Chapter 10

Clause 10: Improvement

Continual improvement and nonconformity management including corrective actions for the AI Management System.

15 min read

Chapter Overview

Clause 10 completes the PDCA cycle with the "Act" phase. It covers how organizations handle nonconformities and drive continual improvement of their AIMS. This clause ensures your management system evolves and improves over time.

Clause Structure

Sub-clauseTitleFocus
10.1Continual improvementOngoing AIMS enhancement
10.2Nonconformity and corrective actionHandling problems and preventing recurrence

10.1 Continual Improvement

Requirement

The organization shall continually improve the suitability, adequacy, and effectiveness of the AI management system.

Three Dimensions of Improvement

Suitability: Is the AIMS appropriate for the organization's context and needs?
Adequacy: Is the AIMS sufficient to manage AI risks and achieve objectives?
Effectiveness: Is the AIMS achieving its intended outcomes?

Sources of Improvement

SourceImprovement Inputs
Internal AuditsFindings, observations, recommendations
Management ReviewDecisions, action items, strategic direction
Performance MonitoringKPI trends, gaps, anomalies
IncidentsRoot causes, lessons learned
Corrective ActionsSystemic issues, pattern analysis
Stakeholder FeedbackComplaints, suggestions, expectations
External ChangesRegulations, technology, best practices
BenchmarkingIndustry comparisons, maturity assessments

Improvement Process

  1. Identify: Recognize improvement opportunities from various sources
  2. Evaluate: Assess potential benefits, costs, and feasibility
  3. Prioritize: Rank improvements based on value and risk
  4. Plan: Define actions, resources, responsibilities, timelines
  5. Implement: Execute improvement actions
  6. Verify: Confirm improvements achieve intended results
  7. Standardize: Embed successful improvements into AIMS

Types of Improvement

TypeDescriptionExamples
CorrectiveFixing identified problemsAddressing audit findings, closing nonconformities
PreventivePreventing potential problemsProactive risk treatment, control enhancements
InnovativeNew approaches and capabilitiesNew tools, automation, process redesign
IncrementalSmall, ongoing enhancementsProcess optimization, efficiency gains

10.2 Nonconformity and Corrective Action

Requirement

When a nonconformity occurs, the organization shall:

  • React to the nonconformity and, as applicable, take action to control and correct it, and deal with the consequences
  • Evaluate the need for action to eliminate the causes of the nonconformity, so it does not recur or occur elsewhere, by reviewing the nonconformity, determining the causes, and determining if similar nonconformities exist or could potentially occur
  • Implement any action needed
  • Review the effectiveness of any corrective action taken
  • Make changes to the AIMS, if necessary

Corrective actions shall be appropriate to the effects of the nonconformities encountered.

The organization shall retain documented information as evidence of the nature of the nonconformities and any subsequent actions taken, and the results of any corrective action.

Nonconformity Definition

A nonconformity is the non-fulfilment of a requirement. This could be:
• Non-compliance with ISO 42001 requirements
• Non-compliance with organizational policies/procedures
• Non-compliance with legal/regulatory requirements
• Failure to meet AI objectives
• Control failures or gaps

Nonconformity Sources

SourceExamples
Internal AuditsAudit findings classified as nonconformities
External AuditsCertification audit findings
IncidentsAI system failures, security breaches, bias incidents
ComplaintsCustomer or stakeholder complaints
MonitoringKPI breaches, control failures
Management ReviewIssues identified during review
Self-identificationStaff reporting issues

Corrective Action Process

Corrective Action Steps

1. Immediate Response (Correction)
• Contain the problem
• Mitigate immediate consequences
• Protect affected parties

2. Root Cause Analysis
• Investigate underlying causes
• Use techniques: 5 Whys, Fishbone, Fault Tree
• Determine if issue is systemic

3. Action Planning
• Define corrective actions to eliminate root cause
• Assign responsibilities
• Set deadlines

4. Implementation
• Execute planned actions
• Document evidence of completion

5. Effectiveness Review
• Verify actions were effective
• Confirm nonconformity has not recurred
• Close the corrective action

Root Cause Analysis Techniques

TechniqueDescriptionBest For
5 WhysAsk "why" repeatedly to drill down to root causeSimple, single-cause issues
Fishbone (Ishikawa)Categorize potential causes (people, process, technology, etc.)Complex issues with multiple factors
Fault Tree AnalysisMap logical relationships between events and causesTechnical/system failures
Pareto AnalysisIdentify the vital few causes from trivial manyRecurring issues, pattern analysis

