AIMS Documentation - The Seven Mandatory Documented Elements
A Monday in March 2027 - Schellman Stage 1 audit week for a 1,900-headcount financial-services SaaS vendor. The lead auditor sits down at 9:04 AM with a single PDF binder open on the laptop. Tab 1: AIMS scope. Tab 2: AI policy. Tab 3: AI objectives. Tab 4: AI impact-assessment process. Tab 5: roles, responsibilities, authorities. Tab 6: the AIMS itself. Tab 7: internal-audit results. Seven tabs. Seven mandatory documented elements. Read in order. This is the Stage 1 review: the documentation-review stage that determines whether the organization is ready to host a Stage 2 operating-effectiveness audit, and the stage where most first-time ISO/IEC 42001 implementations get derailed not by control gaps but by document gaps: a scope statement that contradicts the engagement letter, an AI policy that lacks board signature, AI objectives with no measurement source, an impact-assessment process described in two paragraphs, a roles document with no Responsible AI Officer authority statement, an AIMS that exists conceptually but not as a written artifact, internal-audit results that sampled four clauses out of seven. This lesson is the slow walk through each of the seven: what each is, what auditors expect, sample table of contents, Annex A controls each element satisfies, the cross-walk to EU AI Act Articles 17 + 47 and NIST AI RMF Govern 1 + 2, the refresh cadence, and the six common mistakes that turn a Stage 1 documentation review into a stop-the-audit conversation. The L3 deliverable is the complete seven-element binder ready to hand to Schellman, A-LIGN, BSI, or KPMG.
Why the Seven Mandatory Documented Elements Are the Stage 1 Anchor
ISO/IEC 42001:2023 specifies "documented information" requirements throughout Clauses 4 through 10. Most are conditional ("the organization shall document X where applicable"). Seven are unconditional: the standard's text creates an absolute requirement to maintain these as named, version-controlled, accessible documents. They are the artifacts a certification body's Stage 1 auditor will explicitly request before agreeing to schedule Stage 2; the artifacts a notified body's QMS review under EU AI Act Article 17 will examine first; the artifacts a customer-trust-portal auditor or insurance-underwriter assessor will pull during procurement diligence; the artifacts a Chief AI Risk Officer hands to the Article 47 signing committee before authorizing the declaration of conformity.
The seven, in the order auditors typically request them at Stage 1, with the standard clause that creates the requirement:
- Document 1 - AIMS scope statement (Clause 4.3).
- Document 2 - AI policy (Clause 5.2).
- Document 3 - AI objectives (Clause 6.2).
- Document 4 - AI impact-assessment process (Clause 6.1.4 + A.5.2).
- Document 5 - Roles, responsibilities, authorities (Clause 5.3 + A.3.2).
- Document 6 - The AIMS itself (Clause 4.4).
- Document 7 - Internal-audit results (Clause 9.2).
The list is closed, the standard's text creates these seven and these seven only as unconditionally mandatory. Other documented information is conditional (Statement of Applicability, risk-treatment plan, management-review records, corrective-action records, training records): required when applicable, expected for any certification body to find at Stage 1, but produced through processes rather than standing as named single artifacts. The seven are the named artifacts.
Stage 1 mechanics. The Schellman / A-LIGN / BSI / KPMG lead auditor opens the engagement with a Documentation Request List 7-10 business days before the start date. The first seven items are the seven mandatory elements, read in the order above. A missing element is a critical finding, the audit pauses or terminates. An incomplete element (AI policy without management signature; scope failing to name in-scope systems; internal-audit results sampling fewer than half the applicable controls) is a major finding requiring remediation before Stage 2. A weakly evidenced element (objectives with KPIs but no measurement source; roles with RACI but no Responsible AI Officer authority statement) is a minor finding tracked into Stage 2 closure.
The L3 conformity-package framing from lessons 050-055, Annex IV technical-documentation file, internal-control-vs-notified-body decision (Article 43), notified-body engagement playbook, substantial-modification change control, CE marking + Article 47 declaration + Article 71 EU database registration, Annex XIII non-FLOPs designation, applies at the high-risk system level. The seven mandatory elements apply at the AIMS organizational level. The two layers interlock, the AI policy commits the organization to Annex IV production; the impact-assessment process produces evidence both for ISO 42001 A.5 and for Article 27 FRIA; the roles document names the Article 47 signer. Write the seven at the AIMS level; reference them from the per-system Annex IV file.
Documents 1, 2, 3 - Scope, Policy, Objectives
Document 1 - AIMS Scope Statement (Clause 4.3)
The AIMS scope statement defines the boundary of the AI management system. Clause 4.3 requires the scope to consider external and internal issues (Clause 4.1), interested-party requirements (Clause 4.2), and the organization's products and services. It must be documented information. A clear scope is the single most-leverage document the organization writes. It determines what the auditor samples, what the certificate covers, what the customer-procurement officer reads, what the notified body cross-references against the Article 17 QMS scope.
