Preparation map
Four decisions to connect
AI system contextPurpose, stakeholders, deployment setting, lifecycle stage and external dependencies.
Risk and impactOrganisational uncertainty considered separately from effects on individuals, groups and society.
Lifecycle controlsData, development, validation, deployment, monitoring, change and retirement responsibilities.
Governance evidenceInventories, approvals, logs, monitoring records, incidents, reviews and improvement actions.
Original reasoning example
One register is not two assessments
A healthcare AI team records cybersecurity, availability and financial risks in the enterprise register. It decides this register also serves as the AI impact assessment, although it contains no analysis of patients, carers or vulnerable groups.
Competent next decisionKeep the organisational risk process, but conduct and document the distinct impact assessment needed for effects on relevant individuals and society. Connect the outputs where useful without treating them as interchangeable.
Why it mattersThe artefacts may share owners and inputs, but their questions point in different directions. This distinction is central to competent AIMS implementation.
This is an Aegentra Labs teaching scenario, not a recalled or official examination item.A workable sequence
Study plan
Days 1–2Clauses 4–6Define one AI system, its purpose, affected parties, scope, risks, impacts and objectives.
Days 3–5Annex A themesMap governance, data, lifecycle, third-party and transparency controls to the system.
Days 6–7Risk versus impactCreate two linked but distinct assessments and explain why each exists.
Days 8–10Operation and evidenceList pre-deployment approval, monitoring, change, incident and retirement records.
Days 11–14Scenario decisionsPractise timed sets and revise the domain where your reasoning breaks sequence.
Study an AIMS as a live operating systemThe standard joins management-system governance to AI-specific lifecycle work.
PECB publishes six Lead Implementer competency domains spanning AI and AIMS principles, ISO/IEC 42001 requirements, implementation planning, implementation, monitoring and improvement. A scenario can therefore start with leadership or scope and finish with data, deployment or monitoring evidence.
Avoid revising Annex A as a flat list. For each control objective, ask which AI system it applies to, what risk or impact it addresses, who operates it, what evidence exists and what would trigger review.
Keep risk assessment and impact assessment distinctThey inform each other but do not answer the same question.
Organisational risk assessment considers uncertainty affecting the organisation’s objectives and the AIMS. AI system impact assessment examines consequences for individuals, groups and society across the system lifecycle and use context.
A mature implementation can connect both views to decisions, controls and monitoring. The error is assuming that an enterprise risk register automatically covers social, rights, safety or accessibility effects that were never assessed.
Revise through AI evidenceFor each claimed control, identify the record that proves the decision occurred.
Useful evidence can include an AI system inventory, defined intended use, data provenance, validation results, impact-assessment approvals, human-oversight design, third-party responsibilities, monitoring thresholds, change records and incident follow-up.
- A model card or policy may describe intent; logs and review records show operation.
- A third-party contract does not remove the organisation’s AIMS accountability.
- Human oversight must have authority, competence and a workable intervention path.
- A change in data, model, purpose or deployment context can trigger reassessment.
After this pathway
Choose the next capability for the work you want to do.
Passing one exam does not automatically grant another credential or a job outcome. These are complementary study directions, each with separate requirements.
NIST AI Risk Management Framework
Useful complementary practice for organising AI risk work through Govern, Map, Measure and Manage functions.
It is a voluntary framework, not a substitute for ISO/IEC 42001 requirements or a personal credential.Check the official source ↗ISO/IEC 23894 and ISO/IEC 42005
Useful deeper study for AI risk-management guidance and AI system impact assessment.
Check how each publication applies to your organisation and jurisdiction; buying or reading a standard does not grant certification.Check the official source ↗Continue with the exact qualification
Guide → sample → practice → official training