aims.tidua.io · Working guides for AI management systems
Govern the AI you already shipped.
Five working guides to the standards that decide whether an AI management system is real: how to build one, how to secure the information under it, how to assess what your systems do to people, and how to audit all of it.
The setFive documents
Four deep references and one workbook. The workbook is where most people should start if there is an audit in the calendar; the references are where you go when a clause will not resolve.
Your First 42001 Audit
Nineteen steps end to end. Preparation, question banks for every clause, all 38 controls with evidence prompts, a twelve-question test for an impact assessment, and how to write a finding that holds.
ISO/IEC 42001:2023 · CriteriaThe AI Management System
The only certifiable AI standard. Clauses 4 to 10 with what each requires and what an auditor asks for, the full Annex A catalogue, the Statement of Applicability, and the certification path.
ISO 19011:2026 · MethodAuditing Management Systems
The fourth edition, published May 2026. Seven principles, the audit programme, the six stages of an audit, auditor competence — and the new remote and hybrid auditing guidance.
ISO/IEC 42005:2025 · Subject matterAI System Impact Assessment
What your system could do to the people it decides about. The process, the record, a ready-to-use template, severity and likelihood scales, and the mapping to 42001 and the EU AI Act.
ISO/IEC 27001:2022 · CriteriaThe Information Security Management System
The certifiable security standard most AI programmes sit beside. Clauses 4 to 10, risk assessment and treatment in depth, all 93 Annex A controls with typical evidence, Stage 1 and Stage 2 findings, and a crosswalk to 42001.
Where to startFour ways in
An audit is in the calendar
You have been handed an AI management system and a date. Work through the workbook in order; it tells you what to request, what to ask, and what to do with the answers.
Open the workbook →You are building the system
Start with the 42001 guide — the clause walkthrough, the control catalogue and the six-month rollout — then use the 42005 guide to build the impact assessment process clause 6.1.4 requires.
Open ISO/IEC 42001 →You run an audit programme
The 19011 guide covers programme design, method selection and competence — including what changed in the 2026 edition, and how to point an established programme at a discipline it has never audited.
Open ISO 19011 →You already hold, or need, 27001
The 27001 guide takes the ISMS clause by clause, with the risk method, the SoA and all 93 controls — and shows which artefacts can also serve an AI management system, and which cannot.
Open ISO/IEC 27001 →How they fitFour standards, four jobs
Most of what goes wrong in AI governance work comes from collapsing these into each other. They answer different questions and produce different artefacts.
| Standard | Answers | Produces | Type |
|---|---|---|---|
| ISO/IEC 42001 | Is AI governed here, systematically? | A management system, and a certificate if you want one | Requirements |
| ISO/IEC 27001 | Is information secured here, systematically? | An information security management system, and a certificate if you want one | Requirements |
| ISO/IEC 42005 | What could this system do to people? | A documented impact assessment per system | Guidance |
| ISO 19011 | How do we check any of it is true? | An audit programme, findings, and follow-up | Guidance |
The distinction that matters most sits between 42001's two planning clauses. Clause 6.1.2, AI risk assessment, asks what could happen to the organisation. Clause 6.1.4, AI system impact assessment, asks what could happen to everyone else — individuals, groups of individuals, and society. They overlap, they are not the same exercise, and running one does not discharge the other. Collapsing the second into the first is the most common substantive failure in an AI management system, and the reason a general management system auditor can pass a system that has never been assessed for harm.
Honest limitsWhat this is, and is not
What it is
- Independent implementation readings, written to be used rather than filed
- Accurate on structure: clause numbering, control references, defined terms, the 2026 changes to 19011 and the 2022 revision of 27001 were taken from the standards' publicly viewable sections
- Practical: templates, question banks, scales, evidence lists and checklists you can take into a room
- Free, static, and account-free — nothing here tracks you or asks who you are
What it is not
- Not a substitute for the standards. Their requirement and guidance text is copyrighted and none of it is reproduced here
- Not endorsed by ISO or IEC
- Not a certification, and not legal advice on the EU AI Act or any other regime
- Not sufficient on its own: you cannot audit against criteria you have not read, so buy licensed copies before you do
Every clause title, control reference, defined term and structural fact on this site was taken from the publicly viewable sections of the four standards on the ISO Online Browsing Platform, and from the publishers' document previews. The body text of the operative clauses is paywalled in all four cases. Everything presented as guidance here is an implementation reading written to the clause titles and to established practice — each document says so at the top, and says which parts are inference.