Free ISO 42001 LI Exam Flashcards
Memorize 50 essential terms and definitions for the PECB ISO/IEC 42001 Lead Implementer. See the term, recall the definition, then flip to check yourself.
What is ISO/IEC 42001, and why is it significant?
ISO/IEC 42001:2023 is the world's first international standard for an AI Management System (AIMS), published December 2023. It gives organizations a Plan-Do-Check-Act framework to responsibly develop, provide, or use AI systems while managing AI-specific risks.
Filter by Topic
Jump to Card
About These ISO 42001 LI Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the PECB ISO/IEC 42001 Lead Implementer. Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
What is ISO/IEC 42001, and why is it significant?
ISO/IEC 42001:2023 is the world's first international standard for an AI Management System (AIMS), published December 2023. It gives organizations a Plan-Do-Check-Act framework to responsibly develop, provide, or use AI systems while managing AI-specific risks.
What does ISO/IEC 22989 provide within the 42001 standards family?
ISO/IEC 22989 defines the core AI concepts and terminology used across the ISO/IEC 42001 family, giving Lead Implementers a shared vocabulary for terms like machine learning, AI system, and trustworthiness.
How does ISO/IEC 23053 relate to an AIMS?
ISO/IEC 23053 provides a framework for describing machine learning (ML) systems using AI. It helps AIMS implementers classify and document the ML components inside an organization's AI system inventory.
What role does ISO/IEC 23894 play for an AIMS?
ISO/IEC 23894 is the AI-specific risk management standard. Lead Implementers apply its guidance to identify, analyze, and evaluate AI risks — distinct from the societal-impact focus of an AI system impact assessment (ISO/IEC 42005).
What does ISO/IEC 5338 cover?
ISO/IEC 5338 defines the AI system life cycle processes — from inception and design through deployment, operation, and retirement — which Annex A.6 controls reference when governing AI systems across their life cycle.
What is the purpose of ISO/IEC 38507?
ISO/IEC 38507 provides guidance for governing-body (e.g., board of directors) oversight of AI use in an organization, linking AIMS leadership requirements (Clause 5) to enterprise-level AI governance.
What does ISO/IEC 42005 add to the AIMS toolkit?
ISO/IEC 42005 gives detailed guidance for conducting an AI system impact assessment — evaluating a system's effects on individuals, groups, and society — which the exam tests as a distinct process from an AI risk assessment.
How does the EU AI Act's risk-tier classification work?
The EU AI Act (Regulation 2024/1689) classifies AI systems into four tiers: Unacceptable risk (banned under Article 5), High-risk (Annex III systems, heavily regulated), Limited-risk (transparency duties only), and Minimal-risk (no specific obligation) — plus separate rules for general-purpose AI (GPAI).
How does ISO/IEC 42001 differ in scope from ISO/IEC 27001?
ISO/IEC 42001 governs an AI Management System (AIMS) with Annex A controls addressing AI-specific risk, while ISO/IEC 27001 governs an Information Security Management System (ISMS) with Annex A controls addressing information security risk. Both share the Annex SL Clause 4-10 high-level structure.
What is the PECB credential progression for AIMS professionals?
PECB's ladder runs Provisional Implementer (no experience required) -> Implementer (2 years' work experience, 1 in AI management, plus 200 project hours) -> Lead Implementer (5 years' work experience, 2 in AI management, plus 300 project hours) -> Senior Lead Implementer (10 years' work experience, 7 in AI management, plus 1,000 project hours).
What is the format of the ISO/IEC 42001 Lead Implementer exam?
The exam has 80 multiple-choice questions, each with only 3 options (1 correct answer, 2 distractors), delivered open-book (the standard plus training materials and personal notes, no internet lookup) over 3 hours. A 70% score is required to pass, and questions appear both stand-alone and in 5-question scenario sets.
What do Clauses 4 through 10 of ISO/IEC 42001 cover, at a high level?
Clause 4: Context of the organization. Clause 5: Leadership. Clause 6: Planning. Clause 7: Support. Clause 8: Operation. Clause 9: Performance evaluation. Clause 10: Improvement. This is the same Annex SL harmonized structure shared by ISO/IEC 27001.
What is the difference between Annex A and Annex B of ISO/IEC 42001?
Annex A lists the 38 normative controls organizations must consider implementing (what to do); Annex B is informative and provides implementation guidance for those same controls (how to do it). Only Annex A drives the Statement of Applicability.
What do Annexes C and D of ISO/IEC 42001 provide?
Annex C lists potential AI-related organizational objectives and risk sources for reference during risk assessment. Annex D provides sector-specific guidance for tailoring AIMS implementation to particular industries or use cases.
How does an AI risk assessment differ from an AI system impact assessment?
