{
  "schema": "yarn-pack/2",
  "id": "framework-iso42001",
  "version": "0.1.0",
  "name": "ISO/IEC 42001 (framework self-assessment)",
  "engagement": "AISG — framework self-assessment: workshop prep, workshop, or diagnostic strand",
  "intro": "A guided conversation against ISO/IEC 42001, not a form. Answer in your own words and name the document or record that shows it if you can. About 24 minutes. Assesses the organisation’s AI management system against the audited Clauses 4 to 10, plus selected Annex A objectives and the two distinctive mechanisms. It does not test or certify models, nor judge legal compliance.",
  "tone_default": "professional",
  "prefill_fields": {
    "department": [
      "Executive",
      "Finance",
      "Operations",
      "Customer / Sales",
      "Technology / IT",
      "Data & Analytics",
      "People & Culture",
      "Risk & Compliance",
      "Marketing",
      "Product"
    ]
  },
  "scales": [
    {
      "id": "maturity5",
      "name": "Maturity (distilled model)",
      "levels": [
        {
          "value": 1,
          "label": "Does not exist",
          "gloss": "No capability. Absent, or purely ad hoc / accidental."
        },
        {
          "value": 2,
          "label": "Partially exists",
          "gloss": "Emerging and inconsistent. Pockets of activity, not joined up."
        },
        {
          "value": 3,
          "label": "Fully exists",
          "gloss": "Defined, documented and operating across the organisation."
        },
        {
          "value": 4,
          "label": "Fully exists & optimised",
          "gloss": "Measured, refined and improving against targets."
        },
        {
          "value": 5,
          "label": "Fully exists & adaptive",
          "gloss": "Continuously self-adjusting; a source of advantage."
        }
      ],
      "signals": {
        "1": [
          "no ",
          "not ",
          "none",
          "never",
          "don't",
          "do not",
          "nothing",
          "absent",
          "unaware",
          "haven't",
          "ad hoc",
          "ad-hoc",
          "nonexistent",
          "no idea",
          "not really"
        ],
        "2": [
          "some ",
          "starting",
          "beginning",
          "emerging",
          "pilot",
          "trial",
          "informal",
          "inconsistent",
          "pockets",
          "a bit",
          "occasionally",
          "early",
          "experiment",
          "trying",
          "patchy"
        ],
        "3": [
          "documented",
          "defined",
          "standard",
          "standardised",
          "established",
          "policy",
          "framework",
          "process",
          "consistent",
          "across the",
          "in place",
          "formal",
          "governed",
          "rolled out"
        ],
        "4": [
          "measured",
          "metrics",
          "optimis",
          "improving",
          "kpi",
          "monitored",
          "reviewed",
          "refined",
          "benchmarked",
          "targets",
          "tracked",
          "mature",
          "regularly review"
        ],
        "5": [
          "continuous",
          "adaptive",
          "self-",
          "automated end",
          "best in class",
          "best-in-class",
          "competitive advantage",
          "industry leading",
          "always",
          "real-time monitoring",
          "feedback loop"
        ]
      }
    }
  ],
  "categories": [
    {
      "id": "system",
      "name": "Management system",
      "order": 1,
      "target_default": 3
    },
    {
      "id": "annex",
      "name": "Annex A and mechanisms",
      "order": 2,
      "target_default": 3
    }
  ],
  "audiences": [
    {
      "id": "lead",
      "name": "Governance / risk lead",
      "desc": "Owns the policy, the register or the risk framework",
      "deep_dive_sections": []
    },
    {
      "id": "owner",
      "name": "System or use-case owner",
      "desc": "Runs an AI system or use case day to day",
      "deep_dive_sections": []
    },
    {
      "id": "exec",
      "name": "Executive / sponsor",
      "desc": "Accountable for the outcome, not the mechanics",
      "deep_dive_sections": []
    }
  ],
  "sections": [
    {
      "id": "core",
      "title": "42001 elements",
      "blurb": "Everyone answers these. Top management or the executive sponsor for AI, the AI policy and risk owners, the data and platform leads, internal audit, and whoever manages AI vendors and contracts.",
      "optional": false,
      "questions": [
        {
          "id": "cl4",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 4: Context of the organisation",
          "text": "If an auditor asked which parts of your organisation and which AI systems your management system covers, what would you hand them, and who would you say cares about how you use AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No defined scope for the AIMS; no record of which AI systems, parties or expectations it covers.",
            "3": "A documented AIMS scope names the AI systems and parts of the organisation covered, with interested parties and their expectations recorded and current.",
            "5": "The scope and interested-party register are re-examined on a set cadence and whenever a new AI system, party or regulation appears, with changes recorded."
