Catalog

AIMS-IA

ISO/IEC 42001:2023 Internal Auditor

Level II certification in auditing an AI management system built to ISO/IEC 42001:2023, using ISO 19011:2026 as the audit methodology and ISO/IEC 42001 as the audit criteria. Covers audit programme management, evidence and sampling, testing declared Annex A controls against the Statement of Applicability, and findings through to management review — including the AI system impact assessment as a requirement in its own right, scope that follows from the roles an organization determines toward its AI systems, and the layered normativity of Annex A and Annex B.

50Questions
75%To pass
165Minutes
5Domains

Exam Composition

D1The internal audit function and its boundaries
12.5%

Who the internal auditor is, what governs their work, and what does not. Establishes ISO 19011 as method and ISO/IEC 42001 as criteria, the seven principles and how they interact, and the boundary against certification-body activity. Without this, every downstream judgment rests on borrowed assumptions.

D2Audit programme management
20%

The programme above the individual audit: objectives, risks, resources, competence, scope, methods, monitoring and improvement. ISO 19011:2026 clause 5 throughout, with the AIMS-specific twist that programme scope depends on which roles the organization holds toward its AI systems.

D3Conducting the audit: evidence, sampling and testing
20%

The individual audit from initiation to completion - ISO 19011:2026 clause 6 and Annex A. Domain 3 is about the quality of the evidence: whether it was gathered soundly, sampled defensibly and verified. Whether it satisfies a particular requirement is Domain 4.

D4Auditing the AIMS against ISO/IEC 42001 as criteria
30%

The largest domain, and where this cert diverges from its ISMS sibling. Testing the management system clause by clause, with the layered normativity of Annex A and Annex B, the role-based scope, and the AI system impact assessment as a required artifact with no ISO/IEC 27001 equivalent.

D5Findings, reporting, follow-up and management review
17.5%

Turning evidence into findings that survive challenge, reporting them to the people who can act, and closing the loop through corrective action and management review. Where Domain 4 asks whether a requirement is met, Domain 5 asks whether the statement saying so is defensible.

The first lesson is free.

No card. See whether Certidemy fits how you learn.

Start free