AIMS-IA
ISO/IEC 42001:2023 Internal Auditor
Level II certification in auditing an AI management system built to ISO/IEC 42001:2023, using ISO 19011:2026 as the audit methodology and ISO/IEC 42001 as the audit criteria. Covers audit programme management, evidence and sampling, testing declared Annex A controls against the Statement of Applicability, and findings through to management review — including the AI system impact assessment as a requirement in its own right, scope that follows from the roles an organization determines toward its AI systems, and the layered normativity of Annex A and Annex B.
Exam Composition
D1The internal audit function and its boundaries12.5%›
Who the internal auditor is, what governs their work, and what does not. Establishes ISO 19011 as method and ISO/IEC 42001 as criteria, the seven principles and how they interact, and the boundary against certification-body activity. Without this, every downstream judgment rests on borrowed assumptions.
D2Audit programme management20%›
The programme above the individual audit: objectives, risks, resources, competence, scope, methods, monitoring and improvement. ISO 19011:2026 clause 5 throughout, with the AIMS-specific twist that programme scope depends on which roles the organization holds toward its AI systems.
D3Conducting the audit: evidence, sampling and testing20%›
The individual audit from initiation to completion - ISO 19011:2026 clause 6 and Annex A. Domain 3 is about the quality of the evidence: whether it was gathered soundly, sampled defensibly and verified. Whether it satisfies a particular requirement is Domain 4.
D4Auditing the AIMS against ISO/IEC 42001 as criteria30%›
The largest domain, and where this cert diverges from its ISMS sibling. Testing the management system clause by clause, with the layered normativity of Annex A and Annex B, the role-based scope, and the AI system impact assessment as a required artifact with no ISO/IEC 27001 equivalent.
D5Findings, reporting, follow-up and management review17.5%›
Turning evidence into findings that survive challenge, reporting them to the people who can act, and closing the loop through corrective action and management review. Where Domain 4 asks whether a requirement is met, Domain 5 asks whether the statement saying so is defensible.
The first lesson is free.
No card. See whether Certidemy fits how you learn.
Start free