Artificial Intelligence (AI)

ISO/IEC 42001 AI Management System Implementation and Internal Audit Training

DestinationRiyadh
Dates7 – 11 March 2027
Reference1471_24177

Programme overview

Introduction:

ISO/IEC 42001 AI management system implementation and internal audit training is a 5-day course for governance, risk, compliance, quality and IT staff that ends with an AIMS gap assessment, statement of applicability and internal audit plan for a case organisation. Many organisations deploy AI systems with scattered policies, unclear ownership and no audit trail, so they cannot show a certification auditor that the clauses and Annex A controls actually operate. Nominees already run controls, risk registers or audits and work through case studies built on policy documents, records and audit evidence. CoreConcept Training Center delivers this ISO 42001 course.

Course Objectives:

  • Define the AIMS scope, organisational context, interested parties and AI roles required by ISO/IEC 42001 clauses 4 and 5
  • Run an AI risk assessment, risk treatment and AI system impact assessment using ISO/IEC 23894 and ISO/IEC 42005 methods
  • Select Annex A controls, justify inclusions and exclusions and maintain a statement of applicability
  • Establish operational planning, documented information, monitoring and measurement for AI systems under clauses 7 to 9
  • Plan and conduct internal audits of clauses 4 to 10 with ISO 19011 techniques, then grade nonconformities and verify corrective action
  • Prepare management review inputs, an integrated ISO/IEC 27001 and AIMS structure and a certification readiness file

Target Audience:

  • Staff responsible for designing and maintaining AI governance policies, roles and registers
  • Staff responsible for AI risk assessment, impact assessment and risk treatment records
  • Staff responsible for compliance monitoring and evidence for AI products and services
  • Staff responsible for quality management systems and internal audit programmes
  • Staff responsible for information security management systems and IT controls that support AI systems
  • Staff responsible for supplier oversight of AI models, data and cloud services

Course Outline:

Day 1: AIMS Foundations, Context and Scope

  • ISO/IEC 42001 Harmonised Structure and Clause 4 to 10 Requirements
  • AI System Roles as Developer, Provider and User
  • Internal and External Issues Analysis for AIMS Context
  • Interested Parties Register With AI-Specific Requirements
  • AIMS Scope Statement and Boundary Decisions for AI Systems

Day 2: Leadership, AI Policy, Risk and Impact Assessment

  • Clause 5 Top Management Accountability and AI Policy Drafting
  • RACI Matrix for AIMS Roles, Responsibilities and Authorities
  • ISO/IEC 23894 AI Risk Criteria, Identification and Analysis
  • AI Risk Treatment Plan Linked to Annex A Controls
  • ISO/IEC 42005 AI System Impact Assessment Worksheet

Day 3: Annex A Controls, Operation and Performance Evaluation

  • Annex A Control Objectives and Statement of Applicability Justifications
  • Data for AI Systems Controls on Provenance and Quality
  • AI System Life Cycle Controls From Design to Retirement
  • Third-Party and Customer Relationship Controls for AI Suppliers
  • Clause 9 Monitoring, Measurement and AIMS Performance Indicators

Day 4: Internal Audit, Nonconformity and Integration

  • ISO 19011 Audit Programme Design for AIMS Clauses
  • Audit Checklists, Sampling and Interview Techniques for AI Evidence
  • Nonconformity Grading, Root Cause and Corrective Action Records
  • Management Review Inputs, Outputs and Continual Improvement Decisions
  • ISO/IEC 27001 and AIMS Integrated Documentation and Shared Processes

Day 5: Case Study Gap Assessment, Statement of Applicability and Audit Plan

  • Case Organisation Brief With AI Systems Inventory and Records
  • Clause-by-Clause Gap Assessment Against ISO/IEC 42001 Requirements
  • Statement of Applicability Build for the Case Organisation
  • Certification Readiness Review of Documented Information and Evidence
  • Internal Audit Plan Completion and Peer Challenge

Skills You Will Gain:

  • AIMS Scoping
  • AI Policy Drafting
  • AI Risk Treatment Planning
  • AI System Impact Assessment
  • Statement of Applicability Maintenance
  • Management System Auditing
  • Corrective Action Management
  • Integrated Management System Design

Why Attend This Course:

  • Deliver an AIMS gap assessment, statement of applicability and internal audit plan to the AI governance committee and the quality or compliance lead
  • Decide which Annex A controls apply to each AI system and which exclusions can be justified to an auditor
  • Avoid major nonconformities, repeated audit findings and delays at certification caused by missing records or untested controls
  • Equip colleagues with audit checklists, impact assessment worksheets and nonconformity templates for routine use

Conclusion:

Back at work, the participant presents the gap assessment, statement of applicability and internal audit plan to the AI governance committee, the compliance lead and the owners of each AI system. The committee uses them to approve remediation priorities, confirm control owners and fix the date of the first internal audit cycle. After that audit, the unit should review which clauses produced nonconformities, whether corrective actions closed on time and whether the scope and Annex A selections still match the AI systems in use.

Frequently Asked Questions (FAQ):

What should participants know before ISO/IEC 42001 AI management system implementation and internal audit training?

Participants should already work with policies, risk registers, controls or audits and understand how their organisation uses AI systems. Familiarity with another ISO management system standard helps. Bringing an anonymised AI policy, risk register or system inventory lets them test the templates on real material.

How does ISO/IEC 42001 AI management system implementation and internal audit differ from an executive AI governance course?

It works at practitioner level on the management system itself: clauses, Annex A controls, the statement of applicability, documented information and audit evidence. Executive AI governance courses focus on oversight, strategy and risk appetite and do not build audit checklists or gap assessments.

Why does an ISO/IEC 42001 AI management system need both an AI risk assessment and an AI system impact assessment?

The risk assessment looks at risks to the organisation and its objectives, while the impact assessment looks at consequences for individuals, groups and society from a specific AI system. Both feed the risk treatment plan and the choice of Annex A controls.

What do participants take back from ISO/IEC 42001 AI management system implementation and internal audit training?

Participants take back a gap assessment, a statement of applicability and an internal audit plan for a case organisation, plus a scope statement, interested parties register, impact assessment worksheet, audit checklists and nonconformity templates ready to adapt to their own AIMS.

ISO/IEC 42001 AI Management System Implementation and Internal Audit Training runs in Riyadh over 5 days, with 1 upcoming date in Riyadh. The course fee is 20,000 SAR.

All dates in Riyadh

Training in Riyadh

Looking for training courses in Riyadh? CoreConsept Training Center delivers professional training in Riyadh across governance, PMO, leadership and Vision 2030-aligned programmes — in the Saudi capital.

Venue: KAFD district five-star

All programmes in Riyadh ↗

This course in other cities

More dates & destinations ↗

Let’s talk about your next step.