OREDJA ecosystem · IAPro.ai
AI audit and ISO/IEC 42001 readiness for procurement and supply chain functions
In development. Launching with the first client cohort.
IAPro.ai is the specialist governance capability in the OREDJA ecosystem. It prepares organisations to govern AI before they scale it: an AI management system structured on ISO/IEC 42001, governance frameworks, risk and controls, implementation readiness and the professional capability to run it.
ISO/IEC 42001, explained
The standard
ISO/IEC 42001, explained
ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, was published in December 2023. It is the first certifiable management-system standard for artificial intelligence, and it applies to any organisation that develops, provides or uses AI systems.
Procurement and supply chain functions are adopting AI faster than most: sourcing agents, supplier risk sensing, contract reading and demand forecasting all shape decisions with financial and contractual weight. ISO/IEC 42001 gives those decisions a management system, and gives the CPO and the supply chain director evidence that the function controls what it has automated.
- Published
- December 2023, as ISO/IEC 42001:2023
- Type
- Certifiable management-system standard, the first for artificial intelligence
- Structure
- Harmonised structure, clauses 4 to 10, with 38 Annex A controls under nine objectives
- Certification cycle
- Stage 1 and stage 2 audits, annual surveillance, recertification every three years
The seven requirement clauses, read from procurement and supply chain
4
Context of the organisation
The function identifies the internal and external issues, the interested parties and the AI systems that fall within scope. For procurement this means naming the categories, suppliers, regions and decisions the AI touches.
5
Leadership
Top management commits to an AI policy, assigns roles and makes accountability explicit. The CPO or supply chain director owns the policy, and each AI system has a named owner.
6
Planning
Risks and opportunities are assessed, impacts on people and organisations are evaluated, and measurable AI objectives are set. A sourcing agent that shortlists suppliers is planned with its risk treatment before it goes live.
7
Support
Resources, competence, awareness, communication and documented information are provided for the system. Buyers and planners understand what the models do, and the records an auditor will ask for exist.
8
Operation
AI systems run under planned controls, with impact assessments and the AI system life cycle managed as specified. A change to a forecasting model or a contract-reading tool follows the same discipline as a change to the ERP.
9
Performance evaluation
The system is monitored, measured, internally audited and reviewed by management. Model accuracy, override rates and exception volumes become management information rather than data-science metrics.
10
Improvement
Nonconformities are corrected and the system improves continually. An incident in an inventory agent leads to a root-cause analysis and a corrective action, recorded and closed.
Certification support
We help organisations obtain ISO/IEC 42001 certification. We do not issue it.
ISO/IEC 42001 is the international standard for artificial intelligence management systems. Certificates are issued by accredited certification bodies after an audit. IAPro.ai and OREDJA prepare the organisation: the gap assessment, the management system, the controls, the evidence and the internal audit that make the certification audit a formality rather than a discovery.
Annex A: 38 controls under nine objectives
Annex A groups 38 controls under nine control objectives, A.2 to A.10: policies for AI, internal organisation, resources for AI systems, assessing impacts of AI systems, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. The organisation selects the controls that apply, justifies any exclusion and evidences each one. In a procurement function this becomes concrete: which data a sourcing agent runs on and who governs it, the impact assessment behind a supplier scoring model, the human oversight rules on a tool that extracts contract clauses, and the due diligence performed on the vendors who supply the AI itself.
Risk management
AI audit is a risk-management discipline
An AI audit belongs with the organisation’s enterprise risk management, not with its innovation programme. It identifies where AI systems take or shape decisions, what could go wrong, what the consequences would be and which controls exist. ISO/IEC 42001 requires this assessment and its treatment; the standards below give it method, and the EU AI Act gives it legal weight.
- ISO/IEC 23894:2023 with ISO 31000:2018Guidance on AI risk management built on the ISO 31000 process: establishing context, then identifying, analysing, evaluating and treating risk. It lets the AI risk register sit inside the enterprise register rather than beside it.
- ISO/IEC 42005:2025 impact assessmentGuidance on assessing the impacts of an AI system on individuals, groups and society. It structures the assessment ISO/IEC 42001 requires before a supplier scoring model or a demand agent goes into service.
- EU AI Act alignmentIn force since 1 August 2024, with obligations phased in from 2025 to 2027. ISO/IEC 42001 is widely used to structure compliance, without constituting a legal presumption of conformity.
- Third parties and suppliers (A.10)Control objective A.10 addresses third-party and customer relationships. For a procurement function it covers the AI embedded in suppliers’ offers and in the platforms the function buys, with responsibilities allocated and evidenced.
