The reference AI management system standard, from clause 4 to clause 10, taught for the people who have to design and defend the system — not audit it.
Who this is for
- AI governance leads building an AI management system
- Compliance and risk professionals mapping AI controls
- ISMS practitioners extending into AI
- Consultants supporting 42001 implementations
What you will be able to do
- Read ISO/IEC 42001 fluently, clause by clause
- Design an AI management system (AIMS) that fits your organisation
- Integrate 42001 with existing ISO management systems (27001, 9001, 27701)
- Perform Annex A control gap analysis
- Build the evidence base an external auditor will accept
- Position an AIMS credibly against the EU AI Act and other regimes
Syllabus
Each module comprises a mix of structured reading, worked examples, and applied exercises. Every programme concludes with an integrated written assessment marked against the published rubric.
Module 1. Context and structure of ISO 42001
How the standard sits in the ISO management-systems family. Harmonised structure. Relation to 27001, 27701, 9001.
Module 2. Clauses 4–5: Context and leadership
Determining the AIMS scope, interested parties, leadership commitment, policy, roles.
Module 3. Clause 6: Planning
AI risk assessment, AI impact assessment (a distinctive 42001 addition), objectives, planning of changes.
Module 4. Clause 7: Support
Resources, competence, awareness, communication, documented information.
Module 5. Clause 8: Operation
Operational planning and control, AI system impact assessment in practice, data management.
Module 6. Clauses 9–10: Evaluation and improvement
Monitoring, internal audit, management review, nonconformity and continual improvement.
Module 7. Annex A controls (deep dive)
The reference control set: policies, internal organisation, resources for AI, impact assessment, AI system lifecycle, third-party relationships, and use of AI systems.
Module 8. Integration and certification
Combining with existing management systems. The path to certification. Common findings from early 42001 audits.
Assessment
Brief
For your organisation (or a fictional one), produce: (1) the AIMS scope statement, (2) a completed AI impact assessment for a chosen system, and (3) an Annex A applicability statement with rationale for each excluded control. 3,000 words plus artefacts.
Sample question
Your organisation is already certified to ISO 27001 and considers itself mature on data protection. What is the minimum viable AIMS you can bolt on to reach 42001 conformity, and what gaps will you almost certainly still have?
Assessments are marked by a named human examiner against the four-dimension rubric: regulatory accuracy (30%), applied judgement (30%), artefact quality (25%), communication (15%). Pass at 60, distinction at 75.
Prerequisites
Working knowledge of at least one ISO management system (27001 or equivalent) is strongly recommended.
Certification
On successful completion (pass mark 60), you receive a SAAII Certified Practitioner (CP) — ISO/IEC 42001 for Practitioners credential. The credential is CPD-accredited, verifiable at thesaaii.com/verify, and forms one component toward higher-tier credentials. See the certification ladder for how it stacks.
Ready to enrol?
ISO/IEC 42001 for Practitioners runs continuously with rolling enrolment. Founding-cohort discount (25%) applies to the first 100 enrolments across the whole programme portfolio.
Cohort licensing available from £395/seat (10+). Public sector, education, and registered charity: 20% discount. Instalment plans available for programmes at £495 and above. See For organisations and the FAQ for detail.