and its brevity fools people. It says: everything you planned in clause 6 now runs — under controlled conditions, on a schedule, with evidence.

8.1 Plan, implement, and control the processes needed to meet requirements; establish criteria and control processes against them; control planned changes and review the consequences of unintended changes; and — critical in an ecosystem where most organisations buy more AI than they build — ensure externally provided processes, products, and services relevant to the AIMS are controlled. Your model-API vendor, your data-labeling contractor, and your cloud AutoML platform all live inside this sentence.

8.2 / 8.3 / 8.4 then convert clause 6’s designs into recurring operations: perform the AI risk assessment at planned intervals or when significant changes occur, implement the risk treatment plan and verify it worked, and run impact assessments on the same triggered basis. "Significant change" is your tripwire vocabulary: a model retrained on new data, a system repurposed to a new user population, a vendor swapping the underlying foundation model — each should fire a reassessment, and the audit trail should show it fired.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.