The 12-step playbook: building an AIMS that serves both regimes

Lesson 5 of 5 in The EU AI Act Interface: Harmonized Standards and the 42001 Playbook.

Everything in this domain converges here. The strategic play of 2026–2027 is to build one governance machine that produces 42001 certification evidence and AI Act conformity evidence — because the Omnibus window is exactly wide enough to do it once, properly, and exactly too narrow to do it twice. The playbook below is the field-tested sequence; realistic end-to-end duration is 12–18 months from mandate to Stage 2, with the AI Act mapping woven in rather than bolted on afterwards.

Steps 1–3: Mandate, inventory, scope

1. Secure the mandate and appoint the AIMS lead. Top management commitment is clause 5.1’s first demand and the project’s survival condition — an AIMS run from the compliance team’s spare time fails at Stage 1. Get budget, authority, and a named executive owner.

2. Inventory AI systems and determine roles. Every AI system in use or development, mapped to the organisation’s role per 22989 (provider, developer, user) — and, for EU exposure, to AI Act roles (provider, deployer, importer) and risk tier. This inventory is clause 4 raw material and your Annex III exposure register in one pass.

3. Define the AIMS scope. Which entities, sites, and AI activities. The certifiable-boundary trade-off: scope wide enough to cover your real risk (and your Act-exposed systems), narrow enough to operate honestly. Scoping out the high-risk credit model to make certification easier is a decision an auditor — and a regulator — will eventually read aloud back to you.

Steps 4–6: Gap analysis, policy, methodology

4. Gap analysis against clauses 4–10 and Annex A — extended with an Arts 9–15 column for in-scope high-risk systems, so every gap is tagged ‘42001’, ‘AI Act’, or both. One analysis, two compliance narratives.

5. Establish the AI policy and governance roles (clauses 5.2, 5.3): policy content tied to your context, role assignments with real authority — including who signs risk acceptances and who can stop a deployment.

6. Build the risk and impact assessment methodology. One method, two lenses: organisational risk (23894-style, feeding 6.1.2/8.2) and affected-party impact (42005-style, feeding 6.1.4/8.4) — with Art 9’s named risk objects (health, safety, fundamental rights) built into the criteria so the same assessments serve the Act. Where GDPR applies, coordinate with DPIA; where Art 27 applies, with the FRIA.

Steps 7–9: Treatment, controls, documentation

7. Risk treatment and the SoA. Treat the assessed risks, select controls, and record the Statement of Applicability with justifications that trace to actual risk decisions.

8. Implement lifecycle, data, and supplier controls. The A.6/A.7/A.10 build-out — where engineering happens: documentation templates matching Annex IV structure (so Art 11 is a formatting exercise, not a rewrite), logging designed against Art 12’s capability list, instructions-for-use content against Art 13, oversight design against Art 14.

9. Documentation and training. Close the clause 7 loop: documented information under control, competence gaps filled — data-science literacy for governance staff, governance literacy for engineers, AI-literacy duties (already applicable EU-wide) folded in.

Steps 10–12: Operate, audit, certify

10. Operate and collect evidence. Run the system for real: assessments at planned intervals, monitoring live, incidents handled, suppliers reviewed. Three to six months minimum — this is the step no consultant can compress, because its output is time-stamped operating records.

11. Internal audit and management review. The clause 9 machinery, executed at least once, with findings and closed corrective actions. Your dress rehearsal, and Stage 1’s first question.

12. Select an accredited CB and undergo Stage 1/Stage 2. Apply the buyer’s checklist from the certification module: 42006 accreditation, AI-competent team, defensible audit-day calculation, precise scope statement. Then keep the machine running — surveillance arrives in a year, and the Act’s December 2027 clock does not care that you just celebrated.

The playbook’s failure modes are as well-documented as its steps. Five recur so reliably they deserve names: the shadow-AI scope trap (inventorying every ChatGPT tab in the company into an uncertifiable scope — govern them, but draw the AIMS boundary deliberately); the paper system (twelve months of documents, zero months of operation); the conflation error (one assessment wearing two labels — risk and impact are different lenses, and 42006-trained auditors check); the forgotten supply chain (no A.10 responsibility allocation with the GPAI vendor whose model sits inside your product — and no Art 25-aware contract terms); and the compliance mirage (announcing that certification equals AI Act compliance — the category error you can now dismantle in one sentence).

Interactive sorting exercise: Your program board proposes these moves. Sort each into sound play or classic pitfall.

Key terms: AI management system, Statement of Applicability, fundamental rights impact assessment, data protection impact assessment, AI inventory

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.