aims-audit

v2026.09.24

ISO 42001 AI Management System (AIMS) audit-prep playbook. Use when an ISO 42001 certification audit is scheduled (Stage 1 or Stage 2), when a surveillance or internal AIMS audit is due, or when preparing an AI Impact Assessment (AIIA).

GitHub
Install command
npx skhub add borghei/aims-audit
Markdown
SKILL.md

AIMS Audit Prep (ISO 42001)

Operational playbook for ISO 42001:2023 AI Management System (AIMS) audit preparation. Whether targeting initial certification, surveillance audit, or annual internal audit.

When to use this skill vs. iso42001-ai-management:

  • This skill: audit imminent; need readiness sprint
  • iso42001-ai-management: building AIMS from scratch; multi-quarter program

When to use this skill

SituationSkill applies
ISO 42001 Stage 1 audit scheduledYes — documentation review prep
Stage 2 (onsite/operational) auditYes — operational evidence sprint
Annual surveillance auditYes — surveillance prep
Internal AIMS auditYes — internal audit playbook
AI Impact Assessment for new systemYes — scripts/ai_impact_assessment_checker.py
Building AIMS from scratchUse ra-qm-team/iso42001-ai-management

ISO 42001 audit structure

Stage 1 (documentation review)

  • Auditor reviews AIMS documentation (typically 1-3 days)
  • Confirms scope, applicability, key documents present
  • Identifies gaps before Stage 2
  • Typically 2-3 weeks before Stage 2

Stage 2 (operational assessment)

  • Auditor onsite (or remote) verifies AIMS operating effectively
  • 3-10 days depending on scope + system count
  • Walkthroughs, interviews, evidence sampling
  • Conclusion: certification recommended (subject to non-conformity closure) or not

Surveillance audits

  • Annual; reduced scope vs initial
  • Typically 1-3 days
  • Focus on high-risk areas + changes since prior audit

Re-certification (year 3)

  • Full audit; similar to initial
  • Typically every 3 years

AIMS audit-prep sprint

4-week sprint (mature AIMS, surveillance audit)

Week 1: Internal audit + gap analysis
Week 2: Remediation + AI inventory refresh
Week 3: Documentation review + walkthrough rehearsal
Week 4: Auditor onsite

8-week sprint (Stage 1 + Stage 2 initial certification)

Weeks 1-3: AIMS documentation completion (Annex A controls coverage)
Weeks 4-5: Stage 1 audit + gap closure
Weeks 6-7: Stage 2 operational evidence prep + mock walkthroughs
Week 8: Stage 2 audit

ISO 42001 clauses + Annex A controls

Clauses (4-10): management system

ClauseTopic
4Context of the organization
5Leadership
6Planning (including AI risk + AI objectives)
7Support (resources, competence, awareness, communication, documentation)
8Operation (AI lifecycle, supplier relationships)
9Performance evaluation (monitoring, internal audit, management review)
10Improvement (nonconformity, continual improvement)

Annex A controls (10 areas)

Annex A areaTopics
A.2Policies related to AI
A.3Internal organization
A.4Resources for AI systems
A.5Assessing impacts of AI systems
A.6AI system lifecycle
A.7Data for AI systems
A.8Information for interested parties
A.9Use of AI systems
A.10Third-party relationships

Critical audit areas

AI Inventory + Impact Assessments

ItemEvidenceCommon gap
Complete AI system inventoryInventory documentShadow AI not captured
AI Impact Assessment (AIIA) per systemPer-system AIIASkipped for "low-risk" systems
AIIA reviewed periodicallyReview recordsOne-time only
Risk classification of systemsPer systemNot documented

AI Policy + Governance

ItemEvidenceCommon gap
AI policy approved + datedSigned policyNot signed / stale
AI ethics principlesDocumented principlesGeneric; not actionable
AI governance bodyCharter / minutesNot formalized
Roles + responsibilitiesRACINot defined

AI Lifecycle Management (Annex A.6)

ItemEvidenceCommon gap
AI development lifecycle definedProcess documentationNot formalized
Data quality controlsPer systemGeneric only
Model validation proceduresPer systemValidation skipped
AI system testingPer systemInadequate testing
Deployment controlsPer systemNo controls
Operational monitoringPer systemDrift not monitored
Decommissioning proceduresPer systemNot defined

Data Governance (Annex A.7)

ItemEvidenceCommon gap
Data sources documentedPer systemVague
Data quality assessedQuality metricsNot measured
Data lineage trackedDocumentationUntracked
Sensitive data protectionControlsInsufficient

Third-party AI (Annex A.10)

ItemEvidenceCommon gap
Third-party AI inventoryListIncomplete
Vendor due diligence for AIPer vendorGeneric IT only
Contract terms for AI vendorsAI-specific clausesStandard MSA only

Clarify First

Before running the audit-prep, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Audit type and stage — Stage 1 documentation review, Stage 2 operational, surveillance, or internal (sets sprint length and whether the focus is documentation or operational evidence)
  • AIMS maturity — mature system vs building from gaps (picks the 4-week vs 8-week sprint)
  • AI systems in scope — which systems and how many (drives the AIIA count and Annex A coverage)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the readiness assessment.

Quick start

  1. Run readiness score: python3 scripts/aims_readiness_score.py --config aims-controls.yaml
  2. Check AIIA per system: python3 scripts/ai_impact_assessment_checker.py --aiia system-aiia.yaml
  3. Pick sprint length based on score
  4. Execute sprint per references/iso42001-aims-readiness-checklist.md

Common AIMS audit findings

  • AI inventory incomplete — shadow AI not captured
  • AIIA missing for systems that look "small" but have impact
  • AI lifecycle process not implemented (designed only)
  • Data governance generic — not AI-specific
  • Performance monitoring missing — drift not detected
  • AI policy stale — written before current AI deployment
  • Third-party AI vendors not assessed
  • Continual improvement not evidenced

Tooling

ScriptPurpose
scripts/aims_readiness_score.pyScore AIMS readiness per clause + Annex A area
scripts/ai_impact_assessment_checker.pyValidate AI Impact Assessment completeness

References


Related skills

  • ra-qm-team/iso42001-ai-management — deep ISO 42001 AIMS program management
  • ra-qm-team/eu-ai-act-specialist — EU AI Act regulatory companion
  • ra-qm-team/audit-prep/ai-act-readiness — AI Act audit-prep variant
  • ra-qm-team/audit-prep/compliance-readiness — multi-framework readiness
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

NOASSERTION

Source path

ra-qm-team/audit-prep/aims-audit

Default branch

main

Latest commit

f308cbd

Tree SHA

d30ff9d