Is this you?

Are you a CTO, QA Manager, Tech Lead, Delivery Manager, Product Owner or Risk lead?

Signing off an AI product release is about to become the next big thing. Someone in your organisation will soon have to put their name against a release and say the model was tested, the risks were assessed, and the controls were in place. Right now, most teams have no defensible way to do that.

This program upgrades your skills so you can be the person who audits, challenges and signs off AI systems with evidence — not opinion.

Built for release sign-off owners

  • CTO / Head of Engineering
  • QA & Test Managers
  • Tech Leads
  • Delivery Managers
  • Product Owners
  • Risk & Compliance Managers
  • Internal Auditors
  • AI / ML Leads
  • CISO & Security Leads
  • Data & Privacy Officers

No prior AI background required — Day 1 builds the fundamentals before auditing begins.

2-day instructor-led program · hosted by AramGRC

ISO/IEC 42001 Internal Auditor Training

Learn to plan, conduct and report AI Management System (AIMS) audits with confidence. A practitioner-led program covering ISO/IEC 42001 clauses, the 38 Annex A controls and real audit simulations — taught by a certified ISO 42001 Lead Auditor.

Contact us for dates & pricing
Sakthi Thangavelu, ISO/IEC 42001 Lead Auditor and trainer

Your trainer

Sakthi ThangaveluLinkedIn profile

Co-Founder of AramGRC · AI Governance Consultant · ISO/IEC 42001 Lead Auditor · Trainer & Implementation Expert

24 years in the IT industry across AI governance, privacy and information security. Certified Lead Auditor for ISO/IEC 42001:2023, ISO/IEC 27001:2022 and ISO/IEC 27701:2019, and Certified Lead Implementer for ISO/IEC 42001:2023. Has led AI Management System implementations for multiple startups and delivered 15+ ISO 42001 training batches. Co-founder of AramGRC, an AI assurance consulting company specialising in independent AI audits, assessments and testing.

  • Lead Auditor — ISO/IEC 42001:2023
  • Lead Implementer — ISO/IEC 42001:2023
  • Lead Auditor — ISO/IEC 27001:2022
  • Lead Auditor — ISO/IEC 27701:2019
  • Certified Information & Privacy Manager (IAPP)
  • Certified Responsible AI Professional & FPT (OneTrust)

Why this course

Built for people who will actually run the audit

Most AI governance courses stop at theory. This program is structured the way a real internal audit unfolds — from AI governance orientation to clause-by-clause review, controls testing and nonconformity handling.

Auditor's-eye view

Every clause (4–10) is taught from the internal auditor's perspective — what to review, what evidence to request, and what “good” looks like.

AI fundamentals included

No prior AI background required — Day 1 builds AI concepts, lifecycle and ecosystem knowledge using ISO/IEC 22989 before auditing begins.

38 controls, deep dive

A dedicated session walks through Annex A control implementation using the Statement of Applicability (SoA) and Annex B guidance.

Simulation-based practice

Role-play NC/observation write-ups, review real-style AI policies, risk registers and audit templates in guided exercises.

Course curriculum

A 2-day, clause-by-clause audit journey

Every module is followed by hands-on practice — quizzes, policy and risk-process reviews, controls classification, gap assessments and NC/observation role-play — so concepts are applied as you learn them, not just discussed.

01

Day 1

Foundations & Clauses 4–6

Orientation to AI Governance

  • Frameworks and laws shaping AI governance
  • Enterprise-level, system-level and model-level governance
  • AI ethics principles

AI Concepts & Terminology (ISO/IEC 22989)

  • Core definitions
  • AI types and use cases
  • AI system life cycle
  • AI ecosystem
  • Machine learning concepts

Introduction to ISO/IEC 42001 Internal Auditing

  • Standard overview, clauses and controls
  • PDCA approach and annexure overview
  • Role of the internal auditor (before and after certification)

Clauses 4–6 Overview — the Internal Auditor's Point of View

  • Context of the organization
  • Reviewing certification scope and policy
  • Reviewing roles and responsibilities
  • Risk assessment (ISO/IEC 23894) and impact assessment (ISO/IEC 42005)
  • Reviewing AI objectives

Day 1 closes with a recap, open Q&A and clarifications before moving into Day 2.

