{"description":"An independent internal-audit cycle for the AI management system: set scope and criteria, test governance, risk, documentation, operations, value-chain controls, and reporting, then issue findings and an evidence-backed conclusion. The audit supports management improvement and assurance; it does not certify conformity.","edges":[{"id":"e-confirm-trigger-and-boundaries-formulate-findings-and-conclusion","source":"confirm-trigger-and-boundaries","target":"formulate-findings-and-conclusion"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"controlVerbs":{"UC-AI-01":"tests","UC-AI-02":"tests","UC-AI-03":"tests","UC-AI-04":"tests","UC-AI-05":"tests","UC-AI-06":"tests","UC-AI-07":"tests","UC-AI-08":"tests","UC-AI-09":"tests","UC-AI-10":"tests","UC-AI-11":"tests","UC-AI-12":"tests","UC-AI-13":"tests","UC-AI-14":"tests","UC-AUDIT-21":"tests"},"controls":["UC-AI-01","UC-AI-02","UC-AI-03","UC-AI-04","UC-AI-05","UC-AI-06","UC-AI-07","UC-AI-08","UC-AI-09","UC-AI-10","UC-AI-11","UC-AI-12","UC-AI-13","UC-AI-14","UC-AUDIT-21"],"department":"internal-audit","domains":["audit"],"independence":"The engagement reviewer must be independent of the AI system operation and must not own remediation decisions.","library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso42001-aims-internal-audit","contentDigest":"sha256:15ecca1696f441388036dd0925f0e6d73e923ea467770f5f0b411263de489779","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:15ecca1696f441388036dd0925f0e6d73e923ea467770f5f0b411263de489779","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-iso42001-aims-internal-audit"},"lineOfDefense":"assure","mappingStatus":"mapped","qualification":"An internal-audit conclusion is not a certification opinion. Any AIUC-1 or other crosswalk reference is a scoped evidence aid, not a claim that the source frameworks are interchangeable.","risks":[],"scope":"Internal audit of the in-scope AI management system and its supporting processes against ISO/IEC 42001. Include AIUC-1 evidence only where the crosswalk identifies a relevant safeguard.","slug":"audit-iso42001-aims-internal-audit","source":"coworkcanvas-gallery","standards":["iso-42001","iia-2024","aiuc-1"],"teams":["internal-audit","ai-governance"]},"name":"ISO/IEC 42001 AI Management System Internal Audit","nodes":[{"data":{"controls":["UC-AI-01","UC-AI-02","UC-AI-03","UC-AUDIT-21"],"description":"Establish the engagement mandate, AIMS boundary, criteria, period, and independence safeguards before evidence is assessed.","instructions":"**Objective** — Establish a defensible audit scope for the AI management system (AIMS) and preserve independence before fieldwork begins.\n\n**Inputs** — The approved audit request, AIMS scope and policy, AI system and value-chain inventories, prior findings, the applicable ISO/IEC 42001 clauses and controls, and any AIUC-1 crosswalk rows selected as supplemental criteria.\n\n**Procedure**\n1. Identify the systems, lifecycle stages, providers, data processes, locations, and organizational units inside the AIMS boundary. Record exclusions and the reason each exclusion is appropriate.\n2. Confirm the review period, audit objectives, criteria, sampling approach, evidence sources, materiality considerations, and reporting recipients.\n3. Check the engagement team's independence and competence. Escalate any conflict or management responsibility before testing starts.\n4. Reconcile the criteria to the unified controls in this workflow; distinguish ISO/IEC 42001 requirements from directional AIUC-1 crosswalk evidence.\n\n**Record in AssureSwarm** — Create or update the Audit item with the approved scope, criteria, period, responsible engagement roles, and independence confirmation. Link the AIMS policy, system inventory, prior findings, and any scoped crosswalk record.\n\n**Exit criteria** — The chief audit executive or delegated independent reviewer approves a complete boundary and criteria set, conflicts are resolved, and every selected control has an evidence source or a documented evidence request.","kind":"task","label":"Confirm Trigger, Scope, and Audit Boundaries","performedBy":{"note":"The agent assembles the scope pack and evidence index. The independent reviewer approves the boundary and criteria.","primitives":["coach-query-data","coach-document-upload","coach-items-link"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive or delegated independent assurance lead","ermPhase":"identify","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"confirm-trigger-and-boundaries"},{"data":{"controls":["UC-AI-01","UC-AI-02","UC-AI-13","UC-AI-04","UC-AI-05","UC-AI-09","UC-AI-03","UC-AI-06","UC-AI-14","UC-AI-07","UC-AI-08","UC-AI-10","UC-AI-11","UC-AI-12","UC-AUDIT-21"],"description":"Assess the integrated AIMS test evidence, resolve contradictory findings and authorize the independent conclusion and report release.","instructions":"**Objective** — Complete the scoped AIMS control tests and issue an independently approved conclusion with management responses, limitations and follow-up ownership.\n\n**Inputs**\nThe approved AI policy and objectives, governance charters and meeting records, role descriptions, competency and training records, committee decisions, supplier and customer responsibility agreements, and the current organizational and AI value-chain maps.\n\nThe AI risk methodology and register, sampled impact assessments and classifications, intended-use statements, responsible-AI objectives, data provenance and quality records, deployment approvals, and prior risk decisions.\n\nSystem cards and technical files, model or component inventories, data and compute dependency records, change history, supplier and customer agreements, security and privacy assessments, monitoring specifications, and the approved document-retention procedure.\n\nRelease and change records, validation and verification results, approval decisions, production logs, monitoring dashboards, alert thresholds, incident records, rollback or suspension procedures, and the sampled operating period.