Contact us

OREDJA ecosystem · IAPro.ai

AI audit and ISO/IEC 42001 readiness for procurement and supply chain functions

In development. Launching with the first client cohort.

IAPro.ai is the specialist governance capability in the OREDJA ecosystem. It prepares organisations to govern AI before they scale it: an AI management system structured on ISO/IEC 42001, governance frameworks, risk and controls, implementation readiness and the professional capability to run it.

Request a readiness assessment

ISO/IEC 42001, explained

The standard

ISO/IEC 42001, explained

ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, was published in December 2023. It is the first certifiable management-system standard for artificial intelligence, and it applies to any organisation that develops, provides or uses AI systems.

Procurement and supply chain functions are adopting AI faster than most: sourcing agents, supplier risk sensing, contract reading and demand forecasting all shape decisions with financial and contractual weight. ISO/IEC 42001 gives those decisions a management system, and gives the CPO and the supply chain director evidence that the function controls what it has automated.

Published
December 2023, as ISO/IEC 42001:2023
Type
Certifiable management-system standard, the first for artificial intelligence
Structure
Harmonised structure, clauses 4 to 10, with 38 Annex A controls under nine objectives
Certification cycle
Stage 1 and stage 2 audits, annual surveillance, recertification every three years

The seven requirement clauses, read from procurement and supply chain

4

Context of the organisation

The function identifies the internal and external issues, the interested parties and the AI systems that fall within scope. For procurement this means naming the categories, suppliers, regions and decisions the AI touches.

Illustration of an ISO/IEC 42001 certificate of registration
Illustration of a certificate of registration and the elements an auditor looks for. Not a real certificate.

Certification support

We help organisations obtain ISO/IEC 42001 certification. We do not issue it.

ISO/IEC 42001 is the international standard for artificial intelligence management systems. Certificates are issued by accredited certification bodies after an audit. IAPro.ai and OREDJA prepare the organisation: the gap assessment, the management system, the controls, the evidence and the internal audit that make the certification audit a formality rather than a discovery.

Annex A: 38 controls under nine objectives

Annex A groups 38 controls under nine control objectives, A.2 to A.10: policies for AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. The organisation selects the controls that apply, justifies any exclusion and evidences each one. In a procurement function this becomes concrete: which data a sourcing agent runs on and who governs it, the impact assessment behind a supplier scoring model, the human oversight rules on a tool that extracts contract clauses, and the due diligence performed on the vendors who supply the AI itself.

Risk management

AI audit is a risk-management discipline

An AI audit belongs with the organisation’s enterprise risk management, not with its innovation programme. It identifies where AI systems take or shape decisions, what could go wrong, what the consequences would be and which controls exist. ISO/IEC 42001 requires this assessment and its treatment; the standards below give it method, and the EU AI Act gives it legal weight.

Our specialisation

AI audit for procurement and supply chain

OREDJA audits AI where it is used in procurement and supply chain, with people who have run those functions. The audit follows the clauses and controls of ISO/IEC 42001, documents findings a certification body will recognise and gives leadership a prioritised plan. Six use cases account for most of what we see.

  1. 01

    Spend classification and sourcing agents

    Taxonomy accuracy, training data, the supplier shortlist logic, human validation before award and the audit trail of every recommendation.

  2. 02

    Supplier risk sensing

    Sources and refresh of external signals, false-positive and false-negative rates, escalation rules and the fairness of scores applied to suppliers.

  3. 03

    Contract reading and clause extraction

    Extraction accuracy across the contract portfolio, confidentiality of the documents processed, legal review thresholds and change control on the model.

  4. 04

    Demand forecasting and S&OP

    Input data quality, model monitoring, override discipline in the S&OP cycle and accountability for forecasts that drive purchase commitments.

  5. 05

    Replenishment and inventory agents

    Order parameters, guardrails on quantities and values, exception handling and the record of every automated decision.

  6. 06

    Procure-to-Pay exception handling

    Matching rules, tolerance thresholds, segregation of duties where AI clears exceptions, and fraud controls around automated approvals.

The path to certification

01

Gap assessment

Current AI use cases, governance, data and controls assessed against every clause of ISO/IEC 42001 and against the EU AI Act obligations that apply.

What IAPro.ai provides

EU AI Act alignment

The management system is built so that the obligations of the EU AI Act for the organisation’s risk classes are covered by the same policies, registers and controls, rather than by a second programme.

  • Readiness assessmentA structured questionnaire mapped to the standard, producing a scored gap analysis and a prioritised plan.
  • Control libraryControls, policies and procedure templates aligned with ISO/IEC 42001 Annex A and the EU AI Act, adapted to procurement and supply chain use cases.
  • AI system registerEvery AI system with its purpose, owner, risk classification, data, thresholds and human oversight rules.
  • Evidence and audit trailEvidence collected against each requirement, ready for internal and certification audits.
  • Readiness dashboardProgress by clause, open findings, review calendar and the audit-readiness score leadership can follow.
  • Audit workspaceA shared space where auditors, owners and OREDJA work through findings, corrective actions and evidence until closure.

Start with an AI audit of the function

Questions a CPO or supply chain director asks

Is ISO/IEC 42001 certification mandatory?

No. It is a voluntary standard. It is increasingly requested by customers and boards, and it provides a recognised structure for the obligations of the EU AI Act.

How long does preparation take?

It depends on the number of AI systems in scope, the maturity of existing management systems and the availability of evidence. Organisations already certified to ISO 9001 or ISO/IEC 27001 reuse much of their structure. The gap assessment gives a realistic timeline.

Who issues the certificate?

An accredited certification body, after a stage 1 and a stage 2 audit. ISO/IEC 42006:2025 sets the requirements for those bodies. OREDJA prepares and accompanies the organisation; it does not certify.

Does the standard cover generative AI?

Yes. ISO/IEC 42001 applies to AI systems whatever the technique, including large language models used for contract reading, supplier correspondence or sourcing agents. Their specific risks are treated through the impact assessment and the Annex A controls.

What about the AI our suppliers use?

Control objective A.10 covers third-party and customer relationships. The organisation defines what it expects of its suppliers, allocates responsibilities and keeps evidence, which extends supplier due diligence rather than replacing it.

What drives the cost?

The number and criticality of AI systems in scope, the state of existing documentation and controls, the effort needed to gather evidence and the certification body’s fees. A management system built on existing ISO structures costs less than one built from nothing.

Contact

Start with an AI audit of the function

A structured audit of how AI is already used in procurement and supply chain, mapped to ISO/IEC 42001, with findings leadership can act on and a path to certification if that is the objective.

Request a readiness assessment

About

OREDJA remains the core

Procurement first, Supply Chain second, AI Orchestration as the differentiator. IAPro.ai is the governance capability beside that core.

Explore AI Orchestration