Sample TOC. §1 Purpose and approval. §2 Organizational scope (legal entities, business units, geographies). §3 AI systems in scope by system-card identifier: each with intended-purpose summary, EU AI Act actor classification (Article 3(3) provider / 3(4) deployer / both), risk tier, deployment geographies, business-unit owner. §4 AI systems out of scope with explicit exclusion justifications. §5 Supporting functions in scope (engineering, data, security, legal, compliance, procurement, internal audit, HR). §6 Boundary description with interfaces and supplier/customer touch-points. §7 Cross-walks to AI inventory + per-system tiering memos + EU AI Act Article 17 QMS scope + ISO 27001 ISMS scope. §8 Review cadence: quarterly by AI Governance Committee + annual full re-baseline + on-event refresh (M&A, divestiture, material new system, geographic expansion, regulatory-classification change). §9 Approval signatures, Responsible AI Officer + Chief AI Risk Officer + AI Governance Committee chair + top-management designee.
Sample content. "This AIMS scope statement, effective 2027-Q1-V1.2, covers Acme Financial Services Holdings plc plus named subsidiaries. Scope covers 14 named AI systems: 6 high-risk under Annex III (4 §5(b) creditworthiness, 1 §3(a) education-access, 1 §6(a) law-enforcement-risk-assessment); 5 limited-risk under Article 50; 3 minimal-risk internal-productivity systems retained for AI-policy adherence monitoring. Excludes one internally-developed code-completion assistant as minimal-risk with no external-stakeholder exposure. Supporting functions in scope: ML Engineering, Data Engineering, AI Risk, Information Security, Privacy + Legal, Procurement, Internal Audit. Length 5 pages."
Annex A controls satisfied. A.2.2 (policy foundation), A.3.2 (organizational framing), A.4.2 (scope-bounded resource inventory), A.5.2 (scope triggers impact-assessment), A.6.2 (requirements coverage), A.9.4 (in-scope intended use), A.10.3 + A.10.4 (third-party register).
Common Stage 1 findings: scope boundaries contradict the engagement letter; AI-system list omits a system surfaced during auditor discovery interview; no quarterly review cadence; approval signature block without top-management designee; no explicit-exclusions section. Defensible posture: tight scope; every exclusion justified; signed at top-management; refreshed quarterly.
Document 2 - AI Policy (Clause 5.2)
The AI policy is the top-management statement of intent. Clause 5.2 requires the policy to be appropriate to organizational purpose, provide a framework for setting AI objectives, include commitment to satisfying applicable requirements, include commitment to continual improvement. It must be documented, communicated within the organization, available to interested parties as appropriate, and reviewed for continued suitability.
Sample TOC. §1 Purpose and approval. §2 Scope (cross-reference to Document 1). §3 Principles, alignment to NIST AI RMF Govern principles (valid+reliable; safe; secure+resilient; accountable+transparent; explainable+interpretable; privacy-enhanced; fair-with-bias-managed); ISO 42001 A.2 commitments; EU AI Act values (fundamental-rights, health+safety, democracy+rule-of-law). §4 Framework commitments, apply impact-assessment per Document 4 to all in-scope systems; maintain Annex IV per Article 11 for all high-risk; implement Article 14 oversight + Article 26 deployer; apply Article 50 transparency; provide Article 4 literacy; report Article 73 incidents; maintain Article 17 QMS; A.10 supplier-and-customer obligations. §5 Risk appetite cross-reference. §6 Roles and authority, Responsible AI Officer / Chief AI Risk Officer named with explicit halt-or-pause authority. §7 Policy stack integration: cross-references to AI Acceptable Use (lesson 022), Generative AI Use (lesson 023), AI Vendor Risk (lesson 024), AI Incident Response (lesson 025), InfoSec Policy, Privacy Policy. §8 Continual improvement (Clause 10) + Management review (Clause 9.3). §9 Review cadence: annual minimum + on-event (major regulatory change, organizational change, material risk-appetite change). §10 Signature block, CEO or board-designated top-management + Chief AI Risk Officer + AI Governance Committee chair.
Sample content excerpt. "Acme commits to develop, deploy, and operate AI systems in alignment with NIST AI RMF principles, EU AI Act values, and ISO/IEC 42001:2023. Acme commits to apply the AI Impact-Assessment Process (Document 4) before every deployment; maintain Annex IV per Article 11 for every high-risk system; implement Article 14 oversight; satisfy Article 26 deployer obligations; apply Article 50 transparency; provide Article 4 literacy per the AI Literacy Program (lesson 033); report serious incidents per Article 73; maintain Article 17 QMS evidence. The Responsible AI Officer reports to the CEO with explicit halt-or-pause authority without escalation. Length 7 pages."