\n\nUser and customer notices, transparency records, acceptable-use and responsible-use policies, human-oversight procedures, complaint and concern channels, incident and external-reporting records, legal review evidence, and sampled interactions or outcomes.\n\nThe value-chain inventory, supplier and customer agreements, due-diligence and ongoing-monitoring records, third-party test or assurance reports, issue registers, service changes, and escalation records.\n\nAll workpapers and test results, the criteria matrix, prior findings, management responses, compensating controls, risk ratings, and the approved internal-audit reporting protocol.\n\nThe approved conclusion and finding register, management responses, distribution list, open Issue records, follow-up dates, retention requirements, and the engagement's scope and independence record.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Independent AIMS engagement reviewer and authorized Chief Audit Executive or audit committee owns the stated judgments and authorizations.*\n\n*Evaluate AIMS Governance and Responsibilities.* Determine whether AIMS governance gives accountable people the authority, competence, resources, and oversight needed to direct responsible AI.\n\n1. Trace policy approval, periodic review, objectives, and management oversight from the governing body through the accountable AIMS roles.\n2. Sample role assignments and competency evidence for people who approve, build, deploy, monitor, or review AI systems.\n3. Check that responsibilities at each relevant value-chain hand-off are explicit, including provider, deployer, customer, and supplier obligations.\n4. Compare governance practice to the approved policy and record deviations, compensating arrangements, and evidence gaps.\n\n*Assess AI Risk, Impact, and Objectives.* Establish whether the organization identifies and evaluates AI risks and impacts before deployment and maintains objectives that address the results.\n\n5. Select representative systems across risk classes, lifecycle stages, and material value-chain relationships.\n6. Reperform the link from intended purpose and affected stakeholders to identified risks, impacts, treatment objectives, and approval decisions.\n7. Test whether data quality, provenance, preparation, and known limitations are documented and considered in the risk decision.\n8. Check that risk acceptance, treatment, escalation, and reassessment triggers are explicit and that changes re-enter the assessment where required.\n\n*Inspect AI Documentation, Resources, and Suppliers.* Test whether the AIMS retains enough current technical, resource, dependency, and supplier documentation for an independent reviewer to understand and challenge the system.\n\n9. For each sample, reconcile the system's intended purpose, version, data sources, components, dependencies, operators, and external providers to the inventory and technical documentation.\n10. Inspect whether documentation explains limitations, assumptions, evaluation evidence, operating context, and the changes that triggered reassessment.\n11. Test supplier and customer obligations against contracts, due diligence, service evidence, escalation paths, and received assurance.\n12. Check version control, retention, access, and review dates; distinguish an absent document from a document that exists but does not support the control objective.\n\n*Test Deployment, Change, and Operational Monitoring.* Determine whether sampled AI systems are validated before use, controlled when changed, and monitored with evidence that supports timely intervention.\n\n13. Select new deployments and material changes from the period and trace each from request through testing, approval, release, and post-release observation.\n14. Reperform selected validation and verification checks against the approved acceptance criteria; record the environment, version, sample, and result.\n15. Test whether logs capture the events needed to investigate behavior and whether monitoring thresholds, ownership, escalation, and response timing are defined.\n16. Inspect exceptions, overrides, rollback, suspension, or retraining decisions and verify that they were authorized and recorded.\n\n*Test Transparency, Lawful Use, and Incident Channels.* Determine whether the organization communicates AI use and limitations, constrains prohibited or irresponsible use, and can receive, investigate, and report concerns.\n\n17. Sample deployed experiences and compare the notice, disclosure, documentation, and user controls to the approved intended use and risk classification.\n18. Test a sample of prohibited-use or policy-violation detections, human escalations, overrides, and decisions, preserving the distinction between a system suggestion and a human decision.\n19. Trace concerns and incidents from intake through triage, investigation, notification, corrective action, and closure; verify timeliness and evidence retention.\n20. Where an AIUC-1 crosswalk row is used, document the exact overlapping objective and any residual requirement rather than treating the crosswalk as equivalent certification criteria.\n\n*Test Value-Chain Accountability and Assurance.* Confirm that value-chain responsibilities, supplier oversight, customer commitments, and received assurance are tested where external parties can change the AI risk.\n\n21. Select external relationships by risk, materiality, change, and reliance on provider controls.\n22. Trace each selected relationship from responsibility assignment through due diligence, contract commitments, evidence receipt, performance monitoring, and issue escalation.\n23. Compare external evidence to the organization's own AIMS assumptions; record residual gaps where a supplier report does not cover the needed objective or period.\n24. Check that management has accepted or treated residual risk and that audit retains an independent conclusion about the evidence, without accepting the supplier's assertion uncritically.\n\n*Formulate Findings and Independent Conclusion.* Convert the completed test work into evidence-backed findings, a balanced conclusion, and a remediation follow-up plan.\n\n25. Reconcile every test result to the selected control, evidence reference, period, sample, and conclusion; resolve contradictions before drafting.