          },
          "help": "Evidence that would show it: Documented AIMS scope statement; Register of interested parties and their expectations; AI system inventory tied to the scope.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "cl5",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 5: Leadership",
          "text": "Who at the top of the organisation owns AI here, what have they signed, and if a decision about an AI system landed on the wrong desk, how would people know whose desk it should be?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No AI policy exists; no executive is named as accountable for AI; roles are informal or unassigned.",
            "3": "An approved AI policy is in place, top management has visibly endorsed it, and named people hold documented AIMS roles, responsibilities and authorities.",
            "5": "The AI policy and role assignments are reviewed by top management on a set cadence and changed when the organisation, its AI use or its obligations change."
          },
          "help": "Evidence that would show it: Approved AI policy with an executive signature; Charter of the AI steering body; RACI or roles register for AI decisions.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "cl6",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 6: Planning",
          "text": "Walk me through how you decided which AI risks matter here and what you do about them. What are you trying to achieve with AI this year, and how would you know you got there?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No AI risk assessment has been done; no AI objectives are set; no Statement of Applicability exists.",
            "3": "An AI risk assessment and treatment plan are documented, AI objectives are set and measurable, and the Statement of Applicability records the controls chosen and why.",
            "5": "Risk assessment, objectives and the Statement of Applicability are updated on triggers and cadence, and treatment results feed the next planning cycle."
          },
          "help": "Evidence that would show it: AI risk assessment and treatment plan; AI objectives with measures and owners; Statement of Applicability.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "cl7",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 7: Support",
          "text": "Who works on your AI systems, how do you know they have the skills, and how would a new starter find out what the organisation expects of them around AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No dedicated resources or competence requirements for AI roles; staff are unaware of the AI policy; AIMS documents are missing or uncontrolled.",
            "3": "Competence needs for AI roles are defined and met, staff know the AI policy and their part in it, communication is planned, and AIMS documents are controlled.",
            "5": "Competence gaps and awareness are measured and closed on a cycle, and documented information is kept current through a controlled change process."
          },
          "help": "Evidence that would show it: Competence and training records for AI roles; AI awareness material and completion records; Document control register for AIMS records.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "cl8",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 8: Operation",
          "text": "Take one AI system you rely on. Show me how it got from idea to production, who signed off at each step, and what you checked about its effects on people before it went live.",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "AI systems are built and used without controlled processes; no operational risk assessment or impact assessment takes place.",
            "3": "Documented operational controls govern AI systems across their life cycle, with risk assessment, treatment and impact assessment carried out and recorded per system.",
            "5": "Operational controls are adjusted from monitoring and incident results, and changes to an AI system trigger a fresh risk and impact assessment on their own."
          },
          "help": "Evidence that would show it: Lifecycle procedures with stage gates; Use case intake and register records; Completed impact assessments per AI system; AI incident response procedure.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "cl9",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 9: Performance evaluation",
          "text": "When did someone last check that your AI controls are actually operating, not just written down, and what did top management do with what they found?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No monitoring of AIMS performance; no internal audit has been carried out; top management has not reviewed the system.",
            "3": "Monitoring results are recorded, an internal audit programme runs at planned intervals, and management review minutes show inputs, decisions and actions.",
            "5": "Audit and review findings change the monitoring set and the audit programme itself, and results are compared across cycles to show the trend."
          },
          "help": "Evidence that would show it: Internal audit programme and reports; Management review minutes; Monitoring and measurement results; Board or audit committee reporting.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "cl10",
          "type": "scored_text",
          "category": "system",
          "name": "Clause 10: Improvement",
          "text": "Tell me about the last time an AI system did something it should not have. What was recorded, what was fixed, and what is different now so it does not happen again?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "Nonconformities and AI incidents are not recorded; nothing changes in the system after a failure.",
            "3": "Nonconformities are logged with root cause and corrective action, closure is verified, and a record shows the AIMS being improved from audit and review results.",
            "5": "Corrective actions are checked for recurrence across systems, and improvement is driven from trends in incidents, audits and reviews rather than single events."
          },
          "help": "Evidence that would show it: Nonconformity and corrective action log; AI incident register with lessons learned; Continual improvement record.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "aisia",
          "type": "scored_text",
          "category": "annex",
          "name": "AI system impact assessment (A.5)",
          "text": "Before an AI system goes live here, how do you work out who it could affect and how, and where does that thinking end up once the system is running?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No impact assessment process exists; the effects of AI systems on people are not examined before or after deployment.",
            "3": "A repeatable impact assessment template is applied to each AI system in scope, with the results recorded and the controls selected from them.",
            "5": "Impact assessments are re-run when a system, its use or its context changes, and their findings adjust the risk register and control set without prompting."
