Skip to content
Bharat NeuroTech
NeuroCortex · Live
₹101 Shagun on signup · free
JOURNAL · BUILDING

AI management system under ISO 42001 — controls, evidence, certification

What an AIMS actually contains — 10 management clauses + 38 Annex A controls in 9 categories. The 22-week build that takes an ISO 27001-mature Indian organisation to ISO 42001 certificate.

By Dr. Nitnem Singh Sodhi8 min read← all essays
▸ ANSWER

An AI Management System (AIMS) under ISO/IEC 42001 is the documented set of policies, roles, processes, controls and reviews that an organisation uses to govern its AI — analogous to the ISMS that ISO 27001 demands for information security. The AIMS is what the certification body audits; the AI models themselves are not certified. A compliant 2026 AIMS implements the 10 management clauses (Plan-Do-Check-Act structure) and the 38 Annex A controls grouped into 9 categories, mapped to your operational reality. Average Indian implementation: 4–6 months for a 100-person organisation already running ISO 27001.

AI Management System (AIMS)
The set of interrelated elements — policy, objectives, processes, controls, documentation, evidence — used to establish, implement, maintain and continually improve the governance of an organisation's AI activities, per ISO/IEC 42001:2023.
▸ TL;DR
  • The AIMS is what gets certified, not your models.
  • 10 management clauses (PDCA) + 9 Annex A control categories + 38 controls.
  • If you already have ISO 27001, ~40% of the AIMS is already partially evidenced.
  • The hardest clauses for Indian organisations: 6 (planning), 8.2 (impact assessment), 9 (performance evaluation).
  • Build for evidence first, polish later. Auditors check artefacts, not aesthetics.

The 10 management clauses

Clauses 1–3 are scope, normative references and terms. The work lives in clauses 4–10:

  • Clause 4 — Context: internal/external issues, interested parties, AIMS scope.
  • Clause 5 — Leadership: top-management commitment, AI policy, roles & responsibilities.
  • Clause 6 — Planning: AI risks & opportunities, impact assessment process, objectives.
  • Clause 7 — Support: resources, competence, awareness, communication, documented information.
  • Clause 8 — Operation: operational planning, AI risk treatment, impact assessment, system lifecycle.
  • Clause 9 — Performance evaluation: monitoring, internal audit, management review.
  • Clause 10 — Improvement: continual improvement, corrective action.

The 9 Annex A control categories

ISO 42001 ANNEX A — CONTROL CATEGORIES
CategoryFocus# controls
A.2 Policies for AIAI policy and supporting policies3
A.3 Internal organisationRoles, responsibilities, separation of duties3
A.4 Resources for AI systemsData, tooling, human resources, compute6
A.5 Assessing impactsAI system impact assessments on stakeholders5
A.6 AI system lifecycleDevelopment, deployment, decommissioning processes6
A.7 Data for AIData acquisition, quality, provenance4
A.8 Information for interested partiesDocumentation for users, regulators, affected parties4
A.9 Use of AI systemsAcceptable use, third-party AI procurement3
A.10 Third-party relationshipsSupplier AI risk, customer/contractual issues4

The implementation sequence that actually works

  1. Weeks 1–2: Define AIMS scope. Which AI activities are in? Which are out? Auditors will probe this hard.
  2. Weeks 3–4: Write the AI policy. Get it ratified by top management. Appoint roles.
  3. Weeks 5–8: Build the AI inventory. Run impact assessments on top-tier systems. See our AI risk assessment template.
  4. Weeks 9–14: Operationalise Annex A controls. Data governance, lifecycle process, third-party register.
  5. Weeks 15–18: Internal audit (Clause 9.2). Management review (Clause 9.3). First corrective actions logged.
  6. Weeks 19–22: Stage 1 audit by certification body. Close findings.
  7. Weeks 23–26: Stage 2 audit. Certificate issues post-closure of any major non-conformities.

What auditors check first

  1. AIMS scope statement. Vague or expansive scopes are immediately flagged.
  2. AI policy + sign-off date. Undated or unsigned = finding.
  3. AI inventory completeness. Shadow AI is the most common gap.
  4. Impact assessments on top-tier systems. Aggregate-only or template-only = finding.
  5. Evidence of Clause 9 — internal audit + management review. Often skipped or done once and never repeated.
  6. Corrective-action register. A clean register is suspicious; auditors expect to see real corrective actions tracked.

How the AIMS extends your existing management systems

ISO 42001 is designed to interoperate with ISO 27001, 27701 and 9001. The mature pattern in 2026 is a unified management system with shared clause-level structure and category-specific controls. For the certification mechanics see our ISO 42001 certification in India guide — this essay covers what to build; that one covers how to certify it.

▸ FAQ

Frequently asked

What is an AI Management System (AIMS)?
The set of interrelated elements — policy, objectives, processes, controls, documentation, evidence — used to establish, implement, maintain and continually improve the governance of an organisation's AI activities, per ISO/IEC 42001:2023.
How many controls are in ISO 42001 Annex A?
38 controls grouped into 9 categories: policies, internal organisation, resources, impact assessment, AI lifecycle, data, information for interested parties, use of AI systems, and third-party relationships.
Can ISO 27001 be reused for ISO 42001?
Partially. ISO 27001 covers about 40% of the AIMS by overlap — Clause 5 (leadership), Clause 7 (support), Clause 9 (audit), Annex A.3 (organisation). It gives almost nothing on Clause 6 (AI risk), Clause 8.2 (impact assessment), or Annex A.5–A.7 — that is where the bulk of new AIMS work lives.
How long does ISO 42001 AIMS implementation take?
22–26 weeks for a 100-person Indian organisation already running ISO 27001. Significantly longer (40+ weeks) if starting without an existing management system.
▸ NEXT STEP

Stand up your AIMS without rewriting 27001.

Our /compliance/iso-42001 surface scaffolds the AIMS from your existing 27001 evidence and gaps. Dr. Sodhi is lead auditor of record for the full engagement (₹24,499).

Dr. Nitnem Singh Sodhi is a Lead Auditor for ISO/IEC 42001, 27001 and 27701, accredited by ANSI/ABICB since March 2025.

— Bharat NeuroTech · /dr-sodhi
Open the Lab →