Skip to content

ISO 42001 checklist: what you actually need in place

5 min read by John Bagnall

An ISO 42001 checklist is useful for one thing: seeing, at a glance, what the standard asks you to have in place and where your gaps are. It is a map, not the territory. ISO 42001 certifies a system you run, not a list you have ticked, so treat what follows as a gap analysis, a way to find what is missing before you invest in closing it, not proof of compliance in itself.

The checklist below is grouped the way the standard is structured (the main clauses, then the Annex A controls), so it lines up with how an implementation and an audit actually work. The detail behind each area lives in our ISO 42001 implementation guide.

Scope and context

  • The boundary of your AI Management System is defined: which AI systems and uses it covers.
  • The internal and external issues that affect it are understood.
  • The interested parties (customers, regulators, staff) and their relevant needs are identified.

Leadership and policy

  • Top management owns the system and backs it with real authority.
  • An AI policy is in place: your principles, boundaries, and how AI risk is handled. (How to write one.)
  • Roles, responsibilities and accountability are assigned, with a named owner for the system and for each AI system.

Your AI, mapped

  • An AI system register lists every AI system, model and tool in use or in build, including the shadow AI nobody signed off.
  • Each entry records owner, purpose, the data it touches, risk tier and status. (What to track.)

Risk and impact

  • Each system is classified by risk. (A method.)
  • An AI impact assessment has been run where needed: who a system could affect and how. (How to.)
  • Risks have a treatment plan, and residual risk is recorded.
  • A Statement of Applicability records which Annex A controls apply, and justifies any left out.
  • AI objectives are set, measurable where practicable, and consistent with the policy.

Controls (Annex A)

The controls you select from, based on your risk. Apply the ones that fit.

  • AI policies are documented and reviewed.
  • Internal organisation: roles, reporting and escalation are defined.
  • Resources for AI (data, tooling, compute, people) are identified and managed.
  • Impact assessment process is defined and documented.
  • AI system lifecycle: design, development, deployment, monitoring and retirement are controlled, with a gate before anything goes live.
  • Data for AI is sourced, handled and kept fit for purpose and lawful.
  • Human oversight is in place where decisions carry weight.
  • Information for interested parties: users and affected people get what they need (transparency, instructions).
  • Use of AI systems is governed by clear, followed rules.
  • Third-party and supplier AI is assessed and governed. (Evaluating a vendor.)

People and competence

  • The people using and overseeing AI are competent to do so.
  • AI literacy and awareness is addressed, which also meets the EU AI Act’s Article 4 duty. (In practice.)

Documentation and operation

  • The system’s documented information is controlled and current.
  • The controls are operating in practice, not just written down, with records that show it.
  • Changes and new AI tools go through the process before they go live.

Monitor, audit and review

  • Performance is monitored and measured against the objectives.
  • An internal audit checks the system against the standard.
  • A management review re-prioritises as things change.

Improve

  • Nonconformities are recorded and corrective action is taken.
  • The system is continually improved, not left to go stale.

If you are going for certification

  • A stage 1 audit reviews your documentation and readiness.
  • A stage 2 audit checks the system is genuinely operating.
  • You are running the system long enough to have real evidence to show.
  • You have picked an accredited certification body. (Do you actually need the certificate?)

How to use this

Run down the list and mark honestly: have, partial, missing. The pattern tells you where to start. Most organisations find the foundations (scope, policy, register) are quick wins, the risk and impact work is the real substance, and the monitoring and audit cycle is the part that has to run for a while before certification is realistic. That is your gap analysis, and it is the first thing we do on an ISO 42001 engagement.

The short version

An ISO 42001 checklist is a gap analysis, not a compliance certificate. Work through it, scope and leadership, your AI inventory, risk and impact assessment, the Annex A controls, competence, documentation, and the monitor-audit-review cycle, and mark what you have, what is partial and what is missing. Close the gaps, run the system long enough to generate real evidence, and then, if it earns its place, certify. The list shows you the destination; the work is building the system behind it.

Want the fastest read on where you stand? The free ISO 42001 readiness check scores your maturity against the standard in about ten minutes, no email required. When you want to turn the gaps into a plan, talk to us.

For the full picture, see the ISO 42001 implementation guide.

Frequently asked questions

What is on an ISO 42001 checklist?

The things ISO 42001 requires you to have in place: a defined scope and context, leadership commitment and an AI policy, an inventory of your AI, risk and impact assessments with a Statement of Applicability, the Annex A controls that apply, competence and AI literacy, documented information, and the monitoring, internal audit and management review that keep the system running. A good checklist groups these the way the standard is structured, so you can see at a glance what you have and what is missing.

What do you need to be ISO 42001 compliant?

A working AI Management System, not a document. At minimum: a scope, an AI policy with named accountability, an AI system register, a risk and impact assessment, the selected controls in operation with a Statement of Applicability, records that prove it all works, and a running cycle of monitoring, internal audit and management review. Certification is a separate, optional step where an accredited body audits that system.

Is an ISO 42001 checklist enough to get certified?

No. A checklist tells you what to have in place, but ISO 42001 certifies a system you actually run, not a list you have ticked. An auditor looks for evidence that the controls operate in practice: real risk assessments, real records, a real management review. Use the checklist as a gap analysis to get ready, then run the system for long enough to generate the evidence a certification audit needs.

What are the main ISO 42001 requirements?

The main body of ISO 42001 (clauses 4 to 10) requires: understanding your context and defining scope; leadership and an AI policy; planning through risk and impact assessment and objectives; support such as competence, AI literacy and documented information; operation of the controls; performance evaluation through monitoring, internal audit and management review; and continual improvement. Annex A then provides the reference controls you select from based on your risk.

How many controls are in ISO 42001 Annex A?

ISO/IEC 42001 Annex A sets out around 38 reference controls, grouped into categories covering AI policies, internal organisation and roles, resources, impact assessment, the AI system lifecycle, data for AI, information for interested parties, use of AI systems, and third-party relationships. You do not apply all of them by default: you select the ones relevant to your risk and justify any you leave out, recorded in a Statement of Applicability.


Building something you need to govern?

Start with a fixed-scope AI Opportunity & Risk Audit.

Meet an Expert