          },
          "help": "Evidence that would show it: Impact assessment template; Completed impact assessments per AI system; Record linking assessment results to controls.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "soa",
          "type": "scored_text",
          "category": "annex",
          "name": "Statement of Applicability",
          "text": "If I picked any one of the 38 Annex A controls at random, could you show me whether it applies to you, why, and who looks after it?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No Statement of Applicability exists; there is no record of which controls were chosen or excluded.",
            "3": "A current Statement of Applicability lists every Annex A control with its status, a justification tied to the risk assessment, and an owner for each applied control.",
            "5": "The Statement of Applicability is updated whenever the risk assessment changes, and each applied control carries evidence that it is operating."
          },
          "help": "Evidence that would show it: Statement of Applicability; Controls library with owners and verification method; Risk register entries cited as justification.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "data",
          "type": "scored_text",
          "category": "annex",
          "name": "Data for AI systems (A.7)",
          "text": "For the AI system you use most, where does its data come from, who owns that data, how do you know it is fit for the purpose, and what happens when it changes?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "No record of what data AI systems use, where it came from or its quality; data preparation is undocumented.",
            "3": "Each AI system’s data is documented for source, provenance, quality and preparation, with an owner for the data and rules on what may be used.",
            "5": "Data quality and provenance are monitored in operation, and changes or withdrawals in source data propagate to the AI systems that depend on them."
          },
          "help": "Evidence that would show it: Data provenance and quality records per AI system; Corpus register with content owners; Tested data-access enforcement evidence.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "use",
          "type": "scored_text",
          "category": "annex",
          "name": "Use of AI systems (A.9)",
          "text": "Who is watching your AI systems day to day, what would they see if one started behaving oddly or being used for something it was not meant for, and what could they do about it?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "Intended use is not written down; no human oversight is defined; nobody monitors how AI systems behave in operation.",
            "3": "Each AI system has a documented intended use, a defined human oversight model with rationale, and operational monitoring with a named owner.",
            "5": "Monitoring detects use outside intent or drifting behaviour, and the oversight model is adjusted from what monitoring and incidents show."
          },
          "help": "Evidence that would show it: Human oversight model per use case; Model card or equivalent stating intended use; Operational monitoring records.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        },
        {
          "id": "third",
          "type": "scored_text",
          "category": "annex",
          "name": "Third-party and customer relationships (A.10)",
          "text": "Which of your AI comes from someone else, what did you agree with them about how it is used and changed, and who is on the hook if it goes wrong for a customer?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "rubric": {
            "1": "Vendor-supplied or embedded AI is not identified; contracts are silent on AI; no one knows who is responsible for what in the supply chain.",
            "3": "A register lists vendor and embedded AI, contracts carry AI clauses, and responsibilities between the organisation, its suppliers and its customers are documented.",
            "5": "Vendors notify material changes through an agreed process, the register is updated from those notices, and responsibility allocations are reviewed at renewal."
          },
          "help": "Evidence that would show it: Vendor and third-party AI register; AI clauses in supplier contracts; Material change notification process.",
          "adaptive": {
            "allow_probe": true,
            "allow_skip": false,
            "max_probes": 1
          },
          "ai_drafted": false
        }
      ]
    }
  ],
  "grids": {},
  "outputs": [
    "Level per element and per category, gated",
    "Contested-element view (spread of 2 or more)",
    "Coverage of evidence: confirmed, stated, inferred",
    "Where to start, foundations first",
    "Printable client report"
  ],
  "report_defaults": [
    "rpt-maturity-standard"
  ],
  "playbook": {
    "sequence": [
      "system",
      "annex"
    ],
    "sequence_note": "Most organisations do Clauses 4 to 8 and skip 9 and 10. That is a binder, not a management system. Build the spine first, then select Annex A controls through the risk assessment.",
    "actions": {
      "system": {
        "to_3": [
          "Define the AIMS scope and interested parties, and have top management approve an AI policy.",
          "Run an AI risk assessment, set AI objectives and issue a Statement of Applicability.",
          "Stand up internal audit and management review so Clauses 9 and 10 exist, not just 4 to 8."
        ],
        "to_5": [
          "Put scope, policy, risk assessment and the SoA on triggers and a cadence, with changes recorded.",
          "Use the surveillance-audit cadence to prove controls are operating, not just written."
        ]
      },
      "annex": {
        "to_3": [
          "Build a repeatable AI system impact assessment template and apply it to every system in scope.",
          "Lead with A.7 if data-mature, or A.5 and A.9 if model-anxious, then cover A.10 for vendor AI.",
          "Seed the risk register from Annex C and use Annex B guidance for each selected control."
        ],
        "to_5": [
          "Re-run impact assessments on change and let their findings adjust the control set.",
          "Monitor data provenance and system use in operation so drift and vendor changes surface on their own."
        ]
      }
    }
  }
}