Annex A controls satisfied. A.2.2 (the policy is the control), A.2.3 (policy alignment cross-references), A.3.2 (Responsible AI Officer authority statement), A.5.2 (policy commitment to apply impact-assessment), A.6.1.6 (policy commitment to maintain Annex IV), A.8.2 + A.8.3 + A.8.4 (policy commitments to Article 50/72/73), A.10.2 (Article 25 cooperation commitment).
Common Stage 1 findings: AI policy without management or board signature; policy commitments not mapping to operating processes; review cadence absent or longer than annual; policy omits Article 4 literacy commitment; policy-stack-integration section absent. Defensible posture: signed at CEO or board-designee level; every commitment traceable to a named operational process; annual review with version control; cross-referenced from every other policy in the stack.
Document 3 - AI Objectives (Clause 6.2)
AI objectives are measurable targets operationalizing the AI policy. Clause 6.2 requires objectives to be consistent with the policy; measurable (where practicable); take into account applicable requirements; relevant to AI-system conformity and AIMS-process enhancement; monitored; communicated; updated; documented. Vague aspirations ("we aim to be a leader in responsible AI") are not Clause-6.2-compliant.
FY27 sample objectives - 12 measurable targets:
- O1, 100% of high-risk AI systems have a current Annex IV technical-documentation file by Q2 FY27 (source: Annex IV currency tracker).
- O2, 100% of in-scope AI systems have a completed AI Impact-Assessment per Document 4 before deployment by Q1 FY27 (source: intake-form gate compliance rate).
- O3, 100% of high-risk AI systems have a completed Article 27 FRIA by Q2 FY27 (in advance of the Dec 2, 2027 standalone Annex III deadline) (source: FRIA register).
- O4, 100% of Article 50(1) chatbot disclosures implemented by Q1 FY27 (in advance of the Dec 2, 2026 Omnibus-VII accelerated date).
- O5, Red-team coverage rate ≥80% of high-risk systems with OWASP LLM Top 10 + Agentic Top 10 + MITRE ATLAS baseline by Q3 FY27.
- O6, Article 14 human-oversight effectiveness rate ≥95% of monitored sample by Q4 FY27.
- O7, Article 4 AI-literacy coverage rate 100% of in-scope staff (1,900 headcount target) by Q4 FY27 (source: LMS completion records).
- O8, ISO 42001 Stage 2 certification achieved by Q3 FY27 with no major nonconformities.
- O9, Internal-audit programme covers 100% of applicable Annex A controls and all clauses 4-10 within FY27.
- O10, Management-review cadence quarterly minimum with documented Clause 9.3 inputs and outputs for every meeting.
- O11, Corrective-action closure rate ≥90% within standard windows (30d minor / 90d major).
- O12, Supplier due-diligence completion rate 100% of in-scope AI suppliers by Q2 FY27.
Annex A controls satisfied. A.2.2 (objectives operationalize policy); supports A.5 cluster via O2 + O3; A.6.1.6 via O1; A.6.1.3 via O5; A.6.1.5 via O6; A.4.6 via O7; A.10.3 via O12; A.8 cluster via O4. The objectives document is the operational backbone turning A.2 policy into A.5-A.10 evidence pathways.
Common Stage 1 findings: objectives not measurable; objectives without measurement source; no quarterly tracking; objectives that miss regulatory-deadline pipeline (Article 50 Dec 2, 2026 / FRIA Dec 2, 2027 / Article 4 ongoing); no AI Governance Committee read-out cadence. Defensible posture: every objective measurable + named source + quarterly tracking + explicit deadline alignment.
Documents 4 and 5 - Impact-Assessment Process and Roles
Document 4 - AI Impact-Assessment Process (Clause 6.1.4 + A.5.2)
The impact-assessment process is the documented procedure for evaluating AI-system impact on individuals, groups, and society. Clause 6.1.4 creates the requirement; Annex A.5.2 operationalizes it. This is the single most-leveraged process the organization runs: one well-designed process produces evidence for the AIMS requirement, the EU AI Act Article 27 FRIA, the GDPR Article 35 DPIA, the NIST AI RMF Map function, and U.S. state-level requirements (Colorado SB 24-205 algorithmic-discrimination impact assessment; NYC LL 144 bias audit; Texas TRAIGA disparate-impact analysis). Write once; cite four times.