5 Whys Example

5 Whys - AI Bias Incident Example

Problem: AI model showed discriminatory outcomes for loan applications

Why 1: Why did the model show bias?
→ Training data was not representative of all demographic groups

Why 2: Why was training data not representative?
→ Data was collected from limited geographic regions

Why 3: Why was data collected from limited regions?
→ No data diversity requirements were specified

Why 4: Why were diversity requirements not specified?
→ Data acquisition process didn't include bias assessment

Why 5: Why didn't the process include bias assessment?
→ Data governance procedure was incomplete

Root Cause: Inadequate data governance procedure
Corrective Action: Update data governance procedure to include diversity requirements and bias assessment at data acquisition stage

Template: Corrective Action Request (CAR)

Corrective Action Request Template

CAR Number: [Unique ID]
Date Raised: [Date]
Raised By: [Name]
Source: [Audit/Incident/Complaint/Other]

1. NONCONFORMITY DESCRIPTION
Requirement: [ISO 42001 clause/policy/procedure]
Description: [What was found]
Evidence: [Objective evidence]
Classification: [Major/Minor]

2. IMMEDIATE ACTION (CORRECTION)
Action taken: [Immediate containment/correction]
Date completed: [Date]
Completed by: [Name]

3. ROOT CAUSE ANALYSIS
Analysis method: [5 Whys/Fishbone/Other]
Root cause: [Identified root cause]
Systemic? [Yes/No - does this affect other areas?]

4. CORRECTIVE ACTION PLAN
Actions: [List of actions to eliminate root cause]
Responsible: [Name for each action]
Target date: [Deadline for each action]

5. IMPLEMENTATION EVIDENCE
Actions completed: [Evidence of completion]
Date completed: [Actual completion date]

6. EFFECTIVENESS REVIEW
Review date: [Date - typically 3-6 months after]
Review method: [How effectiveness was verified]
Effective? [Yes/No]
Reviewed by: [Name]

7. CLOSURE
Closed by: [Name]
Date closed: [Date]

Documented Information Requirements

Mandatory Documents - Clause 10

Required:
• Nature of nonconformities (10.2)
• Actions taken (10.2)
• Results of corrective actions (10.2)

Recommended:
• Corrective Action Procedure
• Corrective Action Register/Log
• Improvement Register
• Root Cause Analysis Records

Sample Audit Questions

Auditor Questions - Clause 10

10.1 Continual Improvement:
• How do you identify improvement opportunities?
• Show me examples of improvements made to the AIMS
• How do you prioritize improvements?
• How do improvements from management review get implemented?

10.2 Nonconformity and Corrective Action:
• Show me your corrective action process
• Walk me through a recent corrective action
• How do you conduct root cause analysis?
• How do you verify corrective actions are effective?
• Show me your corrective action register
• Are there any overdue corrective actions?

Common Nonconformities

TypeNonconformityHow to Avoid
MajorNo corrective action process in placeEstablish documented CA procedure
MajorNonconformities not addressedTrack and close all nonconformities
MinorRoot cause analysis not conductedRequire RCA for all nonconformities
MinorEffectiveness not verifiedSchedule effectiveness reviews
MinorCorrective actions overdueMonitor and escalate overdue items
MinorNo evidence of continual improvementDocument improvement activities

Integration with PDCA

Clause 10 in the PDCA Cycle

Clause 10 represents the "ACT" phase of PDCA:

PLAN (Clauses 4-7): Establish AIMS foundation
DO (Clause 8): Operate the AIMS
CHECK (Clause 9): Monitor and evaluate
ACT (Clause 10): Improve based on findings

The cycle then repeats - improvements from Clause 10 feed back into planning (Clause 6), creating a continuous improvement loop.

Key Takeaways - Clause 10

1. Continual improvement covers suitability, adequacy, AND effectiveness
2. Nonconformity handling requires both correction (immediate) and corrective action (root cause)
3. Root cause analysis is essential - don't just treat symptoms
4. Corrective actions must be verified for effectiveness
5. Documented information required for nonconformities, actions, and results
6. Clause 10 completes the PDCA cycle and feeds back into planning

Exam Tips - Clause 10

• Know the difference between correction (immediate fix) and corrective action (eliminate root cause)
• Remember the five steps when nonconformity occurs (react, evaluate, implement, review, change AIMS if needed)
• Corrective actions must be "appropriate to the effects" of the nonconformity
• Three types of documented information required (nature, actions, results)
• Continual improvement addresses suitability, adequacy, and effectiveness
• Understand how Clause 10 completes the PDCA cycle

AI Assistant
00:00