Resources, competence and awareness
Clause 7 requires the organization to provide the necessary resources for the AI Management System (AIMS), ensure that personnel performing AI-related roles are competent, and guarantee that all relevant staff are aware of the AIMS policies and their role within it. Essentially, you must prove you have the tools, the skills, and the internal communication to manage AI risks effectively.
What it means
In practice, this is about operational readiness. It moves beyond high-level policy into the actual capacity of your workforce and infrastructure. You cannot claim to manage AI risks if you lack the compute power, budget, or specialized expertise required to oversee those specific AI systems.
Competence focuses on "capability." The organization must identify exactly what skills are needed for roles that impact the AIMS—such as data scientists, ethics reviewers, or system administrators—and verify that the people in those roles actually possess those skills through education, training, or experience.
Awareness is broader than competence; it applies to everyone involved in the AI lifecycle. It ensures that employees understand the organization's AI policy and realize how their specific daily actions contribute to the success of the AIMS or could lead to systemic failures if ignored.
How to meet it
- Conduct a resource gap analysis to identify necessary hardware, software, budget, and personnel required to maintain the AIMS.
- Define a competence matrix that maps specific AI roles (e.g., Model Validator, Data Curator) to required qualifications or certifications.
- Implement a formal training program for technical staff focusing on AI-specific risks, bias mitigation, and the requirements of ISO/IEC 42001.
- Establish an awareness campaign—via newsletters, town halls, or intranet portals—to communicate the AI Policy and the objectives of the AIMS to all employees.
- Integrate AIMS awareness into the onboarding process for all new hires who will interact with AI systems.
- Create a mechanism to verify competence after training (e.g., assessments, peer reviews, or successful project delivery).
Evidence an auditor asks for
- Competence Records: CVs, certificates of completion for AI training, and professional certifications mapped to specific roles.
- Training Logs: Attendance sheets or digital logs showing who received AIMS awareness training and when.
- Resource Allocation: Budget approvals, cloud service contracts, or headcount authorizations dedicated to the AIMS.
- Role Descriptions: Job descriptions that explicitly list AI-related competencies as a requirement for the position.
- Communication Artifacts: Copies of emails, slide decks from orientation meetings, or screenshots of internal policy portals showing AI awareness materials.
Common pitfalls
- Generic Training: Relying on generic "Introduction to AI" courses rather than role-specific training that addresses your organization's specific AIMS controls.
- Assuming Competence: Assuming a person is competent because they have a degree, without documenting how that education maps to the specific requirements of your AI system.
- Ignoring Non-Technical Staff: Failing to provide awareness training to legal, HR, or procurement teams who may influence AI risk but aren't "AI experts."
- Lack of Records: Performing the necessary training and resource allocation but failing to maintain a centralized record that an auditor can review.