Sample TOC. §1 Purpose and scope (applies to every in-scope AI system at intake and on substantial modification). §2 Triggers, new intake; substantial modification under Article 43(4); new use context; data-source change; regulatory-classification change; upstream-GPAI model update. §3 Process roles, conductor (AI Officer for governance content; Business-Unit Owner for use-context; ML Engineering for technical); reviewer (AI Risk + Privacy + Security Officers); approver (AI Governance Committee for high-risk; AI Officer + Business-Unit Owner for limited; AI Officer for minimal). §4 Combined-template structure, the single artifact satisfying ISO 42001 A.5.2-A.5.5 + Article 27 FRIA + GDPR Article 35 + NIST Map 1-5 + state law:
- §4.1 System identification + intended purpose (Article 3(1) + A.6.1.1 + NIST Map 1).
- §4.2 Affected individuals and groups (Article 3(32) + A.5.4 + NIST Map 3).
- §4.3 Use context and foreseeable misuse (Article 9(2)(b) + A.5.4 + NIST Map 3).
- §4.4 Societal impacts (A.5.5 + NIST Map 3 + Map 5).
- §4.5 Benefit-and-harm with severity/likelihood matrix (A.5.4 + Article 27(1)(c) + NIST Map 5).
- §4.6 Mitigations existing + proposed (A.5.4 + Article 27(1)(d) + NIST Manage 1).
- §4.7 Residual risk + acceptance posture (A.5.4 + Article 9(5) + NIST Map 5).
- §4.8 Cross-reference to Article 27 FRIA template + Article 35 DPIA + applicable state template.
§5 Sign-off and documentation, version-controlled artifact stored in AI inventory record. §6 Integration with risk treatment, output feeds the AI Risk Register (Clause 6.1.2) and Risk Treatment Plan (Clause 6.1.3); residual-risk acceptance routes through the Risk Acceptance Memo (lesson 042). §7 Refresh cadence, annual + on substantial modification + on new use context + on regulatory-classification change. §8 Cross-walks to Annex IV §5; ISO 42001 A.5/A.6/A.7; NIST AI RMF Map 1-5; Article 27/35/state. §9 Approval signatures.
Sample content excerpt. "The process applies at intake and on substantial modification. It produces a single combined-template artifact satisfying ISO 42001 A.5.2-A.5.5 + Article 27 FRIA + Article 35 DPIA + NIST Map 1-5 + applicable U.S. state requirements. The intake form gates deployment, no system reaches production without a completed assessment. §4.5 satisfies Article 27(1)(c) + NIST Map 5; §4.6 satisfies Article 27(1)(d) + NIST Manage 1; §4.7 satisfies Article 9(5). Version-controlled, stored in the AI inventory, reviewed quarterly for high-risk systems. Length 12 pages."
Annex A controls satisfied. A.5.2 (the process is the control), A.5.3, A.5.4, A.5.5; supports A.6.1.1 + A.6.2 + A.9.4.
Common Stage 1 findings: process described in two paragraphs without sections; process that names FRIA or DPIA but not the AIMS impact assessment; no defined conductor / reviewer / approver; no integration into risk treatment; no refresh cadence. Defensible posture: a single named process producing one combined-template; explicit cross-walks; named roles; integrated with risk treatment; refreshed annually + on event.
Document 5 - Roles, Responsibilities, and Authorities (Clause 5.3 + A.3.2)
The roles document names the persons and functions accountable for the AIMS and authorized to act within it. Clause 5.3 requires top management to assign responsibilities and authorities for ensuring AIMS conformity and reporting performance to top management. Annex A.3.2 operationalizes with specific AI-role expectations. The Stage 1 auditor examines for clear authority, particularly the Responsible AI Officer's authority to halt or pause a non-compliant deployment, not just to recommend.
Sample TOC. §1 Purpose and approval. §2 Top-management designee, CEO or named board-level executive accountable for the AIMS. §3 Responsible AI Officer / Chief AI Risk Officer, top-management designee; reports to §2 (CEO direct typical); explicit halt-or-pause authority for non-compliant deployments; chairs the AI Governance Committee; signs or counter-signs the Article 47 declaration of conformity per the delegation-of-authority policy (Article 47 personal-accountability framing per lesson 102). §4 AI Governance Committee: membership (Chief AI Risk Officer chair; CISO; Chief Privacy Officer; General Counsel; Chief Data Officer; ML Engineering Lead; Internal Audit Lead; named Business-Unit Owners), cadence (monthly minimum), decision authorities, quorum, minutes-retention. §5 AI Risk Officer: risk register, treatment, residual-risk acceptance memos. §6 AI Privacy Officer - GDPR DPIA / Article 35 input; cross-walks with DPO. §7 AI Security Officer - OWASP LLM Top 10 + Agentic Top 10 + MITRE ATLAS red-team coverage; cross-walks with CISO. §8 AI Internal Audit Lead, internal-audit programme per Document 7; independence requirement. §9 Engineering function leads. §10 Business-Unit Owners. §11 Third-party risk lead, A.10.3 supplier register + due diligence + Annex XII receivable verification. §12 Article 47 declaration signing committee, General Counsel signing authority + Chief AI Risk Officer counter-signature + accountable Business-Unit Owner counter-signature; Chief AI Risk Officer carries personal-accountability framing. §13 RACI matrix across AIMS activities. §14 Reporting lines and escalation paths. §15 Refresh cadence, annual + on organizational change. §16 Approval signatures.
