AI Management System
(AIMS) Audit

AISTA®  PROVE

SHOW THAT IT STANDS UP

An independent audit of your AI Management System against ISO/IEC 42001 — sampling real evidence, tracing it through the lifecycle, and reporting conformity without ambiguity.

ASSESS through an evidence-based lens

Scope

TEST THE CLAIM. SHOW THE PROOF.

Governance-and-Controls-Assessment

ISO/IEC 42001 Conformity

Audit your system against the standard's requirements, clause by clause.

Evidence-and-Traceability-Review

Lifecycle Traceability

Follow decisions and controls through the AI lifecycle, end-to-end.

Readiness-Prioritisation

Non-Conformance Findings

Report gaps precisely, with evidence supporting each finding.

ISO-42001-Gap-Analysis

Evidence Sampling

Examine real records rather than relying on stated intentions, using risk-based sampling.

AI-Lifecycle-Assessment

Control Effectiveness

Test whether controls operate as designed — not merely whether they exist.

Leadership-Perspective

Prioritised Improvement Schedule

Sequence remediation by materiality, not by ease.

Approach

HOW  PROVE  WORKS

1

Initiate the Audit

We make formal contact, confirm the audit objectives, scope and criteria with you, and establish that the audit is feasible: access, information, cooperation and time.

2

Plan and Prepare

We review your documented information, issue a risk-based audit plan, assign the audit team and prepare the working documents — including how evidence will be sampled.

3

Conduct the Audit

An opening meeting sets expectations, then evidence is collected and verified through interviews, observation and examination of records, with communication maintained throughout.

4

Determine Findings and Conclusions

Evidence is evaluated against the audit criteria to determine findings and conclusions. We present these at the closing meeting before the final audit report is issued.

5

Report the Audit

The audit report records the conformity position, non-conformities and conclusions, and is issued to the recipients agreed at initiation.

6

Complete the Audit

The audit closes when the planned activities are complete and the report distributed, with audit records retained as required.

7

Follow Up

Where the audit plan provides for it, we verify that corrective actions have been completed and are effective.

Outputs

WHAT IS FOUND. WHAT IT MEANS. WHAT NEXT?

Readiness-Report

Audit Report

  • Conformity Position
  • Non-Conformances
  • Observations
  • Evidence Index
Remediation-Roadmap

Findings & Decisions

  • Contextualised Findings
  • Materiality Assessment
  • Residual Risk Position
  • Recommended Actions
  • Report Acceptance
Senior-Leadership-Briefing

Improvement Schedule

  • Prioritised Remediation Plan
  • Ownership & Accountabilities
  • Target Closure Dates
  • Re-Audit Trigger Points

WHEN TO USE PROVE

WHEN CONFORMITY
NEEDS DEMONSTRATING

Before certification, to remove surprises from the certification audit.
When a client, regulator or board asks for independent confirmation.
To verify that remediation has genuinely closed previous findings.
On a defined cycle, to keep conformity current as AI use changes.
After significant changes to models, suppliers or use cases.

YOUR NEXT MOVE

Your Internal Audit — Done Independently

ISO/IEC 42001 requires internal audit at planned intervals.

We conduct yours in accordance with ISO 19011, through an impartial lens.

Contact Us

Start the Conversation

Office

124 City Road, Suite G4005, London, EC1V 2NX

Hours

M-F: 09:00 - 17:00
S-S: Closed