← All lessons
Level 5 · Optimized8 min read

Management systems in practice: ISO 42001, NIST AI RMF and continuous assurance

At the top level, compliance stops being a project and becomes a system: a repeating cycle that plans, runs, checks and improves, with evidence at each step. Two frameworks describe that cycle. Neither is law, but both are what regulators, customers and insurers point to when they ask "show me your programme".

ISO/IEC 42001:2023

ISO/IEC 42001 is the first certifiable AI management system standard, published in December 2023. It follows the same structure as ISO 27001 (security) and ISO 9001 (quality), so it drops into an existing management system. Its core asks:

  • Context and scope: which AI systems, which sites, which roles.
  • Leadership and policy: top management commitment, an AI policy, assigned roles.
  • Planning: AI risk assessment, AI impact assessment, objectives.
  • Support: resources, competence (training), awareness, documentation.
  • Operation: controls over the AI lifecycle, from data to decommissioning; the Annex A control list covers inventory, impact assessment, data quality, transparency, human oversight, third parties and incident handling.
  • Performance evaluation: monitoring, internal audit, management review.
  • Improvement: corrective action.

If you have followed this Academy, you already hold most of the artefacts. Certification adds an external auditor's opinion, which is valuable when large customers or public-sector buyers require it; many organisations run the standard without certifying.

NIST AI RMF

The NIST AI Risk Management Framework 1.0 (January 2023) is a US voluntary framework organised around four functions: Govern (culture, roles, policy), Map (context, inventory, classification), Measure (testing for accuracy, fairness, security, and tracking), and Manage (prioritise, respond, monitor, improve). The Generative AI Profile (NIST AI 600-1, July 2024) adds actions specific to generative models. NIST is revising the framework under the 2025 AI Action Plan and published a critical-infrastructure profile concept in April 2026; expect a new version. Texas TRAIGA and other state laws reference NIST-aligned programmes as evidence of reasonable care.

Continuous assurance: the check in the cycle

Assurance is the discipline of proving to yourself, before anyone else asks, that the controls are working. Build a simple annual assurance calendar:

  • Quarterly: inventory reconciliation against spend and network data; fairness re-tests for consequential systems; open-incident review.
  • Twice a year: sample five system record files and check each section is current; test the off switch; review vendor changes.
  • Annually: internal audit against your policy and the standard you follow; the NYC-style independent bias audit for hiring tools; management review with a written report; policy and training refresh.
  • On trigger: after a material model change, a serious incident, or a new law.

Use the Academy's assessment as one quarterly input: re-take it, compare domain scores, and treat any drop as a finding.

Internal audit for small organisations

You do not need an audit department. Ask someone who did not build the control to check it against a checklist and write three lines: what was checked, what was found, what was agreed. Independence is about not marking your own homework, not headcount.

Metrics that mean something

  • Share of inventory entries with an owner, tier and current record file.
  • Override rate and complaints per thousand decisions.
  • Fairness impact ratios by system, quarterly trend.
  • Incidents opened, closed, and time to contain.
  • Training completion and quiz scores.
  • Findings from audits and how many are closed on time.

Report these on one page to leadership. The trend matters more than the number.

What this means for you

Choose one framework as your reference (ISO 42001 if customers ask for certification, NIST AI RMF if you mostly operate in the US) and map your existing artefacts to it. Then put the assurance calendar in place; the first internal audit can be one afternoon with a checklist.

Related laws

Quick check · 3 questions

  1. 1.What are the four core functions of the NIST AI RMF?

  2. 2.What distinguishes ISO/IEC 42001 from the NIST AI RMF?

  3. 3.What is the point of internal audit in a small organisation?

0 of 3 answered

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.