Sample content excerpt. "The Responsible AI Officer is the Chief AI Risk Officer, reporting directly to the CEO. The CARO holds explicit authority to halt or pause the deployment, modification, or operation of any in-scope AI system upon determination of non-conformity, without further escalation. The authority extends to ordering immediate take-down under serious-incident conditions (with subsequent AI Governance Committee ratification). The CARO chairs the AI Governance Committee (monthly) and co-signs the Article 47 declaration for every high-risk system placed on the EU market. The Article 47 signing committee comprises the General Counsel (signing authority per delegation-of-authority policy), the CARO (counter-signature), and the accountable Business-Unit Owner (counter-signature). The CARO is personally accountable for the declaration's accuracy under the Article 47 framing detailed in lesson 102. Length 9 pages plus 2-page RACI annex."
Annex A controls satisfied. A.3.2 (the role-and-authority statement is the control), A.3.3 (escalation-path documentation); supports A.2.2 (policy operationalization), A.5.2 (process roles), A.6.1.4 (halt-or-pause authority), A.10.2 (supplier-and-customer roles).
Common Stage 1 findings: Responsible AI Officer role exists but with recommend-only authority; AI Governance Committee composition described without quorum or decision authority; Article 47 signing committee unnamed; RACI absent; Responsible AI Officer reporting line a layer below CEO. Defensible posture: explicit halt-or-pause authority signed at top-management; AI Governance Committee with quorum + decision authorities; named Article 47 signing committee; full RACI; Responsible AI Officer reporting line to CEO direct.
Documents 6 and 7 - The AIMS Itself and Internal-Audit Results
Document 6 - The AIMS Itself (Clause 4.4)
The AIMS itself is the integrating management-system document. Clause 4.4 requires the organization to establish, implement, maintain, and continually improve an AI management system, including the processes needed and their interactions. Documented information must demonstrate the AIMS exists. This document is the binder that integrates the other six elements with the Statement of Applicability (SoA), the operational procedures for Clauses 7-10, and the supplier-and-third-party obligations.
Sample TOC. §1 Purpose and scope (cross-reference to Document 1). §2 Context (Clause 4.1 internal/external issues; Clause 4.2 interested parties: regulators, customers, employees, Article 3(32) affected persons, suppliers, investors). §3 Leadership and AI policy (Clause 5; cross-references to Documents 2 + 5). §4 Planning (Clause 6 risk methodology + treatment + impact-assessment process, cross-reference to Document 4; cross-reference to Document 3 objectives). §5 Support (Clause 7 resources, competence: cross-reference to Article 4 AI Literacy Program from lesson 033, awareness, communication, documented-information control). §6 Operation (Clause 8 operational planning; per-system lifecycle integration with A.6; per-system data integration with A.7). §7 Performance evaluation (Clause 9 monitoring, cross-reference to objectives KPI tracker; Clause 9.2 internal-audit programme, cross-reference to Document 7; Clause 9.3 management review with charter + cadence + agenda template). §8 Improvement (Clause 10 corrective-action + nonconformity + continual improvement). §9 Statement of Applicability: all 38 Annex A controls with applicability determination, justification, implementation reference, "not applicable" justification. §10 Process map, visualization of AIMS processes and interactions. §11 Integration with adjacent management systems (ISO 27001 ISMS; ISO 9001 QMS where applicable; ISO 22301 BCMS where applicable). §12 Cross-walk appendix, explicit cross-references from each in-scope element to EU AI Act articles + NIST AI RMF outcomes + Annex A controls. §13 Review and update, annual minimum; continuous improvement through Clause 10. §14 Approval signatures.
Sample content excerpt. "The Acme AIMS v2.1 integrates the seven mandatory documented elements with the SoA covering all 38 Annex A controls, the operational procedures for Clauses 7-10, and the supplier-and-customer-relationship procedures. The SoA at §9 documents applicability, 36 applicable, 2 NA with justification (A.4.5 GPU/TPU computing not applicable to the hosted-LLM-only architecture; A.7.6 data preparation not applicable to the zero-fine-tune deployment posture). The AIMS integrates with the ISO 27001 ISMS through shared context analysis and shared internal-audit programme structure. The §12 cross-walk appendix maps every applicable Annex A control to corresponding EU AI Act articles and NIST AI RMF outcomes. Reviewed annually at Q1 management review. Length 34 pages including SoA appendix."
