Checklist for Clause 6.3 of ISO/IEC 42001 (AIMS): Planning of Changes
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 6.3 of ISO/IEC 42001 - Planning of Changes, developed directly from the PECB auditing slides shared and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.
This checklist ensures changes to the AIMS are identified, assessed, planned, approved, implemented, and controlled without introducing unmanaged AI risk.
2. ISO/IEC 42001 - Clause 6.3: Planning of Changes
Audit Checklist (Change Identification, Assessment & Control)
| # | Clause 6.3 Requirement Area | Audit Objective | Audit Questions (Checklist) | Expected Evidence | Conformance (Y/N/Partial) | Findings / Gaps | Risk Rating | Improvement Actions |
|---|---|---|---|---|---|---|---|---|
| 6.3-1 | Change Identification Process | Confirm formal mechanism | Has the organization established a process to identify the need for changes to the AIMS? | Change management procedure | ||||
| 6.3-2 | Triggers for Change | Validate completeness | Are triggers for AIMS changes defined (e.g. new AI systems, incidents, regulatory changes, risk findings)? | Trigger lists; procedures | ||||
| 6.3-3 | Change Request Recording | Ensure traceability | Are proposed changes formally recorded and tracked? | Change logs; request forms | ||||
| 6.3-4 | Impact Assessment | Assess risk awareness | Does the organization systematically assess the impact of proposed changes on the AIMS? | Impact assessment records | ||||
| 6.3-5 | Risk & Impact Integration | Verify Clause 6.1 linkage | Are AI risks, impacts, and objectives considered when assessing changes? | Risk reassessments; impact updates | ||||
| 6.3-6 | Scope & Boundary Effects | Prevent scope drift | Are impacts on AIMS scope, boundaries, and applicability evaluated before approval? | Scope review notes | ||||
| 6.3-7 | Resource Implications | Validate feasibility | Are resource requirements (skills, budget, tools) assessed as part of change planning? | Resource impact analyses | ||||
| 6.3-8 | Compliance Consideration | Ensure regulatory alignment | Are legal, regulatory, and contractual implications considered when planning changes? | Compliance assessments | ||||
| 6.3-9 | Change Planning | Confirm systematic planning | Are changes planned in a systematic manner, including actions, responsibilities, and timelines? | Change implementation plans | ||||
| 6.3-10 | Responsibilities & Authority | Confirm governance | Are roles and authorities for approving and implementing changes clearly defined? | Approval matrices; RACI | ||||
| 6.3-11 | Approval of Changes | Verify authorization | Are changes reviewed and approved by appropriate management before implementation? | Approval records | ||||
| 6.3-12 | Communication of Changes | Ensure awareness | Are approved changes communicated to relevant interested parties? | Communication records | ||||
| 6.3-13 | Controlled Implementation | Prevent disruption | Are changes implemented in a controlled manner to avoid adverse effects on the AIMS? | Implementation logs | ||||
| 6.3-14 | Post-Change Review | Validate effectiveness | Is the effectiveness of changes reviewed after implementation? | Post-implementation reviews | ||||
| 6.3-15 | Unintended Consequences | Detect new risks | Are unintended effects or new risks identified and addressed after changes? | Incident logs; reassessments | ||||
| 6.3-16 | Documentation Updates | Ensure accuracy | Are AIMS documents updated to reflect approved changes? | Updated policies; procedures | ||||
| 6.3-17 | Change Records Retention | Confirm evidence | Are records of changes, assessments, and approvals retained as documented information? | DMS records | ||||
| 6.3-18 | Continual Improvement | Promote maturity | Do change outcomes contribute to continual improvement of the AIMS? | Improvement logs; lessons learned |
3. Auditor's Conclusion - Clause 6.3
| Assessment Area | Conclusion |
|---|---|
| Overall Conformance Status | ☠Conform ☠Minor NC ☠Major NC |
| Effectiveness of Change Planning | ☠Effective ☠Partially Effective ☠Ineffective |
| Control of AI Risk During Change | ☠Strong ☠Moderate ☠Weak |
| Risk of Change-Induced Failure | ☠Low ☠Medium ☠High |
4. Common Auditor Findings (Clause 6.3)
Auditors frequently raise findings where:
- Changes are implemented without formal impact assessment
- AIMS documentation is not updated after changes
- New AI risks introduced by changes are not reassessed
- Change approvals are informal or undocumented
- Post-implementation reviews are not performed
This checklist explicitly prevents those failures.
5. ISOLTX Operational Alignment
Clause 6.3 is operationalised through:
- ERMS → Risk reassessment during change
- DMS → Controlled change records & document updates
- AUDIT → Change control effectiveness testing
- PERFORMANCE → Monitoring post-change outcomes
- I²MAS → Incidents revealing change impacts
It ensures changes strengthen—rather than destabilise—the AIMS.
7. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!