At the top level, compliance stops being a project and becomes a system: a repeating cycle that plans, runs, checks and improves, with evidence at each step. Two frameworks describe that cycle. Neither is law, but both are what regulators, customers and insurers point to when they ask "show me your programme".
ISO/IEC 42001:2023
ISO/IEC 42001 is the first certifiable AI management system standard, published in December 2023. It follows the same structure as ISO 27001 (security) and ISO 9001 (quality), so it drops into an existing management system. Its core asks:
- Context and scope: which AI systems, which sites, which roles.
- Leadership and policy: top management commitment, an AI policy, assigned roles.
- Planning: AI risk assessment, AI impact assessment, objectives.
- Support: resources, competence (training), awareness, documentation.
- Operation: controls over the AI lifecycle, from data to decommissioning; the Annex A control list covers inventory, impact assessment, data quality, transparency, human oversight, third parties and incident handling.
- Performance evaluation: monitoring, internal audit, management review.
- Improvement: corrective action.
If you have followed this Academy, you already hold most of the artefacts. Certification adds an external auditor's opinion, which is valuable when large customers or public-sector buyers require it; many organisations run the standard without certifying.
NIST AI RMF
The NIST AI Risk Management Framework 1.0 (January 2023) is a US voluntary framework organised around four functions: Govern (culture, roles, policy), Map (context, inventory, classification), Measure (testing for accuracy, fairness, security, and tracking), and Manage (prioritise, respond, monitor, improve). The Generative AI Profile (NIST AI 600-1, July 2024) adds actions specific to generative models. NIST is revising the framework under the 2025 AI Action Plan and published a critical-infrastructure profile concept in April 2026; expect a new version. Texas TRAIGA and other state laws reference NIST-aligned programmes as evidence of reasonable care.
Continuous assurance: the check in the cycle
Assurance is the discipline of proving to yourself, before anyone else asks, that the controls are working. Build a simple annual assurance calendar:
- Quarterly: inventory reconciliation against spend and network data; fairness re-tests for consequential systems; open-incident review.
- Twice a year: sample five system record files and check each section is current; test the off switch; review vendor changes.
- Annually: internal audit against your policy and the standard you follow; the NYC-style independent bias audit for hiring tools; management review with a written report; policy and training refresh.
- On trigger: after a material model change, a serious incident, or a new law.
Use the Academy's assessment as one quarterly input: re-take it, compare domain scores, and treat any drop as a finding.
Internal audit for small organisations
You do not need an audit department. Ask someone who did not build the control to check it against a checklist and write three lines: what was checked, what was found, what was agreed. Independence is about not marking your own homework, not headcount.
Metrics that mean something
- Share of inventory entries with an owner, tier and current record file.
- Override rate and complaints per thousand decisions.
- Fairness impact ratios by system, quarterly trend.
- Incidents opened, closed, and time to contain.
- Training completion and quiz scores.
- Findings from audits and how many are closed on time.
Report these on one page to leadership. The trend matters more than the number.