An AI risk assessment (ISO/IEC 23894 methodology) evaluates threats to the organization using likelihood x severity. An AI system impact assessment (ISO/IEC 42005 methodology) evaluates the AI system's effect on individuals, groups, and society — a distinction the exam tests heavily.
When must an organization conduct an AI system impact assessment?
Before deploying a new or significantly changed AI system, the organization should conduct an AI system impact assessment to evaluate its potential effects on individuals and society, per Clause 6.1.4 and Annex A.5.
What is the Statement of Applicability (SoA) in an AIMS?
The SoA is a mandatory document listing every Annex A control, whether it is included or excluded, and the justification for each decision. It is a core Planning-domain deliverable and a key artifact reviewed during certification audits.
If an organization decides an Annex A control does not apply, what must it do?
It must document a justification for excluding that control in the Statement of Applicability. Controls cannot simply be omitted — the exclusion rationale must be defensible and auditable.
What is a gap analysis used for during AIMS planning?
A gap analysis compares the organization's current state against ISO/IEC 42001 requirements to identify missing policies, controls, or processes, forming the basis of the implementation roadmap.
What must an organization's AI policy establish?
The AI policy is a top-level management commitment statement that sets the organization's direction and principles for responsible AI use, required under Clause 5.2 and referenced by Annex A.2.
What are the typical risk treatment options once an AI risk is evaluated?
Common risk treatment options include: modify the risk (add controls), retain the risk (accept it), avoid the risk (discontinue the activity), or share the risk (e.g., insurance or third-party transfer). The chosen options become the risk treatment plan.
What internal context factors must AIMS planning consider?
Internal context includes the organization's culture, governance structure, available resources, existing AI systems, and internal capabilities — a required input for Clause 4.1 context of the organization.
What external context factors must AIMS planning consider?
External context includes regulatory requirements (e.g., the EU AI Act), market conditions, competitor practices, and societal expectations around AI — a required input for Clause 4.1 alongside internal context.
What must an organization do to identify interested parties for its AIMS?
Clause 4.2 requires identifying interested parties (employees, customers, regulators, affected individuals) and determining their relevant needs and expectations regarding the organization's AI systems.
What makes a good AIMS objective under Clause 6.2?
AIMS objectives must be measurable (or capable of performance evaluation), consistent with the AI policy, and take applicable requirements into account — enabling later verification during monitoring and management review.
What does the AIMS implementation project plan/roadmap define?
The project plan lays out the sequence, timeline, responsibilities, and resources needed to move from gap-analysis findings to a fully operating AIMS — the bridge between the Planning and Implementation domains.
During planning, how should an organization respond if an AI risk is judged unacceptable?
An unacceptable AI risk requires a formal risk treatment plan — selecting and implementing additional controls, or another treatment option, before the AI system can proceed to deployment.
What does Annex A.2 (AI policies) require an organization to implement?
A.2 requires establishing and communicating AI-specific policies that translate the organization's top-level AI policy into operational direction for AI development, deployment, and use.
What does Annex A.3 (internal organization) require?
A.3 requires defining clear roles, responsibilities, and reporting lines for AI governance — for example, who owns AI risk decisions, who approves new AI systems, and who monitors compliance.
What does Annex A.4 (resources for AI systems) require?
A.4 requires ensuring adequate resources — including compute, data, tooling, and skilled personnel — are allocated to develop, operate, and maintain AI systems responsibly.
What does Annex A.5 (AI system impact assessment) require during implementation?
A.5 operationalizes the impact-assessment process defined in Planning — requiring documented procedures for assessing effects on individuals and society before and during AI system deployment.
What does Annex A.6 (AI system life cycle) control?
A.6 requires controls across the full AI system life cycle — design, development, verification/validation, deployment, operation, and decommissioning — including technical documentation and record-keeping aligned with EU AI Act Articles 11-12.
What does Annex A.7 (data for AI systems) require?
A.7 requires governance over the data used to train, validate, and operate AI systems — covering data quality, provenance, and management practices that reduce bias and error.
What does Annex A.8 (information for interested parties) require?
A.8 requires providing transparent information to affected parties — such as users and regulators — about how an AI system works, its limitations, and how to raise concerns.
What does Annex A.9 (responsible use of AI) require?
A.9 requires controls ensuring AI systems are used responsibly within the organization, including human oversight, use-case restrictions, and safeguards against misuse — closely aligned with EU AI Act transparency and human-oversight obligations.
What does Annex A.10 (third-party relationships) require?
A.10 requires managing AI risk introduced by suppliers, vendors, and partners — including due diligence on third-party AI components and contractual controls over their use.
What are the three categories of bias mitigation methods?
Pre-processing (reweighing or resampling training data before model training), in-processing (adversarial debiasing during training), and post-processing (adjusting decision thresholds after the model produces outputs).