Annex A controls satisfied. Document 6 indirectly satisfies all 38 Annex A controls through the SoA and integration of operational procedures. Directly: A.2.2 (integration), A.2.3 (cross-walk to ISO 27001), A.3.2 (integration of Document 5); plus integration of all A.4-A.10 controls through per-area operational procedures.
Common Stage 1 findings: AIMS exists conceptually but no written integrating document; SoA incomplete (controls listed without applicability or implementation reference); "Not applicable" controls without justification; no cross-walk appendix; AIMS omits Clause 7.5 documented-information control. Defensible posture: a single integrating AIMS document; complete SoA with justification for every control; full cross-walk appendix; version control documented; reviewed annually.
Document 7 - Internal-Audit Results (Clause 9.2)
The internal-audit results are the outputs of the internal-audit programme. Clause 9.2 requires planned-interval internal audits to determine whether the AIMS conforms to its own requirements and the standard's requirements and is effectively implemented and maintained. The programme must consider process importance and prior-audit results. Documented information of the programme and results must be retained.
Sample TOC. §1 Programme charter: purpose, scope, methodology, auditor qualification + independence. §2 Annual cycle plan, Q1 risk-based prioritization + full-clause audit (4-10); Q2 focused-audit on A.5 + A.6 + A.7; Q3 focused-audit on A.8 + A.9 + A.10; Q4 corrective-action follow-through + Stage 2 readiness review. §3 Auditor competence + independence, ISACA AI audit certification + IIA AI audit guidance training + applicable vendor training; AI Internal Audit Lead reports to Audit Committee, not to Chief AI Risk Officer. §4 Audit work papers per audit: scope, methodology, sampling strategy, evidence reviewed, findings, recommendations, management response, target closure date. §5 Findings register: all FY26 cycle findings classified major NC / minor NC / OFI with status, owner, target closure date. §6 Corrective-action follow-through verification. §7 Audit-report-to-management synthesis to Responsible AI Officer + AI Governance Committee + Audit Committee. §8 Management-review input (Clause 9.3 Q1 FY27). §9 Approval signatures, AI Internal Audit Lead + Audit Committee chair.
Sample content excerpt. "The Acme FY26 AI Internal Audit Programme covered all seven clauses (4-10) plus 36 of 38 applicable Annex A controls on a quarterly cycle. The team comprised 3 AI Internal Auditors (ISACA-AI-audit-certified) with documented independence (reporting line to the Audit Committee). The cycle produced 1 major NC (A.10.3 supplier due-diligence gap, closed Q4), 7 minor NCs (A.4.6 literacy-record format; A.5.3 template version-drift; A.6.1.5 monitoring-cadence; A.6.1.7 event-log retention; A.7.4 data-quality on 2 systems; A.8.4 incident-classification rubric; A.10.2 contract-clause mismatch: 6 closed Q4, 1 in remediation Q1 FY27), 12 OFIs. Findings register, work papers, corrective-action register, synthesis report are in the FY26 Internal Audit Binder. Length: 180 pages including work papers."
Annex A controls satisfied. Document 7 directly satisfies operating-effectiveness evidence for every applicable Annex A control through audit findings and remediation status. Specifically: A.2.2 + A.2.3 (policy audit), A.3.2 + A.3.3 (organization audit), A.4.2-A.4.6 (resources audit), A.5.2-A.5.5 (impact-assessment audit), A.6.1.1-A.6.2 (lifecycle audit), A.7.2-A.7.6 (data audit), A.8.2-A.8.5 (information audit), A.9.2-A.9.4 (use audit), A.10.2-A.10.4 (third-party audit).
Common Stage 1 findings: no internal-audit programme exists (critical finding); programme exists but FY cycle incomplete at Stage 1; auditor independence questionable (AI Internal Audit Lead reports to Chief AI Risk Officer); auditor competence not evidenced; findings register without corrective-action follow-through; results not fed to management review. Defensible posture: full FY cycle completed with sampling across all clauses and majority of Annex A controls; documented independence; documented competence; complete findings register with remediation; results fed to management review.
Cross-Walks, Refresh Cadence, and Six Common Mistakes
Cross-Walks - The Seven ↔ Annex A ↔ EU AI Act ↔ NIST AI RMF
The defensible posture is that each element is written once and cited multiple times across frameworks. Summary:
- Document 1 (Scope) ↔ A.2.2 + A.3.2 + A.4.2 + A.5.2 + A.6.2 + A.9.4 + A.10.3 + A.10.4 ↔ Article 17 QMS scope ↔ NIST Govern 1.2.
