Making it operate

Lesson 3 of 5 in Lead Implementer Track: Building an AIMS from Mandate to Certificate.

Clauses 7 and 8 are where implementations either become habits or become shelves. The implementer’s first structural decision is the documented information architecture — and the mistake to avoid is not under-documenting. It is over-documenting.

Think in four tiers: the policy says why and commits; procedures say who does what, when; templates and work instructions say how; records prove it happened. The design principle: write the minimum that lets a competent person do the right thing and leaves evidence behind. The aims-42001 module lists what the standard makes mandatory — beyond that list, every sentence is a choice. And here is the trap in that choice: every ‘shall’ you write about yourself becomes an audit criterion you can fail. A procedure demanding weekly bias reviews that your team performs monthly is not ambition — it is a standing nonconformity you authored. Auditors do not audit you against best practice; they audit you against your own documents.

Write it

The standard’s mandatory documented information (scope, policy, SoA, assessment processes and results, objectives — the full list is in the aims-42001 module), plus procedures where consistency across people and time is the point: the impact assessment method, supplier evaluation, the change-triggered reassessment rule. Add decision records — who accepted which residual risk, who approved which exception. Short beats complete: a two-page procedure people follow outperforms a twenty-page one they route around.

Put it in tooling

Evidence that tools generate as exhaust: model-registry entries, pipeline logs, ticket workflows, access reviews, deployment approvals. A record produced automatically at the moment of action is cheaper and more credible than a form a human fills in retrospectively — auditors know backfilled paperwork when they see it, because real exhaust has timestamps that match the system logs. Design the workflow so doing the work is creating the record.

Don’t write it

Aspirational procedures beyond your current maturity (write them when you can live them). Restatements of the standard’s own text (the auditor owns a copy). Parallel documents duplicating what the 27001 machinery already controls. And the 80-page ‘AIMS manual’ — a genre that exists to be written, not read. Each of these adds audit surface and maintenance debt while adding zero governance.

Competence and awareness (7.2/7.3) run on a role-based matrix, not a company-wide webinar: governors need enough ML literacy to interrogate a drift metric; engineers need enough governance literacy to know which changes trip the reassessment wire; everyone needs to know the policy exists and what nonconformance means for them. Keep the evidence per role — auditors increasingly interview staff against the training records.

Operational controls (clause 8) live or die on placement. The impact assessments you designed in planning need a trigger list wired into the intake and change process — new system, new use case, new population, vendor model swap — so they fire from workflow, not from memory. Lifecycle controls from Annex A belong inside the ML workflow: required fields in the model registry, review gates in the pull-request template, a deployment checklist that blocks promotion. Supplier controls mean a due-diligence questionnaire, contract clauses allocating AI responsibilities, and a re-assessment trigger when the vendor swaps its underlying model — the scenario the aims-42001 module drilled.

Clause 9 metrics that auditors respect — two layers, both mandatory in spirit
MetricLayerWhy it earns respect

% of in-scope systems with a current impact assessment

Process health

Directly evidences 6.1.4/8.4 operating — and its denominator forces the inventory to stay honest

Days from significant change to completed reassessment

Process health

Tests the tripwire that detects paper systems: change log versus assessment log, as a number

Drift alerts raised vs actioned, by system

System behaviour

Watches the AI, not the bureaucracy — and the raised/actioned gap exposes monitoring theatre

Fairness metrics within threshold at each release

System behaviour

Connects AI objectives to production reality, release by release, with thresholds someone signed

Corrective actions closed with effectiveness verified

Improvement loop

Separates a management system from a ticket queue — the clause 10.2 loop, measured

Key terms: documented information, competence, impact assessment, supplier controls

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.