Checklist for Clause 8.1: Operational Control
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 8.1 of ISO/IEC 42001 - Operational Planning and Control, developed directly from the PECB auditing slides and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.
This checklist ensures AI operations are planned, controlled, monitored, documented, and governed end-to-end, including internal processes and externally provided services.
2. ISO/IEC 42001 - Clause 8.1: Operational Planning and Control
Updated Audit Checklist (Including Unintended Changes & External Providers)
| # | Clause 8.1 Requirement Area | Audit Objective | Audit Questions (Checklist) | Expected Evidence | Conformance (Y/N/Partial) | Findings / Gaps | Risk Rating | Improvement Actions |
|---|---|---|---|---|---|---|---|---|
| 8.1-1 | Process Criteria Definition | Define operational standards | Has the organization established criteria for AIMS operational processes (standards, thresholds, KPIs)? | SOPs; process criteria | ||||
| 8.1-2 | Criteria Alignment | Ensure consistency | Are operational criteria aligned with AI policy, objectives, and risks? | Mapping matrix | ||||
| 8.1-3 | Process Control Implementation | Validate execution | Are controls implemented to ensure processes meet established criteria? | Procedures; controls | ||||
| 8.1-4 | Consistency of Operations | Prevent variability | Are operational processes performed consistently across AI lifecycle stages? | Logs; audits | ||||
| 8.1-5 | AIMS Controls Implementation | Embed risk treatment | Are controls from Clause 6.1.3 (AI risk treatment) embedded in operations? | SoA; control mappings | ||||
| 8.1-6 | AI Lifecycle Coverage | Ensure completeness | Do operational controls cover design, development, deployment, use, monitoring, and retirement of AI systems? | Lifecycle procedures | ||||
| 8.1-7 | Monitoring of Controls | Verify effectiveness | Is the effectiveness of operational and AIMS controls monitored? | KPIs; monitoring reports | ||||
| 8.1-8 | Corrective Action | Address failures | Are corrective actions taken when controls fail to achieve intended results? | NCRs; action plans | ||||
| 8.1-9 | Reference Controls | Align with Annex A | Are Annex A reference controls used where applicable? | Annex A mapping | ||||
| 8.1-10 | Implementation Guidance | Apply Annex B | Is Annex B implementation guidance followed for operational controls? | Guidance references | ||||
| 8.1-11 | Documented Information | Demonstrate execution | Is documented information available to prove operations were carried out as planned? | Records; logs | ||||
| 8.1-12 | Control of Planned Changes | Govern intentional change | Are planned operational changes controlled, reviewed, and approved before implementation? | Change approvals | ||||
| 8.1-13 | Review of Unintended Changes | Detect deviations | Are unintended changes identified, reviewed, and analysed? | Incident/change logs | ||||
| 8.1-14 | Consequence Analysis (Unintended) | Assess impacts | Does the organization review consequences of unintended changes, including AI performance, safety, and compliance impacts? | Impact assessments | ||||
| 8.1-15 | Mitigation of Adverse Effects | Act on findings | Are mitigation actions implemented to address adverse effects arising from unintended changes? | Corrective actions | ||||
| 8.1-16 | Responsiveness to Unexpected Developments | Ensure agility | Does the organization demonstrate timely response to unexpected AI-related developments? | Response timelines | ||||
| 8.1-17 | Identification of External Providers | Extend operational control | Are externally provided processes, products, or services relevant to AIMS identified? | Supplier register | ||||
| 8.1-18 | Control of External Providers | Enforce governance | Has the organization established controls for externally provided processes, products, or services affecting AIMS? | Supplier controls; contracts | ||||
| 8.1-19 | External Performance Monitoring | Ensure contribution | Is external provider performance monitored to ensure it supports AIMS objectives? | SLAs; reviews | ||||
| 8.1-20 | External Risk Integration | Manage dependencies | Are risks arising from external providers integrated into AI risk management? | Risk register entries | ||||
| 8.1-21 | External Change Management | Prevent blind spots | Are changes by external providers assessed for impact on AI systems and AIMS? | Change notifications | ||||
| 8.1-22 | Management Oversight | Ensure accountability | Does management review operational performance, unintended changes, and external dependencies? | Management review minutes |
3. Auditor's Conclusion - Clause 8.1 (Updated)
| Assessment Area | Conclusion |
|---|---|
| Overall Conformance Status | ☠Conform ☠Minor NC ☠Major NC |
| Control of Operational Changes | ☠Strong ☠Moderate ☠Weak |
| Management of External Providers | ☠Effective ☠Partially Effective ☠Ineffective |
| Risk of Operational AI Failure | ☠Low ☠Medium ☠High |
4. Why This Matters in Certification Audits
PECB auditors frequently raise Major NCs when:
- Unintended changes are not formally reviewed
- AI drift or vendor updates occur without consequence analysis
- External AI providers are used without defined controls
- Organizations cannot demonstrate responsiveness to unexpected AI behavior
This updated checklist closes all those audit risks.
5. ISOLTX Mapping (Operational Reality)
Clause 8.1 is fully operationalised through:
- ERMS → Risk reassessment for unintended changes
- I²MAS → Incident detection & response
- AUDIT → Operational & supplier control testing
- DMS → Change records & approvals
- CAS/CAL → External provider compliance
- PERFORMANCE → Control effectiveness metrics
It turns AI operations into a continuously governed system, not a static design.
6. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!