What is the difference between LIME, SHAP, a model card, and a datasheet?
LIME and SHAP are explainability techniques that approximate or attribute a model's predictions (local approximation vs. Shapley-value attribution). A model card documents a model's intended use and limitations; a datasheet documents the dataset used to train it.
What are AIMS metrics used for under Clause 9.1?
AIMS metrics are performance indicators the organization defines to measure whether AI systems and the management system itself are operating as intended — feeding into internal audit and management review.
What is drift monitoring, and why does it matter for an AIMS?
Drift monitoring detects when an AI model's input data (data drift) or the relationship between inputs and outputs (concept drift) changes over time, signaling that a model may need retraining or review to stay reliable and fair.
Why is bias monitoring performed after an AI system is deployed, not just before?
Bias can emerge or worsen after deployment as real-world data shifts, so ongoing bias monitoring in production complements the pre-deployment impact assessment and catches issues that only appear at scale.
What standard underpins the AIMS internal audit process?
ISO 19011 provides the guidelines for auditing management systems that AIMS internal audits (Clause 9.2) are based on, covering audit program management, auditor competence, and evidence-gathering.
What is the purpose of management review under Clause 9.3?
Management review is top management's periodic evaluation of the AIMS's continuing suitability, adequacy, and effectiveness — considering audit results, AI risk changes, and performance against objectives.
What does a 'suitability review' check that a management review does not fully capture?
A suitability review specifically asks whether the AI policy and AIMS scope still fit the organization's current AI landscape and external context — flagging when the AIMS needs to be re-scoped rather than just fine-tuned.
What is a nonconformity in an AIMS context?
A nonconformity is any instance where an AIMS requirement — a clause requirement or an implemented Annex A control — is not met, triggering corrective action under Clause 10.1.
What is the purpose of root cause analysis after a nonconformity is found?
Root cause analysis identifies the underlying failure source behind a nonconformity — not just the symptom — so the corrective action addresses why the problem occurred and prevents recurrence.
How does corrective action differ from simply fixing an isolated problem?
Corrective action both fixes the immediate nonconformity and addresses its root cause to prevent recurrence, distinguishing it from a one-off fix that leaves the underlying issue unresolved.
What does the PDCA cycle mean for continual improvement of an AIMS?
Plan (set AIMS objectives) -> Do (implement the AIMS) -> Check (monitor and audit) -> Act (correct and improve) — the cycle that drives Clause 10's continual improvement requirement.
What distinguishes a major nonconformity from a minor nonconformity?
A major nonconformity reflects a systemic failure that blocks certification until resolved, while a minor nonconformity is an isolated lapse that can typically be addressed with an accepted corrective action plan.
What happens at each stage of the ISO/IEC 42001 certification audit cycle?
Stage 1 reviews documentation readiness (often off-site); Stage 2 tests whether the AIMS is actually operating as documented (on-site evidence of implementation); an annual surveillance audit checks continued conformity; and a full recertification audit occurs every 3 years.
Frequently Asked Questions
How many questions are on the ISO/IEC 42001 Lead Implementer exam, and how is it scored?
The PECB ISO/IEC 42001 Lead Implementer exam has 80 multiple-choice questions, each offering only 3 options (1 correct answer and 2 distractors). A 70% passing score is required. Per the PECB Candidate Handbook, 40% of questions test comprehension/analysis and 60% test evaluation-level thinking, delivered as stand-alone questions and 5-question scenario sets.
What happens if I fail the ISO/IEC 42001 Lead Implementer exam?
PECB places no limit on the number of retake attempts, but waiting periods apply from the date of the failed attempt: 15 days after a 1st failure, 3 months after a 2nd failure, 6 months after a 3rd failure, and 12 months after a 4th or later failure. Candidates who completed PECB-authorized training receive one free retake within 12 months of their original exam.
What is the official domain weighting for the exam?
Per the PECB Candidate Handbook (v1.5, 2026), the 80 questions split across six domains: Fundamental AI/AIMS principles (21.25%), AI Management System requirements/clauses (6.25%), Planning an AIMS implementation (25%), Implementing an AIMS (22.5%), Monitoring and measurement (12.5%), and Continual improvement/certification audit prep (12.5%).
Is the ISO/IEC 42001 Lead Implementer exam open-book?
Yes. Candidates may use a hard copy of the ISO/IEC 42001 standard, their training course materials, and any personal notes taken during training. Internet lookups and other outside materials are not permitted, and the session is proctored (remote webcam for online exams, an in-person invigilator for paper-based exams).
Does PECB publish an official pass rate for this exam?
No. PECB does not publish official pass rates for the ISO/IEC 42001 Lead Implementer exam. The 70% passing score is the only publicly documented performance benchmark; candidates who fail receive a breakdown of weak domains to guide their retake preparation.
Explore More PECB Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.