About this checklist
Getting ready for ISO/IEC 42001 certification starts with knowing where the gaps are. The standard defines what a functioning AI management system (AIMS) looks like: how you govern AI-related risk, how you handle data and transparency, and how you manage the lifecycle of the systems you build or deploy. This self-assessment walks through those requirements domain by domain, so you can see which parts of your organization are already in shape and which still need work before an audit.
Go through each section and answer Yes or No for every item. An honest answer is more useful here than an optimistic one.
A note on what's ahead
Certification itself isn't a single event. It typically runs as a Stage 1 audit (documentation, policies, risk assessments) followed by a Stage 2 audit that checks whether your controls actually hold up in practice. Once certified, the standard cycle continues with annual surveillance audits and full recertification every three years. Treat this checklist as a way to walk in prepared. It's not a substitute for the audit itself.
How to use it
Give each section an owner rather than filling it in solo. Most of these questions sit with different teams (risk, IT, HR, legal), and one person rarely has visibility into all of them. Come back to the checklist as your AI systems or their risk profile change, since a result from six months ago may no longer hold. The scoring breakdown at the end is there to help you prioritize, not to predict how an audit would go.
ISO/IEC 42001 Readiness Checklist
Assess your organization's preparedness for responsible AI governance.
Your Readiness Score
Results by section
Next steps
Once you have completed this self-check, DQS conducts independent ISO/IEC 42001 certification audits aligned with your organization's scope and the AI systems in use. Contact DQS to confirm the audit approach and to schedule your certification journey.