- Document 2 (AI Policy) ↔ A.2.2 + A.2.3 + A.3.2 + A.5.2 + A.6.1.6 + A.8 cluster + A.10.2 ↔ Article 17(1)(a) QMS compliance strategy ↔ NIST Govern 1.1 + 1.3.
- Document 3 (AI Objectives) ↔ A.2.2 + A.5 cluster + A.6.1.3/.5/.6 + A.4.6 + A.10.3 + A.8 cluster ↔ Article 17(1)(h) QMS performance + Article 4 literacy + Article 50 + Article 27 + Article 11 ↔ NIST Govern 1.4 + Measure 4.
- Document 4 (Impact-Assessment Process) ↔ A.5.2 + A.5.3 + A.5.4 + A.5.5 + A.6.1.1 + A.6.2 + A.9.4 ↔ Article 27 FRIA + Article 9 RMS + Article 35 GDPR DPIA ↔ NIST Map 1 + Map 3 + Map 5.
- Document 5 (Roles) ↔ A.3.2 + A.3.3 + A.2.2 + A.5.2 + A.6.1.4 + A.10.2 ↔ Article 17(1)(k) designated QMS person + Article 47 declaration signer + Article 26(2) deployer designated person ↔ NIST Govern 2.1 + 2.2 + 2.3.
- Document 6 (AIMS Itself) ↔ All 38 Annex A controls through SoA + integration ↔ Article 17 QMS + Article 11 Annex IV + Article 9 RMS + Article 14 oversight + Article 26 deployer + Article 72 post-market ↔ NIST Govern all + Map all + Measure all + Manage all.
- Document 7 (Internal Audit Results) ↔ All applicable Annex A controls operating-effectiveness ↔ Article 17(1)(h) QMS testing + Article 17(1)(j) record-keeping ↔ NIST Govern 4.3 + Measure 4.
The cross-walk turns the seven into the multi-framework evidence backbone, customer-trust-portal auditor pulls Document 6 for SoA + cross-walk appendix; EU AI Act notified body pulls Documents 2 + 4 + 6 for Article 17 QMS evidence; NIST AI RMF maturity assessor pulls Documents 2 + 3 + 4 + 6 for Govern + Map + Measure outcomes; Article 47 signer pulls Document 5 for personal-accountability framing.
Refresh Cadence
- Document 1 (Scope): quarterly review by AI Governance Committee + annual full re-baseline + on-event (M&A, divestiture, material new AI system, geographic expansion, regulatory-classification change).
- Document 2 (AI Policy): annual minimum + on-event (major regulatory change, organizational change, material risk-appetite change).
- Document 3 (AI Objectives), quarterly tracking + annual re-baseline at FY-end.
- Document 4 (Impact-Assessment Process), annual minimum + on regulatory change; per-assessment instances refreshed annually for high-risk systems + on substantial modification.
- Document 5 (Roles): annual minimum + on organizational change (M&A, reorganization, key personnel change).
- Document 6 (AIMS Itself), continuous improvement through Clause 10; annual full review at Q1 management review.
- Document 7 (Internal Audit Results), annual minimum (full FY cycle) + quarterly focused audits + corrective-action follow-through ongoing.
Six Common Mistakes
Mistake 1 - Weak AIMS scope (vague boundaries). Generic language ("AI systems used in the organization") rather than naming specific in-scope and out-of-scope systems with justification. Fix: write the scope with explicit named-system lists, named-exclusion lists with justification, explicit boundary descriptions; quarterly review with the AI Governance Committee.
Mistake 2 - Leadership-unendorsed AI policy. Signed at a layer below top management, a Director of Compliance, a VP of Engineering. Clause 5.2 requires top-management commitment. Fix: sign at CEO or board-level designee with signature page; counter-sign by Chief AI Risk Officer + AI Governance Committee chair; communicate to all in-scope staff with acknowledgment records.
Mistake 3 - Unmeasurable AI objectives. Aspirations ("improve AI governance maturity") rather than measurable targets with named measurement sources. The auditor cannot verify operating-effectiveness against unmeasurable objectives. Fix: every objective with numerical target + deadline + named measurement source + tracking cadence + escalation threshold.
Mistake 4 - Weak impact-assessment process (no template). Described conceptually in two paragraphs without a structured template, named conductors/reviewers/approvers, or cross-walks to Article 27 + Article 35 + state law. Fix: structured combined-template artifact with explicit sections cross-walked to each framework; named roles; integrated with risk treatment; refreshed annually + on event.