Our specialisation
AI audit for procurement and supply chain
OREDJA audits AI where it is used in procurement and supply chain, with people who have run those functions. The audit follows the clauses and controls of ISO/IEC 42001, documents findings a certification body will recognise and gives leadership a prioritised plan. Six use cases account for most of what we see.
- 01
Spend classification and sourcing agents
Taxonomy accuracy, training data, the supplier shortlist logic, human validation before award and the audit trail of every recommendation.
- 02
Supplier risk sensing
Sources and refresh of external signals, false-positive and false-negative rates, escalation rules and the fairness of scores applied to suppliers.
- 03
Contract reading and clause extraction
Extraction accuracy across the contract portfolio, confidentiality of the documents processed, legal review thresholds and change control on the model.
- 04
Demand forecasting and S&OP
Input data quality, model monitoring, override discipline in the S&OP cycle and accountability for forecasts that drive purchase commitments.
- 05
Replenishment and inventory agents
Order parameters, guardrails on quantities and values, exception handling and the record of every automated decision.
- 06
Procure-to-Pay exception handling
Matching rules, tolerance thresholds, segregation of duties where AI clears exceptions, and fraud controls around automated approvals.
The path to certification
01
Gap assessment
Current AI use cases, governance, data and controls assessed against every clause of ISO/IEC 42001 and against the EU AI Act obligations that apply.
02
AI management system design
Policy, objectives, roles, risk methodology, documented processes and the register of AI systems, sized for the organisation.
03
Controls and evidence
Impact assessments, human oversight rules, data governance, supplier due diligence, incident handling and audit trails, implemented and evidenced.
04
Internal audit and management review
The organisation audits itself, corrects the findings and holds its first management review with the records an external auditor expects.
05
Certification audit
Stage 1 and stage 2 audits by the accredited body of the organisation’s choice, with OREDJA alongside the team.
06
Surveillance and recertification
Annual surveillance audits and the three-year recertification are prepared from the same management system, so certification stays a routine rather than a project.
What IAPro.ai provides
The management system is built so that the obligations of the EU AI Act for the organisation’s risk classes are covered by the same policies, registers and controls, rather than by a second programme.
- Readiness assessmentA structured questionnaire mapped to the standard, producing a scored gap analysis and a prioritised plan.
- Control libraryControls, policies and procedure templates aligned with ISO/IEC 42001 Annex A and the EU AI Act, adapted to procurement and supply chain use cases.
- AI system registerEvery AI system with its purpose, owner, risk classification, data, thresholds and human oversight rules.
- Evidence and audit trailEvidence collected against each requirement, ready for internal and certification audits.
- Readiness dashboardProgress by clause, open findings, review calendar and the audit-readiness score leadership can follow.
- Audit workspaceA shared space where auditors, owners and OREDJA work through findings, corrective actions and evidence until closure.
Start with an AI audit of the function
Questions a CPO or supply chain director asks
Is ISO/IEC 42001 certification mandatory?
No. It is a voluntary standard. It is increasingly requested by customers and boards, and it provides a recognised structure for the obligations of the EU AI Act.
How long does preparation take?
It depends on the number of AI systems in scope, the maturity of existing management systems and the availability of evidence. Organisations already certified to ISO 9001 or ISO/IEC 27001 reuse much of their structure. The gap assessment gives a realistic timeline.
Who issues the certificate?
An accredited certification body, after a stage 1 and a stage 2 audit. ISO/IEC 42006:2025 sets the requirements for those bodies. OREDJA prepares and accompanies the organisation; it does not certify.
Does the standard cover generative AI?
Yes. ISO/IEC 42001 applies to AI systems whatever the technique, including large language models used for contract reading, supplier correspondence or sourcing agents. Their specific risks are treated through the impact assessment and the Annex A controls.
What about the AI our suppliers use?
Control objective A.10 covers third-party and customer relationships. The organisation defines what it expects of its suppliers, allocates responsibilities and keeps evidence, which extends supplier due diligence rather than replacing it.
What drives the cost?
The number and criticality of AI systems in scope, the state of existing documentation and controls, the effort needed to gather evidence and the certification body’s fees. A management system built on existing ISO structures costs less than one built from nothing.
Start with an AI audit of the function
A structured audit of how AI is already used in procurement and supply chain, mapped to ISO/IEC 42001, with findings leadership can act on and a path to certification if that is the objective.
OREDJA remains the core
Procurement first, Supply Chain second, AI Orchestration as the differentiator. IAPro.ai is the governance capability beside that core.

