Competence and awareness in the AIMS: meeting clauses 7.2 and 7.3 of ISO 42001

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

When preparing for ISO 42001 certification, most attention goes to the risk assessment, the AI policy and the Annex A controls. Chapter 7 tends to get left behind. That is a shame, because the requirements on competence (clause 7.2) and awareness (clause 7.3) produce nonconformities at audits surprisingly often. The question behind them is not optional either: who in your organisation is allowed to perform an AI risk assessment, and what shows that this person is able to? This article covers what both clauses require, which nonconformities we see in audit practice, and how a single programme can also cover the AI literacy obligation under Article 4 of the EU AI Act.

What clause 7.2 requires

In our own words, clause 7.2 comes down to four steps. Determine which competences are needed for work that affects the performance of the AI management system and the outcomes of AI systems. Ensure the people doing that work are demonstrably competent, based on education, training or experience. Take action where competences are missing and afterwards evaluate whether that action worked. And retain documented information as evidence.

Anyone who runs an ISO 27001 system knows these four steps; the wording runs in parallel. The difference is in the substance. For information security, an organisation usually knows what a security officer needs to know. For AI, that is far less settled. What does a product manager need to understand when commissioning an AI feature? What knowledge does someone need to review an impact assessment for societal consequences? That is where the work starts.

More roles than just the data scientist

The scope of 7.2 is work that affects the outcomes of AI systems. That is a wider group than the AI team. Think of the developers and engineers who build and train models. The people who run the AIMS and its governance. Product managers who decide which AI features get built. The colleagues who perform risk assessments and impact assessments; for that group in particular the standard expects knowledge of AI ethics, fairness and the evaluation of consequences for individuals and society. And the management that oversees AI systems and takes decisions about them.

The practical instrument is a competence matrix: per role, the required knowledge and skills, for example ML fundamentals, data management, bias detection, explainability and knowledge of AI regulation. Not every role needs everything. A board member does not need to be able to train a model, but should understand what a fairness metric says and what is at stake when it deteriorates. The matrix shows where the bar is and where the gaps are, and the training plan follows from it.

What clause 7.3 requires

Awareness is not the same as competence. Competence is about being able to; awareness is about knowing. Clause 7.3 requires that everyone working under the organisation's control knows three things: what the AI policy says, what their own contribution to the AIMS is, and what the consequences are of not conforming to its requirements. That last part is more concrete than it sounds. A developer should know that deploying a model without the agreed tests is not sloppiness but a nonconformity of the management system, with possible consequences for customers and affected individuals.

The audience for 7.3 is deliberately wider than for 7.2. The colleague who only uses an AI chatbot as a tool should also know that there is an AI policy and what it means for their work. In practice this means an awareness programme that reaches beyond the technical team: a module in onboarding, periodic communication when the policy changes or new AI systems go live, and some form of record that lets you show the message landed.

Nonconformities we often see

From our audit practice and the guidance in our internal audit module, a familiar list emerges. Competence requirements for AI roles are not defined anywhere; there is no matrix or framework. Training covers technology only and skips ethics, responsible AI and regulation. There are no records: training happened, but nobody can show who, when and in what. Training effectiveness is never evaluated, so nobody knows whether participants can apply the knowledge. And the people performing risk and impact assessments lack demonstrable knowledge of fairness and societal impact, even though their judgement is the foundation of the AIMS.

For 7.3, the most common finding is that awareness stays within the AI team and never reaches business users or managers. Or the policy comes up once during onboarding and never again. Activities are ad hoc, unplanned and unrecorded, which means there is nothing to show at the audit.

The link with AI literacy under the EU AI Act

Since 2 February 2025, Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy among their staff, tailored to their knowledge, role and context. In addition, Article 26(2) requires that human oversight of high-risk systems is assigned to persons with the necessary competence, training and authority.

If you set up 7.2 and 7.3 properly, most of these legal obligations are already covered. The competence matrix, training plan and records from the AIMS are exactly the evidence you would show a supervisory authority to demonstrate work on Article 4. The reverse also holds: an organisation that already built a literacy programme for the AI Act can bring that programme into the AIMS instead of building something new. One programme, two purposes.

What documents an auditor expects

For clause 7.2: a competence matrix or role profiles with AI competence requirements, a training plan, training records and certificates, and records showing that effectiveness was evaluated (test results, assessments or reviews). For clause 7.3: an awareness programme plan, completion records, acknowledgments of the AI policy and internal communications on AI governance, such as announcements when new systems or policy changes go live.

The interview questions follow the same line. How were competence requirements for AI roles determined? What training do the people performing risk assessments receive? How do you measure whether a training worked? And the litmus test for 7.3: can a random colleague outside the AI team explain that there is an AI policy and what it means for their work? If the answer is no, you know what the coming months look like.

The internal audit module of the Secure Audit platform contains the criterion, interview questions, an example of a good setup and the documents to have ready for 7.2 and 7.3. That way you can test whether this part of your AIMS is audit-proof before the auditor arrives. Get in touch for a no-obligation conversation.

Frequently asked questions

What is the difference between competence (7.2) and awareness (7.3)?+

Competence is about being able to: does someone have the education, training or experience to do the work well? Awareness is about knowing: does someone know the AI policy, their role in the AIMS and the consequences of nonconformity? The audience for 7.3 is wider and includes colleagues who only use AI.

Is our existing security awareness training enough for clause 7.3?+

Not without changes. The training must cover the AI policy, each person's contribution to the AIMS and the consequences of nonconformity. You can add AI awareness as a module to an existing awareness programme; that saves effort and works well in an integrated management system.

Which documents does an auditor expect for 7.2 and 7.3?+

For 7.2: a competence matrix or role profiles, a training plan, training records and evidence that effectiveness was evaluated. For 7.3: an awareness programme plan, completion records, policy acknowledgments and internal communications on AI governance.

Is AI literacy under Article 4 of the EU AI Act the same as competence under ISO 42001?+

They overlap strongly but are not identical. Article 4 is a legal obligation that has applied since 2 February 2025 to providers and deployers of AI systems. Clauses 7.2 and 7.3 are requirements for organisations running an AIMS. One programme with a competence matrix, training and records can cover both.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us