Checklist for Clause 7.3 of ISO/IEC 42001 (AIMS): Awareness
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 7.3 of ISO/IEC 42001 - Awareness, developed directly from the PECB auditing slides provided and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.
This checklist ensures awareness is deliberate, role-specific, measurable, and effective, not assumed.
2. ISO/IEC 42001 - Clause 7.3: Awareness
Audit Checklist (Policy Awareness, Role Impact & Consequence Understanding)
| # | Clause 7.3 Requirement Area | Audit Objective | Audit Questions (Checklist) | Expected Evidence | Conformance (Y/N/Partial) | Findings / Gaps | Risk Rating | Improvement Actions |
|---|---|---|---|---|---|---|---|---|
| 7.3-1 | AI Policy Awareness | Confirm policy understanding | Are individuals under the organization's control aware of the AI Policy? | Training records; acknowledgements | ||||
| 7.3-2 | Strategic Direction Awareness | Verify alignment | Do individuals understand how the AI Policy aligns with organizational strategy? | Interviews; awareness assessments | ||||
| 7.3-3 | Commitment to Responsible AI | Confirm ethical awareness | Are individuals aware of the organization's commitment to responsible AI development and use? | Policy statements; ethics training | ||||
| 7.3-4 | Role Contribution to AIMS | Validate role clarity | Do individuals understand how their roles contribute to the effectiveness of the AIMS? | Role briefings; SOPs | ||||
| 7.3-5 | Impact of Activities | Ensure operational awareness | Are individuals aware of how their activities affect AI system performance and risk? | Interviews; scenario exercises | ||||
| 7.3-6 | Awareness of Benefits | Promote positive outcomes | Are individuals aware of the benefits of improved AI performance, such as reliability, safety, and trust? | Communications; learning materials | ||||
| 7.3-7 | Value of Compliance | Reinforce adherence | Do individuals understand how adherence to AIMS requirements improves outcomes? | Awareness campaigns; training content | ||||
| 7.3-8 | Nonconformance Awareness | Confirm consequence knowledge | Are individuals aware of the implications of nonconformance with AIMS requirements? | Training modules; interviews | ||||
| 7.3-9 | Risk & Consequence Understanding | Validate risk perception | Do individuals understand potential AI risks, consequences, and stakeholder impacts if AIMS requirements are not met? | Scenario-based assessments | ||||
| 7.3-10 | Stakeholder Impact Awareness | Extend beyond organization | Are individuals aware of impacts on external stakeholders (users, affected persons, society)? | Ethics briefings; case studies | ||||
| 7.3-11 | Incident & Escalation Awareness | Ensure readiness | Do individuals know how to report incidents, concerns, or breaches related to AI systems? | Incident procedures; I²MAS guides | ||||
| 7.3-12 | Role-Specific Awareness | Ensure tailoring | Is awareness tailored to different roles (developers, users, managers)? | Role-based training records | ||||
| 7.3-13 | Awareness Delivery Methods | Confirm effectiveness | Are effective methods used to raise awareness (training, workshops, simulations)? | Attendance records; materials | ||||
| 7.3-14 | Awareness Evaluation | Validate understanding | Is awareness evaluated for effectiveness (tests, surveys, interviews)? | Evaluation results | ||||
| 7.3-15 | New Personnel | Ensure onboarding | Is AI awareness provided to new or transferred personnel? | Onboarding programs | ||||
| 7.3-16 | Change-Driven Awareness | Adapt to changes | Is awareness updated when AI systems, risks, or policies change (Clause 6.3)? | Change communications | ||||
| 7.3-17 | Documentation | Ensure evidence | Is evidence of awareness activities documented and retained? | DMS records | ||||
| 7.3-18 | Management Oversight | Confirm leadership role | Does management monitor and promote awareness as part of AIMS effectiveness? | Management review minutes |
3. Auditor's Conclusion - Clause 7.3
| Assessment Area | Conclusion |
|---|---|
| Overall Conformance Status | ☠Conform ☠Minor NC ☠Major NC |
| Level of AI Awareness | ☠High ☠Moderate ☠Low |
| Effectiveness of Awareness Activities | ☠Effective ☠Partially Effective ☠Ineffective |
| Risk of Awareness-Driven Failure | ☠Low ☠Medium ☠High |
4. Common Auditor Findings (Clause 7.3)
Auditors frequently raise findings where:
- Awareness is assumed due to training attendance, not verified
- Staff know the policy exists but do not understand their role
- Consequences of nonconformance are not understood
- Awareness is generic, not role-specific
- Awareness is not updated after changes
This checklist explicitly prevents those failures.
5. ISOLTX Operational Alignment
Clause 7.3 is operationalised through:
- PERFORMANCE → Awareness KPIs & assessments
- DMS → Controlled awareness records
- I²MAS → Incident reporting awareness
- AUDIT → Awareness effectiveness testing
It ensures awareness becomes a measurable risk control, not a checkbox.
6. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!