The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 50 |
| 2 | Domain training | 50 |
| 3 | Domain training | 50 |
| 4 | Domain training | 50 |
| 5 | Timed simulation | 80 |
| 6 | Timed simulation | 80 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
D3 Fundamental audit concepts and principles
An audit team preparing a certification audit of an AI management system intends to run a text analytics tool over the auditee's model documentation, to feed it from an extract produced by an automation script, and to have a generative assistant draft the working paper summaries. What position should the audit team leader take?
- Permit the tools while requiring that every output be verified against the auditee's own records before it enters a working paper or supports a finding, since the team owns the conclusion.
- Prohibit the three tools, because material produced with an automated aid falls outside what a certification audit may consider, and only records read by an auditor personally may be relied on.
- Treat the analytics output as documentary evidence in its own right, name the tool, its supplier and its version in the report, and reduce the testing of the underlying records accordingly.
- Send the model documentation to a public generative service, obtain consent afterwards, and record the tool, the prompt and the date.
-
D4 Preparing an ISO/IEC 42001 audit
A certification body offers four on-site days for the stage 2 audit of an organisation that operates eleven AI systems on three sites, one of them a clinical triage model. The audit team leader concludes that four days cannot support an adequate evaluation of the AI management system. What is the defensible course of action?
- Conduct the audit within the four days as scheduled and record the shortage of time as a limitation in the audit report.
- Accept the four days as adequate, because the duration of a certification audit follows from the number of employees at the audited organisation alone, so the number of AI systems in operation, the diversity of the technologies behind them and the number of sites involved have no bearing on it.
- Narrow the audit scope unilaterally to the AI systems that the team can cover comfortably within the four days available.
- The audit team may decline the mandate, because a proposed duration that does not allow an adequate evaluation of the management system makes the audit unfeasible; the shortfall is raised first with the certification body, and an alternative is proposed to the audit client.
-
D5 Conducting an ISO/IEC 42001 audit
During a stage 2 audit an auditor is gathering evidence on how training data is labelled and checked before use. The data annotator answers in broad terms, then turns to complaints about the annotation team's budget. Which interview technique should the auditor apply for the rest of the session?
- Accept the broad answer, let the account of the budget run its course, and read the written labelling procedure afterwards for the detail the session did not produce.
- Ask open follow-up questions to obtain the missing detail, steer the session back to labelling, then rephrase the answers and ask the annotator to confirm them.
- Work through the prepared list in its fixed order, record every reply verbatim, and leave anything unclear for the closing meeting.
- Put the question again in a form that already carries the expected answer, so that the annotator returns to the documented steps, and record the reply as confirmation.
-
D6 Closing an ISO/IEC 42001 audit
As the audit team prepares its conclusions, the auditee's AI ethics director asks the team leader to record two of the four nonconformities as opportunities for improvement, offering to fix both within the week. She then produces a signed model release record that the team had not seen, which shows that a third nonconformity rests on an incomplete sample. What should the team leader do?
- Refuse the reclassification and examine the new record, revising that finding if it no longer holds.
- Refer the whole disagreement to the certification committee without presenting conclusions, letting the committee decide which of the findings survive.
- Refuse both requests and present the four nonconformities unchanged, since evidence produced after the evidence-gathering phase cannot influence the audit conclusions.
- Agree to reclassify the two nonconformities, because a correction completed during the audit week removes the need to report them, and set the release record aside as evidence that arrived too late to count.
-
D1 Principles and concepts of an AI management system
A logistics company develops one routing model in house, buys two others from suppliers and uses a generative assistant across its back office. The documented scope of its AI management system covers the routing model alone. Given that the standard reaches any organisation regardless of size, type and nature, is such a scope acceptable and how does it relate to the reach of the standard itself?
- The scope is invalid, because the standard applies to any organisation that develops, provides or uses AI systems, so every AI system in the company is inside the management system by operation of the standard.
- The organisation determines the boundaries of its own management system, so a narrow scope can stand where it matches what the company actually does, provided the report makes plain what has been left outside it.
- The scope is acceptable as it stands, and the two purchased models, the assistant and their suppliers fall outside the audit entirely, so no evidence about them may be examined, requested or recorded.
- The auditor should set the boundaries during the audit, extending them to the purchased models, to the assistant and to any system acquired later, since determining the scope forms part of the certification audit.