Mistake 5 - RACI gaps for the Article 47 signer. The roles document names the Responsible AI Officer and AI Governance Committee but fails to name the Article 47 declaration signing committee, leaving Article 47 personal-accountability framing unaddressed. For any organization placing a high-risk system on the EU market this is a critical gap. Fix: name the Article 47 signing committee explicitly (General Counsel as signing authority + Chief AI Risk Officer counter-signature + accountable Business-Unit Owner counter-signature); reference the personal-accountability framing of lesson 102; document the delegation-of-authority policy.
Mistake 6 - No internal-audit programme. Policies, an AIMS, role assignments exist, but no documented internal-audit programme covering the AIMS at planned intervals. Clause 9.2 requires it; absence is a critical finding that stops Stage 1. Fix: charter the internal-audit programme; staff with qualified independent auditors; complete a full FY cycle ahead of Stage 1; document work papers, findings register, corrective-action follow-through; feed results to Clause 9.3 management review.
Key Takeaways
- ISO/IEC 42001:2023 specifies seven mandatory documented elements, the Stage 1 audit anchor artifacts. Missing element = critical finding; incomplete element = major finding; weakly evidenced element = minor finding.
- The seven, in Stage 1 request order: (1) AIMS scope (Clause 4.3); (2) AI policy (Clause 5.2); (3) AI objectives (Clause 6.2); (4) AI impact-assessment process (Clause 6.1.4 + A.5.2); (5) roles, responsibilities, authorities (Clause 5.3 + A.3.2); (6) the AIMS itself (Clause 4.4); (7) internal-audit results (Clause 9.2).
- Document 1 (Scope) bounds the certificate: list in-scope systems by system-card identifier with Article 3(3)/(4) actor classification, risk tier, geography, business-unit owner; list out-of-scope with justification; quarterly review.
- Document 2 (AI Policy) commits the organization, signed at CEO or board-designee level; commits to NIST principles + ISO 42001 + EU AI Act values + Article 4 literacy + Article 14 oversight + Article 50 transparency + Article 73 reporting + Article 17 QMS; annual review.
- Document 3 (AI Objectives) operationalizes the policy: measurable, deadline-anchored, named measurement sources; quarterly tracking; FY27 baseline of 12 objectives covering Annex IV currency, FRIA, Article 50, Article 4 literacy, red-team coverage, supplier diligence, ISO 42001 certification.
- Document 4 (Impact-Assessment Process) is the write-once-cite-four artifact, one combined-template satisfying ISO 42001 A.5.2-A.5.5 + Article 27 FRIA + Article 35 DPIA + NIST Map 1-5 + applicable U.S. state requirement; named conductors/reviewers/approvers; integrated with risk treatment.
- Document 5 (Roles) names the accountability structure, Responsible AI Officer with explicit halt-or-pause authority reporting to CEO; AI Governance Committee with quorum + decision authorities; AI Risk Officer + AI Privacy Officer + AI Security Officer + AI Internal Audit Lead; Article 47 declaration signing committee explicitly named with personal-accountability framing per lesson 102.
- Document 6 (AIMS Itself) integrates everything, Statement of Applicability for all 38 Annex A controls; cross-walk appendix to Article 17 + Annex IV + NIST AI RMF; integration with ISO 27001 ISMS + ISO 9001 QMS; process map; review annually.
- Document 7 (Internal Audit Results) demonstrates operating effectiveness, full FY cycle covering all 7 clauses + 36 of 38 Annex A applicable controls; qualified independent auditors; findings register with classification + remediation; results fed to Clause 9.3 management review.
- Cross-walk turns the seven into the multi-framework evidence backbone, one AIMS produces evidence for ISO 42001 certification + EU AI Act Article 17 QMS + NIST AI RMF Govern/Map/Measure/Manage + customer-trust-portal disclosure + insurance-underwriter assessment.
- Refresh cadence: scope quarterly + annual + on-event; policy annual + on-event; objectives quarterly + annual; impact-assessment process annual + on regulatory change; roles annual + on organizational change; AIMS continuous; internal-audit results annual minimum + quarterly focused.
- Six common mistakes: weak scope (vague boundaries); leadership-unendorsed policy; unmeasurable objectives; weak impact-assessment process (no template); RACI gap for Article 47 signer; no internal-audit programme. Each is a Stage 1 stoppage; each has a defensible fix.
- L3 deliverable: the complete seven-element binder ready to hand to Schellman / A-LIGN / BSI / KPMG at Stage 1, integrated with the per-system Annex IV file (lesson 050) + the Article 47 declaration committee structure (lessons 054 + 102) + the internal-control-vs-notified-body decision (lesson 051).
Skill.re