What an AIMS is — and is not
Lesson 1 of 5 in ISO/IEC 42001 Clause by Clause: Building the AI Management System.
On 18 December 2023, ISO and IEC published ISO/IEC 42001 — and for the first time, an organisation could be certified for how it governs AI. Not for having a good model. Not for passing a bias test. For running a conforming AI management system: a standing, auditable machine of policies, roles, risk processes, and evidence that makes responsible AI an organisational habit rather than a heroic one-off.
Three scoping facts define the standard before you read a single clause:
- Anyone can adopt it. The scope covers any organisation — any size, any sector — that provides, develops, or uses AI systems. A ten-person startup fine-tuning open models and a global bank buying vendor tools are both in scope.
- It certifies the system, not the products. A 42001 certificate attests that the management machinery conforms. Your models can still fail — the certificate’s promise is that failures will be detected, corrected, and learned from systematically.
- It stands on ISO/IEC 22989. The terminology standard is 42001’s normative reference: every defined term — AI system, provider, lifecycle stage — means what 22989 says it means. That is why the previous module came first.
The engine under every MSS: Plan–Do–Check–Act. The PDCA cycle — plan what you will do, do it, check whether it worked, act on what you learned — is the operating rhythm the Harmonized Structure encodes. Clauses 4–10 are PDCA written out as requirements. Hold this map in your head and the standard stops being a list and becomes a loop:
Clauses 4–10 on the PDCA cycle
- Clause 4 — Context
Understand the organisation, its AI roles, interested parties; fix the AIMS scope. Everything downstream inherits from here.
- PLAN — Clauses 5 & 6
Leadership sets the AI policy and assigns roles (5); planning runs risk assessment, risk treatment with the SoA, impact assessment, and sets AI objectives (6).
- Support — Clause 7
The enablers: resources, competence, awareness, communication, documented information. Bridges planning into operation.
- DO — Clause 8
Operate the plan: execute controls, re-run risk and impact assessments at intervals and on significant change, control suppliers.
- CHECK — Clause 9
Monitor and measure, run internal audits, hold management reviews. This is where the system observes itself.
- ACT — Clause 10
Continual improvement plus the nonconformity-and-corrective-action loop. Findings feed the next planning turn.
- Next cycle
Management review outputs and corrective actions update context, policy, risks, and objectives — the loop never terminates.
Here is the whole operative standard as an advance organiser — each clause with what it demands and the evidence an auditor will ask to see. The rest of this module walks these seven doors one by one.
Clause 4 — Context of the organization
Demands: Determine external and internal issues relevant to the AIMS — explicitly including whether climate change is a relevant issue, and crucially the organisation’s role(s) with respect to AI (provider, producer/developer, user — often several). Identify interested parties and their requirements. Define the AIMS scope in writing.
Evidence auditors expect: a context analysis, a documented role determination, an interested-party register, and a scope statement precise enough to know which AI systems are in and which are out.
Clause 5 — Leadership
Demands: Top management demonstrably leads — integrating AIMS requirements into business processes and resourcing them. It establishes an AI policy appropriate to the organisation’s purpose, providing a framework for AI objectives and committing to applicable requirements and continual improvement. Roles, responsibilities, and authorities are assigned and communicated.
Evidence auditors expect: the signed AI policy, communication records, an org chart or RACI naming who owns the AIMS and who reports on its performance.
Clause 6 — Planning
Demands: The intellectual core. Address risks and opportunities; run an AI risk assessment against defined criteria; run AI risk treatment, comparing chosen controls against Annex A and producing a Statement of Applicability; run an AI system impact assessment (6.1.4) examining consequences for individuals, groups, and societies; set measurable AI objectives; plan changes deliberately.
Evidence auditors expect: risk criteria, the risk register, the SoA with justified inclusions and exclusions, impact assessment reports, an objectives sheet with metrics and owners.
Clause 7 — Support
Demands: Provide resources; ensure competence (and keep evidence of it); create awareness of the AI policy and of what nonconformance means for each person; decide internal and external communication (what, when, with whom, how); create, update, and control documented information.
Evidence auditors expect: training records and competence matrices, awareness materials, a communication plan, and a functioning document-control regime (versioning, approval, availability, protection).
Clause 8 — Operation
Demands: Plan, implement, and control the processes that meet requirements — including controlling planned changes, reviewing unintended ones, and governing externally provided processes, products, and services (your AI suppliers). Re-run the AI risk assessment at planned intervals or upon significant changes; implement the risk treatment plan; perform impact assessments likewise.
Evidence auditors expect: operational procedures in use, dated risk and impact reassessments triggered by real changes, supplier due-diligence and contract records.
Clause 9 — Performance evaluation
Demands: Decide what to monitor and measure, with which methods, when, and by whom — then do it and evaluate results. Run an internal audit programme (objective, impartial auditors; defined criteria and scope per audit). Hold management review at planned intervals with specified inputs (audit results, nonconformities, monitoring results, changes in context…) and outputs (improvement decisions, change needs).
Evidence auditors expect: a metrics dashboard or reports, the audit programme with completed audit reports, management review minutes showing decisions — not just attendance.
Clause 10 — Improvement
Demands: Continually improve the AIMS. When a nonconformity occurs: react and correct; deal with consequences; evaluate the need to eliminate the root cause (and check for similar nonconformities elsewhere); implement corrective action; review its effectiveness; update the AIMS if needed.
Evidence auditors expect: a nonconformity and corrective-action log where entries actually close the loop — root cause identified, action taken, effectiveness verified — not a list of patched symptoms.
Key terms: AI management system, Plan-Do-Check-Act, Statement of Applicability, documented information, top management
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.