-
D7 Managing an ISO/IEC 42001 audit program
The person managing a certification body's AIMS audit programme reports on its effectiveness once a year using a single indicator: the percentage of audits delivered on the planned dates. Last year the figure was 98 per cent. In the same period two certified clients suffered AI incidents that were later traced to controls the audits had sampled and passed. Which judgement of the programme is soundest?
- The programme is not really being evaluated, and the incidents are a signal to modify it and to re-evaluate the auditors concerned.
- A replacement programme is needed: incidents at certified clients show that its objectives were unachievable from the outset and cannot be salvaged by review.
- The indicator is adequate for monitoring, and the incidents are complaints, so the only action required is to add a complaint-handling process to the programme.
- The programme is effective, because delivery against schedule is the outcome the programme manager controls, and incidents remain the responsibility of the certified organisations.
-
D2 AI management system requirements
At stage 2 the auditor examines the Annex A control on the verification and validation of AI systems, which the organisation has declared applicable in its Statement of Applicability. The organisation has implemented the control through an approach of its own that departs in several respects from the implementation guidance of Annex B, the results are documented and the acceptance criteria the organisation set were met. How should the auditor treat the departure?
- Raise a minor nonconformity, since Annex B sets out how the Annex A controls are implemented, and another route cannot be regarded as met.
- Raise an opportunity for improvement recommending alignment with Annex B, note the divergence in the report, and ask for the acceptance criteria to be rewritten in the words of the guidance.
- Test the control against the requirement it states and against the organisation's own documented approach, because Annex B is guidance rather than a criterion.
- Record the control as excluded, since implementing it by another route amounts in substance to an exclusion, and ask the organisation to justify that exclusion in the Statement of Applicability.
-
D3 Fundamental audit concepts and principles
During a quality review of a completed AIMS audit the reviewer asks the audit team leader why the file cannot state that a deliberately falsified model evaluation record would certainly have been detected. What determines the level of assurance that an audit team is able to offer?
- The team could have offered certainty, and would have done so had it drawn a larger sample, since detection failures are always a question of sample size.
- Certainty follows from the auditor's independence, so a team free of conflicts of interest, of familiarity threats and of self-review threats detects whatever has been concealed.
- The level is set by the certification body in its audit programme, which fixes for each client the confidence that its certificates carry, and the audit team applies the figure it is given.
- No sample ever yields certainty: testing may not reveal a misrepresentation, the auditee's internal processes can be defeated by collusion, and most evidence is persuasive.
-
D4 Preparing an ISO/IEC 42001 audit
Two weeks before a stage 2 audit, the auditee informs the audit team leader that the training data records and the model evaluation results of its credit-scoring AI system will not be made available, because it considers them too sensitive to disclose to an external party. How should the team leader characterise this situation?
- As a confidentiality matter that is already settled, since the auditors are bound by a confidentiality undertaking and may therefore review the records without further arrangements.
- As a scope matter, resolved by excluding the data management processes from this audit.
- As a matter of audit feasibility, because those controls cannot be validated without access to the information, to be resolved before the audit proceeds.
- As a nonconformity against ISO/IEC 42001 clause 7.5, raised at once, because withholding documented information from an auditor is itself a failure to meet a requirement.
-
D5 Conducting an ISO/IEC 42001 audit
For the stage 2 audit of an organisation whose staff work mainly from home, an audit team proposes to review the documented information at the certification body's premises and to hold one video call with the AI governance manager, with no visit to the organisation's sites. How should this proposal be judged?
- It is acceptable, because remote methods such as document review, video interviews, screen sharing and remote access to the platform are recognised, the auditee's personnel genuinely work from home, the records of design, development and deployment are held electronically, and interviews, sampling and evidence collection can all be conducted from the certification body's premises.
- Remote conduct is acceptable provided the audit team records the choice of audit methods in the audit plan and in the audit report.
- Working off site is acceptable for a surveillance audit, though not for the initial certification audit of an AI management system.
- The proposal fails: stage 2 takes place at the client's sites and must address evidence of conformity with all the requirements, performance against objectives and targets, compliance with legal and contractual requirements, operational control of the processes, internal audits and management review, and management responsibility for the policies.
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 42001 Lead Auditor training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.