Human oversight, logging and incident response: the operating core of an AIMS
A policy states intent and a risk register shows understanding — but an auditor's real question is whether the system operates. That lives in your procedures: human oversight, logging, incident response, supplier and change management. These are the parts you can't fake the night before, because they leave a trail.
Human oversight: a role, not a slogan
"Human in the loop" means nothing until you say who, when and with what authority. Effective oversight defines the decision points where a person can review, override or escalate an AI output, names the competent people who do it, and — crucially — gives them the authority and information to act. For higher-risk uses this also satisfies the EU AI Act's human-oversight expectations. An auditor will ask to see it happen, not just be described.
Logging: the memory of the system
Records and logging turn claims into evidence. What did the system do, when, on whose input, and what did the human oversight step conclude? Good logging is proportionate — you don't record everything, you record what you'd need to investigate a problem or demonstrate a control worked. It's also the backbone of the EU AI Act's record-keeping expectations for higher-risk systems, so building it well does double duty.
Incident response: the test everyone eventually faces
AI incidents — a harmful output, a data issue, a model behaving unexpectedly — will happen. What separates a mature system is a defined path: detect, contain, assess, remediate, record and learn. An incident log with even one real, well-handled entry is more convincing to an auditor than a flawless-looking system with none, because it proves the loop works under pressure.
Supplier and change management: the quiet controls
Most mid-market AI is bought or licensed, which makes supplier management a real control: what do you require of your AI vendors, and how do you check? And because AI systems change — retraining, new versions, new uses — change management ensures a modification doesn't silently move you into a higher-risk tier or a provider role under the AI Act. These procedures are unglamorous and disproportionately important.
Educational orientation, not legal advice. ISO/IEC 42001 references current as of September 2026. Certification is performed by accredited bodies.