Q: 19
[Managing an ISO/IEC 42001 Audit Program]
Scenario 9 (continued):
Scenario 9: Securisai, located in Tallinn.Estonia, specializes in the development of automated
cybersecurity solutions that utilize AIsystems. The company recently implemented an artificial
intelligence management system AIMS in accordance with ISO/IEC 42001. Indoing so, the company
aimed to manage its Al-driven systems’ capabilities to detect and mitigate cyber threats more
efficiently andethically. As part of its commitment to upholding the highest standards of Al use and
management, Securisai underwent a certificationaudit to demonstrate compliance with ISO/IEC
42001.
The audit process comprised two main stages: the initial or stage 1 audit focused on reviewing
Securisai's documentation, policies, andprocedures related to its AIMS. This review laid the
groundwork for the stage 2 audit, which involved a comprehensive, on-site evaluation
of the actual implementation and effectiveness of the AIMS within Securisai's operations. The goal
was to observe the AIMS in operation,ensuring that it not only existed on paper but was effectively
integrated into the company's daily activities and cybersecurity strategies.
After the audit, Roger, Securisai's internal auditor, addressed the action plans devised to rectify
nonconformities identified during thecertification audit. He developed a long term strategy,
highlighting key AIMS processes for triennial audits. Roger's internal audits play a
key role in advancing Securisai's goals by employing a systematic and disciplined method to assess
and boost the efficiency of risk
management, governance processes, and strategic decision-making. Roger reported his findings
directly to Securisai's top management.
Following the successful rectification of nonconformities, Securisai was officially certified against
ISO/IEC 42001.
Recently, the company decided to transfer its ISO/IEC 42001 certification registration from
onecertification body to another despitebeing initially bound by a long-term agreement with the
current certification body. This decision was motivated by the desire to partnerwith a certification
body that offers deeper insights and expertise in the rapidly evolving field of artificial intelligence in
cybersecurity.
To ensure a smooth transition and uphold its certification status, Securisai is diligently compiling the
required documentation forsubmission to the new certification body. This includes a formal request,
the most recent audit report underscoring its adherence toISO/IEC 42001, the latest corrective action
plan that highlights its continuous efforts toward improvement, and a copy of its current
validcertification registration.
A year following Securisai's initial certification audit, a subsequent audit was carried out by the
certification body on its AIMS. The
purpose of this audit was to assess compliance with ISO/IEC 42001 and verify the ongoing
improvement of the AIMS. The audit team
concluded that Securisai's AIMS consistently meets the requirements set by ISO/IEC 42001.
What type of audit is described in the last paragraph of Scenario 9?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.