The organization must plan, establish, and maintain a formal internal audit program to govern how it audits its AI Management System (AIMS).
This program must define the overall framework for audits, including:
- The frequency and methodologies for conducting audits.
- The responsibilities, planning requirements, and reporting procedures.
- How the significance of different processes and the results of previous audits will be used to plan future audits.
For each specific audit conducted under the program, the organization must:
- Define the audit's objectives, scope, and criteria.
- Select auditors in a way that ensures their objectivity and impartiality (e.g., they cannot audit their own work).
- Ensure the audit results are reported to relevant management.
The organization must keep documented information as evidence of both the implementation of the audit program itself and the results of each audit conducted.