Training module

Auditing AI Risk & Impact Management

Evaluate harm, impact and risk reasoning, intended use alignment, and decision traceability in ISO/IEC 42001

Artificial IntelligenceManagement System Auditor
Manager presenting AI risk and impact decisions to auditors in a meeting setting, representing auditing of AI risk and impact management, intended use alignment, and traceable decision-making under ISO/IEC 42001.

Does your audit move beyond paperwork to defensible, traceable AI risk and impact decisions?

AI risk and impact management is credible when it clearly connects intended use, affected stakeholders, and documented decisions to real controls and oversight. This module helps auditors test that chain and recognise where reasoning, traceability, or documentation breaks down in practice.

Overview

What this module is about

In ISO/IEC 42001 audits, weak AI risk and impact management rarely fails because an organisation used the wrong framework. It fails because the organisation cannot show a coherent line from intended use and stakeholders to impact reasoning, risk decisions, and documented acceptance of trade-offs. This creates false assurance: the system looks controlled on paper, while key harms, misuses, and operational realities remain unaddressed.

This standard-specific auditing module shows how to audit the quality of reasoning and documentation behind AI risk and impact decisions, without re-teaching generic risk methods or generic audit craft. It is designed to stand on its own in the ISO/IEC 42001 auditor pathway and is applicable to internal auditors and third-party auditors, including certification-body and independent assurance contexts.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

seek to audit the quality of AI risk and impact reasoning.

are aiming to judge alignment between intended use, impacts, and decisions.

focus on traceability from risk reasoning to documented controls.

are prepared to test whether decisions hold up under real use conditions.

expect to strengthen audit conclusions on AI risk governance.

It may not be the best fit if you…

prefer to design AI risk frameworks or impact assessment methods.

are looking for guidance on harm analysis or ethical risk modelling.

focus primarily on managing or mitigating AI risks yourself.

do not intend to audit AI risk and impact management under ISO/IEC 42001.

Agenda

What is taught

6 parts
01AI risk and impact management in an ISO/IEC 42001 audit

What auditors judge: coherence, traceability, and operational credibility of AI risk and impact decisions. Scope boundary: no generic risk frameworks, no audit-craft re-teaching.

02Testing harm and impact reasoning

Assesses whether harms and impacts are defined in a usable, decision-ready way (who/what is affected, how, why it matters), and whether severity, likelihood, and uncertainty are treated consistently and transparently.

03Intended use integrity and stakeholder alignment

Tests alignment between intended and actual use, including scope drift, misuse paths, and silent expansion via configuration or integration. Verifies that affected stakeholders and obligations were substantively considered, not just listed.

04Decision documentation quality

Evaluates decision records for rationale, trade-offs, approvals, and residual risk acceptance. Checks cross-document consistency across impact assessments, risk decisions, controls, monitoring triggers, and incident learning.

05Evidence trails, sampling focus, and red flags

Identifies where evidence actually sits in governance routines and operational records. Flags template compliance, post-hoc rationales, unowned residual risks, and undocumented trade-offs.

06Case-based audit simulation

Applying the learned concepts, methods, and approaches in a realistic case setting

Outcomes

Learning outcomes

01

Evaluate whether harm/impact reasoning is specific, complete enough for decisions, and consistent across artefacts

02

Test traceability from intended use and stakeholder considerations to impact assessment, risk decisions, and controls

03

Assess whether risk and impact decisions are documented in a way that supports accountability and later review

Identify and prioritise evidence sources that demonstrate real operation (not just planned intent)

Recognise common ISO/IEC 42001 risk/impact audit red flags that indicate false assurance

Define focused audit tests for decision quality without substituting for generic audit planning or interviewing techniques

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of Auditing AI Risk & Impact Management is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Auditing AI Risk & Impact Management · HAM-AI-A-01

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Auditing AI Risk & Impact Management · HAM-AI-A-01

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.