Compliance Certification Portal
The following AI systems are registered under the organisation's AI Management System (AIMS). Each asset is subject to ongoing risk classification and control obligations per ISO 42001 Clause 8.4. Click any row to review its mitigation controls.
| AI Asset | Primary Function | Risk Level | Owner | Status |
|---|
You are the designated AI Systems Lead. An employee has submitted the following request. Evaluate it against the organisation's AIMS policies and take the appropriate action.
An employee in the Infrastructure team wants to upload sensitive internal system architecture maps — including network topology data and server configurations — to a public, unapproved AI tool to automate documentation.
The tool is not on the organisation's approved AI register. No Data Protection Impact Assessment (DPIA) has been completed. The data is classified as CONFIDENTIAL under the organisation's information classification policy.
Permit the upload. The employee is senior and the productivity gain is significant.
Prevent the upload and formally escalate through the incident reporting channel.
Three questions covering core ISO 42001 compliance principles. Read carefully — detailed feedback is provided for each answer.
This certifies that
has successfully completed the training programme