Rhindon Cyber logo
    Support & Documentation
    Contact Support

    AIMS Resources & Infrastructure (ISO 42001 §7.1)

    Register and manage the resources that support your AI Management System: people, infrastructure, tooling, data, budget, and external services. Track adequacy, ownership, and review cadence so leadership has a defensible answer to ISO 42001 Clause 7.1 ("the organization shall determine and provide the resources needed for the AIMS").

    Where it lives

    Open Governance → AIMS Scope & Context → Resources (7.1).

    Available on Professional and Enterprise tiers when ISO 42001 is enabled for your organization.

    Resource types

    • People — internal headcount, roles, FTE allocations.
    • Infrastructure — compute, hosting, networking.
    • Tooling — platforms, SaaS, dev tools.
    • Data — datasets and pipelines (cross-references the Dataset Registry).
    • Budget — funding lines (one-time, monthly, quarterly, annual).
    • External Service — third-party providers (cross-references Suppliers).
    • Other — anything else relevant to the AIMS.

    Adequacy review

    Each active resource carries an adequacy status: Adequate, Partially Adequate, Inadequate, or Not Assessed. Adequacy changes are independently audited (RESOURCE_ADEQUACY_CHANGED).

    Reviews use the canonical scheduling module (weekly, monthly, quarterly, semi-annual, annual, custom). Use Mark Reviewed to advance the cadence; the next due date is computed automatically.

    Backfill

    Open the Backfill dialog to register existing AI Systems and Suppliers as resources in one pass. Already-registered linked records are excluded from the candidate list.

    Exports

    CSVRhindonCyber_AIMS_Resources_<stamp>.csv (full register).

    DOCX — branded snapshot with KPI summary and register table.

    Audit codes

    • RESOURCE_REGISTERED
    • RESOURCE_UPDATED
    • RESOURCE_REVIEWED
    • RESOURCE_ADEQUACY_CHANGED
    • RESOURCE_RETIRED
    • RESOURCE_EXPORTED
    • RESOURCE_LINKED
    All entries are written to the org audit log and mirrored to the platform activity log.