\n26. Classify exceptions using the approved severity and root-cause criteria. Distinguish an isolated deviation, design deficiency, operating deficiency, and cross-cutting AIMS weakness.\n27. Draft each finding with condition, criteria, cause, effect or risk, evidence, owner, target date, and proposed validation approach. Do not prescribe management's treatment where alternatives are possible.\n28. Hold a factual-accuracy discussion with management, record disagreements and changes, and preserve the auditor's independent judgment.\n29. Draft the conclusion on the scoped AIMS objectives and state exclusions, limitations, reliance, and the qualification that the work is an internal-audit engagement rather than certification.\n\n*Issue the Report and Close the Engagement.* Close the engagement with a durable evidence package, an approved internal-audit report, and visible follow-up ownership.\n\n30. Confirm that the report states the objective, scope, criteria, period, methods, evidence limitations, findings, management responses, and conclusion clearly.\n31. Obtain the required chief audit executive or audit committee release approval while keeping approval of remediation with management.\n32. Deliver the report to authorized recipients, record the release date, and create the follow-up checkpoints for open findings.\n33. Export and retain the scope, workpapers, evidence index, decisions, report, and immutable references according to the approved retention rule.\n\n**Record in AssureSwarm**\nAttach the governance test matrix and meeting evidence to the Audit item. Link each tested responsibility and unresolved gap to the relevant unified controls and accountable owner.\n\nAttach the sample register, reperformance notes, and criteria-to-evidence matrix. Link material gaps to the relevant Risk and Issue records with the sampled system, control, date, and owner.\n\nAttach a documentation reconciliation workbook and source references. Link each missing or stale artifact to an Issue and to the affected Control or Risk.\n\nAttach test sheets, log extracts, monitoring evidence, and change references. Link failed attributes to the relevant Issue and record the affected release or system version.\n\nAttach the disclosure sample, incident trace, and concern-channel test sheet. Link issues to affected controls and risks, with the event date, evidence reference, owner, and next action.\n\nAttach the value-chain sample matrix and received assurance. Link residual gaps to the supplier, risk, control, and Issue records, preserving the relationship and evidence period.\n\nCreate or update Issue records for agreed findings, attach the conclusion memo and management responses, and link each finding to the tested controls and risks.\n\nMark the Audit item complete, link the issued report and exported evidence package, and ensure every open Issue has an owner, target date, and follow-up relationship.\n\n**Exit criteria**\nGovernance and responsibility tests have a documented result, evidence sources are traceable, and each exception has a precise condition, owner, and proposed next action.\n\nEach sampled system has a traceable risk and impact conclusion, data evidence is sufficient for the stated decision, and gaps are classified without the auditor making management's treatment decision.\n\nSampled documentation and dependencies reconcile to the boundary, supplier evidence is evaluated, and every material gap has a reproducible reference and accountable owner.\n\nEvery selected release and operating sample has a test result with evidence, monitoring and escalation are traceable, and any deficiency is described precisely enough for management to remediate and for audit to retest.\n\nTransparency and lawful-use tests have traceable evidence, human escalation is visible, concern and incident paths are reperformable, and reporting gaps are classified for management response.\n\nThe selected value-chain relationships have current responsibility and assurance evidence, residual reliance gaps are explicit, and any required management treatment has an owner and due date.\n\nThe reviewer approves a complete finding register and independent conclusion, disagreements and limitations are visible, and actions have accountable owners and validation dates.\n\nThe report and evidence package are retrievable, authorized recipients are recorded, open actions are visible for follow-up, and the engagement is closed without implying external certification.","kind":"task","label":"Formulate Findings and Independent Conclusion","performedBy":{"note":"The agent reconciles role and governance evidence. The independent reviewer decides whether the evidence supports the control conclusion. The agent prepares samples and traces evidence. The independent reviewer assesses sufficiency and records the assurance result. The agent reconciles authorized records and prepares the workpaper. The independent reviewer evaluates completeness and relevance. The agent gathers release and monitoring evidence. The independent reviewer re-performs selected tests and signs the result. The agent assembles samples and traces records. The independent reviewer evaluates the control result and protects the distinction between assurance and management action. The agent indexes contracts and assurance evidence. The independent reviewer determines whether reliance is supportable. The agent reconciles workpapers and drafts the report. The independent reviewer owns the assurance conclusion and management retains treatment decisions. The agent packages and links the approved record. The chief audit executive or audit committee releases the report and management owns remediation.","primitives":["coach-query-data","coach-document-upload","coach-items-link","coach-workflow-export"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive or delegated independent assurance lead","ermPhase":"report","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"formulate-findings-and-conclusion"}],"sourceTemplateId":"workflow-library:audit-iso42001-aims-internal-audit"}
