Learn to plan, conduct, and report AI Management System (AIMS) audits with confidence. A practitioner-led program covering ISO/IEC 42001 clauses, the 38 Annex A controls, and real audit simulations — taught by a certified ISO 42001 Lead Auditor.
Weekend & corporate batches available · Contact@AramGRC.com
Most AI governance courses stop at theory. This program is structured the way a real internal audit unfolds — from AI governance orientation to clause-by-clause review, controls testing, and nonconformity handling.
Every clause (4–10) is taught from the internal auditor's perspective — what to review, what evidence to request, and what "good" looks like.
No prior AI background required — Day 1 builds AI concepts, lifecycle, and ecosystem knowledge using ISO/IEC 22989 before auditing begins.
A dedicated session walks through Annex A control implementation using the Statement of Applicability (SoA) and Annex B guidance.
Role-play NC/observation write-ups, review real-style AI policies, risk registers, and audit templates in guided exercises.
Click a module to expand it. Every module is followed by hands-on practice — quizzes, policy and risk-process reviews, controls classification, gap assessments, and NC/observation role-play — so concepts are applied as you learn them, not just discussed.
Want the full session-by-session curriculum as a document?We're happy to send the detailed course outline for internal review or approvals.
Request Curriculum PDFA foundational understanding of ISO standards and working experience relating to IT / InfoSec / Privacy / GRC is a must. Basic AI concepts is helpful. No prior certification is required — Day 1 builds the AI and standards foundation before auditing begins.
This course is delivered by a certified ISO/IEC 42001 Lead Auditor with real implementation and audit experience — not a generic instructor reading standards text.
24 years in the IT industry across AI governance, privacy, and information security. Certified Lead Auditor for ISO/IEC 42001:2023, ISO/IEC 27001:2022, and ISO/IEC 27701:2019, and Certified Lead Implementer for ISO/IEC 42001:2023. Has led AI Management System implementations for multiple startups and delivered 15+ ISO 42001 training batches. Co-founder of AramGRC, an AI assurance consulting company specializing in independent AI audits, assessments, and testing.
This Internal Auditor course sits alongside AramGRC's structured curriculum — from foundational literacy to implementer and evaluator-level training.
Taught by a certified, practicing ISO 42001 Lead Auditor — not a generic corporate trainer.
Work with real-style policies, risk registers, SoA extracts, and internal audit templates during exercises.
Curriculum cross-references ISO/IEC 22989, 23894, and 42005 alongside ISO/IEC 42001 itself.
Weekend online and corporate/team formats designed for discussion, not passive lecture.
NC/observation role-play and gap-assessment exercises mirror what a real audit day looks like.
A 2-day, instructor-led program covering AI governance foundations, AI concepts and terminology (ISO/IEC 22989), and a clause-by-clause internal auditor's walkthrough of ISO/IEC 42001 — including Clauses 4–10 and the 38 Annex A controls — with hands-on exercises throughout.
You should have a foundational understanding of ISO standards and working experience in IT, InfoSec, Privacy, or GRC — that background is a must. Prior AI knowledge is helpful but not required: Day 1 is designed to bring everyone up to speed on AI concepts and the ISO/IEC 42001 structure before the auditing work begins. No prior audit certification is required.
Live, instructor-led sessions delivered online, with weekend batch options and corporate/team formats available. Contact us for the current schedule.
This Internal Auditor course focuses on auditing your own organization's AI Management System (first-party audits) — the clause interpretation, evidence review, and NC/observation handling skills you need internally. A Lead Auditor course additionally covers certification-body-level audit management and is typically pursued after internal audit experience.
Depends on what you hold today. If you're a Lead Implementer, yes — this course builds the internal auditor's lens on top of your implementation knowledge. If you're already a Lead Auditor, this course is largely redundant for you. If you hold neither, it's still valuable — it upskills your existing internal audit experience and extends its scope into the AI domain.
Yes. On successful completion of the course exam, you receive an ISO/IEC 42001 Internal Auditor certificate issued through an Exemplar Global–accredited certification body.
Email us at Contact@AramGRC.com and we'll share the next available batch dates, pricing, and corporate training options.
Join the next ISO/IEC 42001 Internal Auditor batch, or bring this training in-house for your team.