02

Day 2

Clauses 7–10, Controls & Audit Practice

Clause 7 Overview

  • Reviewing AI system, model and tool inventories
  • Reviewing competence, communication and awareness

Clause 8 Overview

  • Operational planning — reviewing process KPIs / benchmarks
  • Reviewing sampling scope and coverage

ISO/IEC 42001 — 38 Controls Deep Dive

  • Reviewing control implementation using the Statement of Applicability (SoA)
  • Annex B controls guidance

Clauses 9 & 10 Overview

  • Reviewing KPIs for the AI system life cycle
  • Internal audit requirements
  • Reviewing management review records
  • NC and observation lifecycle walkthrough

Day 2 — and the program — closes with a recap, open Q&A, clarifications and course wrap-up.

Learning outcomes

What you'll be able to do after this course

  • Independently plan and conduct an internal audit of an AI Management System (AIMS) — from audit planning and sampling through evidence review to reporting.
  • Audit across every level and focus area that matters for AI — enterprise, system and model-level governance; AI life-cycle checks; and data-, safety-, security- and privacy-focused audits.
  • Explain AI governance frameworks and where ISO/IEC 42001 fits at the enterprise, system and model level.
  • Apply core AI concepts and terminology (ISO/IEC 22989) confidently during an audit.
  • Interpret ISO/IEC 42001 Clauses 4–10 and the PDCA structure from an auditor's perspective.
  • Review AI risk and impact assessments aligned to ISO/IEC 23894 and ISO/IEC 42005.
  • Evaluate Annex A control implementation using the SoA and Annex B guidance.
  • Manage the NC/observation lifecycle end-to-end, from raising findings to closure.

Who should attend

Built for these roles

  • Internal & external auditors
  • AI governance & compliance managers
  • Risk & compliance officers
  • Expert advisors & consultants
  • Business & risk analysts
  • AI solution owners / architects

Prerequisites

A foundational understanding of ISO standards and working experience relating to IT / InfoSec / Privacy / GRC is a must. Basic AI concepts are helpful. No prior certification is required — Day 1 builds the AI and standards foundation before auditing begins.

Certification

On successful completion of the course exam you receive an ISO/IEC 42001 Internal Auditor certificate issued through an Exemplar Global-accredited certification body.

Why AramGRC

Part of a broader AI GRC learning ecosystem

This Internal Auditor course sits alongside AramGRC's structured curriculum — from foundational literacy to implementer and evaluator-level training.

01

Practitioner-led

Taught by a certified, practising ISO 42001 Lead Auditor — not a generic corporate trainer.

02

Audit-ready templates

Work with real-style policies, risk registers, SoA extracts and internal audit templates during exercises.

03

Standards-aligned

Curriculum cross-references ISO/IEC 22989, 23894 and 42005 alongside ISO/IEC 42001 itself.

04

Small, interactive batches

Weekend online and corporate/team formats designed for discussion, not passive lecture.

05

Simulation-based

NC/observation role-play and gap-assessment exercises mirror what a real audit day looks like.

Browse all programs on the Learn page.

FAQ

Common questions

What does this course cover?

A 2-day, instructor-led program covering AI governance foundations, AI concepts and terminology (ISO/IEC 22989), and a clause-by-clause internal auditor's walkthrough of ISO/IEC 42001 — including Clauses 4–10 and the 38 Annex A controls — with hands-on exercises throughout.

Do I need prior AI or auditing experience?

You should have a foundational understanding of ISO standards and working experience in IT, InfoSec, Privacy or GRC — that background is a must. Prior AI knowledge is helpful but not required: Day 1 brings everyone up to speed on AI concepts and the ISO/IEC 42001 structure before the auditing work begins. No prior audit certification is required.

How is the course delivered?

Live, instructor-led sessions delivered online, with weekend batch options and corporate/team formats available. Contact us for the current schedule.

What's the difference between this and a Lead Auditor course?

This Internal Auditor course focuses on auditing your own organization's AI Management System (first-party audits) — clause interpretation, evidence review and NC/observation handling. A Lead Auditor course additionally covers certification-body-level audit management and is typically pursued after internal audit experience.

I'm already an ISO/IEC 42001 Lead Auditor or Lead Implementer — does this course still help?

If you are a Lead Implementer, yes — this course builds the internal auditor's lens on top of your implementation knowledge. If you are already a Lead Auditor, it is largely redundant. If you hold neither, it upskills your existing internal audit experience and extends its scope into the AI domain.

Will I get a certificate?

Yes. On successful completion of the course exam you receive an ISO/IEC 42001 Internal Auditor certificate issued through an Exemplar Global-accredited certification body.

How do I enrol or get batch dates and pricing?

Email Contact@AramGRC.com and we'll share the next available batch dates, pricing and corporate training options.

Ready to audit AI with confidence?

Join the next ISO/IEC 42001 Internal Auditor batch, or bring this training in-house for your team.

Corporate batches available

WhatsApp