# ISO/IEC 42001 Lead Implementer interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | What is an AI management system, and how is it different from an AI policy? | A system of policy, objectives, processes, roles and records that is run and improved over time. A policy is one part of it. | |
| 2 | What does ISO/IEC 42001 ask for that ISO/IEC 27001 does not? | The same clause structure, plus an AI system impact assessment and AI-specific controls in Annex A, such as data for AI systems and the AI system life cycle. | |
| 3 | How would you set the scope of our AIMS? | Context and interested parties, which AI systems are in and out, our role for each (developer, provider, user), and clear boundaries. | |
| 4 | Walk me through an AI risk assessment and an AI system impact assessment. | Risk criteria, likelihood and consequence, treatment and a Statement of Applicability; then the impact on individuals, groups and society, recorded and reviewed. | |
| 5 | How do you roll out the controls without stalling AI projects? | Prioritize by risk, name owners, build competence and awareness, keep documented information lean, and phase the rollout. | |
| 6 | How would you know the AIMS is working? | Objectives with measures, monitoring and analysis, an internal audit program, and management review that changes something. | |
| 7 | An internal audit finds a nonconformity. What happens next? | Correct it, find the root cause, take corrective action, check it worked, and keep the record. | |
| 8 | How do you get us ready for the certification audit? | Documented AIMS ready for stage 1; evidence it runs for stage 2; at least one internal audit and one management review done first. | |

Source: https://credentialpress.com/guides/iso-42001-lead-implementer-interview-questions
