Checklist for Clause 7.3 of ISO/IEC 42001 (AIMS): Awareness

1. Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 7.3 of ISO/IEC 42001 - Awareness, developed directly from the PECB auditing slides provided and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.

This checklist ensures awareness is deliberate, role-specific, measurable, and effective, not assumed.

2. ISO/IEC 42001 - Clause 7.3: Awareness

Audit Checklist (Policy Awareness, Role Impact & Consequence Understanding)

# Clause 7.3 Requirement Area Audit Objective Audit Questions (Checklist) Expected Evidence Conformance (Y/N/Partial) Findings / Gaps Risk Rating Improvement Actions
7.3-1 AI Policy Awareness Confirm policy understanding Are individuals under the organization's control aware of the AI Policy? Training records; acknowledgements     
7.3-2 Strategic Direction Awareness Verify alignment Do individuals understand how the AI Policy aligns with organizational strategy? Interviews; awareness assessments     
7.3-3 Commitment to Responsible AI Confirm ethical awareness Are individuals aware of the organization's commitment to responsible AI development and use? Policy statements; ethics training     
7.3-4 Role Contribution to AIMS Validate role clarity Do individuals understand how their roles contribute to the effectiveness of the AIMS? Role briefings; SOPs     
7.3-5 Impact of Activities Ensure operational awareness Are individuals aware of how their activities affect AI system performance and risk? Interviews; scenario exercises     
7.3-6 Awareness of Benefits Promote positive outcomes Are individuals aware of the benefits of improved AI performance, such as reliability, safety, and trust? Communications; learning materials     
7.3-7 Value of Compliance Reinforce adherence Do individuals understand how adherence to AIMS requirements improves outcomes? Awareness campaigns; training content     
7.3-8 Nonconformance Awareness Confirm consequence knowledge Are individuals aware of the implications of nonconformance with AIMS requirements? Training modules; interviews     
7.3-9 Risk & Consequence Understanding Validate risk perception Do individuals understand potential AI risks, consequences, and stakeholder impacts if AIMS requirements are not met? Scenario-based assessments     
7.3-10 Stakeholder Impact Awareness Extend beyond organization Are individuals aware of impacts on external stakeholders (users, affected persons, society)? Ethics briefings; case studies     
7.3-11 Incident & Escalation Awareness Ensure readiness Do individuals know how to report incidents, concerns, or breaches related to AI systems? Incident procedures; I²MAS guides     
7.3-12 Role-Specific Awareness Ensure tailoring Is awareness tailored to different roles (developers, users, managers)? Role-based training records     
7.3-13 Awareness Delivery Methods Confirm effectiveness Are effective methods used to raise awareness (training, workshops, simulations)? Attendance records; materials     
7.3-14 Awareness Evaluation Validate understanding Is awareness evaluated for effectiveness (tests, surveys, interviews)? Evaluation results     
7.3-15 New Personnel Ensure onboarding Is AI awareness provided to new or transferred personnel? Onboarding programs     
7.3-16 Change-Driven Awareness Adapt to changes Is awareness updated when AI systems, risks, or policies change (Clause 6.3)? Change communications     
7.3-17 Documentation Ensure evidence Is evidence of awareness activities documented and retained? DMS records     
7.3-18 Management Oversight Confirm leadership role Does management monitor and promote awareness as part of AIMS effectiveness? Management review minutes     


3. Auditor's Conclusion - Clause 7.3

Assessment Area Conclusion
Overall Conformance Status ☐ Conform ☐ Minor NC ☐ Major NC
Level of AI Awareness ☐ High ☐ Moderate ☐ Low
Effectiveness of Awareness Activities ☐ Effective ☐ Partially Effective ☐ Ineffective
Risk of Awareness-Driven Failure ☐ Low ☐ Medium ☐ High

4. Common Auditor Findings (Clause 7.3)

Auditors frequently raise findings where:

  • Awareness is assumed due to training attendance, not verified
  • Staff know the policy exists but do not understand their role
  • Consequences of nonconformance are not understood
  • Awareness is generic, not role-specific
  • Awareness is not updated after changes

This checklist explicitly prevents those failures.

5. ISOLTX Operational Alignment

Clause 7.3 is operationalised through:

  • PERFORMANCE → Awareness KPIs & assessments
  • DMS → Controlled awareness records
  • I²MAS → Incident reporting awareness
  • AUDIT → Awareness effectiveness testing

It ensures awareness becomes a measurable risk control, not a checkbox.

6. Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!