Management + processes + supporting registers. Everything needed for a full, certifiable ISO/IEC 42001 AIMS.
Shared library: Process Registry, Annex A catalog, traceability spine, completeness scoring, menu ordering, Merkle helpers, navigation patches.
Central evidence engine. 5 PDCA phases, 39 diagram boxes, governance gates, context/stakeholder registers, automatic evidence aggregation from all processes.
Structured 3-tab understanding records for 4.1 (context), 4.2 (interested parties), 4.3 (scope). Verbatim clause guidance + evidence fields.
AI risk assessment, Statement of Applicability (SoA), risk treatment, impact assessment (6.1.4), and Annex A control mapping.
Controlled change management with full audit trail, QMS logs, and integration to the AIMS hub change box.
Supplier lifecycle, GPAI/LLM vendor due diligence, acceptance evaluation, ongoing monitoring and evidence packages.
Operational planning, risk assessment/treatment during operation, impact assessment, and runtime controls.
AI system lifecycle processes per ISO/IEC 5338/5339. Design, development, validation and deployment phases.
Documented information register, competence & training tracking, version control integration.
Data quality, lineage, management processes aligned with ISO/IEC 5259 and 8183 series.
Performance monitoring, measurement, incidents, personal data breaches, post-market surveillance.
Internal audit programme, four-stage workflow, findings, and automatic CAPA creation.
Management review inputs/outputs with twelve-sub-process workflow and decision recording.
Continual improvement register + full CAPA (nonconformity & corrective action) lifecycle.
AI system inventory, components, business processes, personal data elements. The traceability spine.
Legal, regulatory and contractual obligations register feeding context and risk processes.
Mandatory documented information matrix and centralized record catalogue.
Strategic objectives, KPIs and performance targets linked across all AIMS clauses.
ISO-oriented conformity dashboard with cross-regulatory bridge (EU AI Act QMS, etc.).
Runtime technical and organizational controls (often used as a lightweight facade layer).