About this checklist

Getting ready for ISO/IEC 42001 certification starts with knowing where the gaps are. The standard defines what a functioning AI management system (AIMS) looks like: how you govern AI-related risk, how you handle data and transparency, and how you manage the lifecycle of the systems you build or deploy. This self-assessment walks through those requirements domain by domain, so you can see which parts of your organization are already in shape and which still need work before an audit.

Go through each section and answer Yes or No for every item. An honest answer is more useful here than an optimistic one.

A note on what's ahead

Certification itself isn't a single event. It typically runs as a Stage 1 audit (documentation, policies, risk assessments) followed by a Stage 2 audit that checks whether your controls actually hold up in practice. Once certified, the standard cycle continues with annual surveillance audits and full recertification every three years. Treat this checklist as a way to walk in prepared. It's not a substitute for the audit itself.

How to use it

Give each section an owner rather than filling it in solo. Most of these questions sit with different teams (risk, IT, HR, legal), and one person rarely has visibility into all of them. Come back to the checklist as your AI systems or their risk profile change, since a result from six months ago may no longer hold. The scoring breakdown at the end is there to help you prioritize, not to predict how an audit would go.

ISO/IEC 42001 Readiness Checklist

ISO/IEC 42001 Readiness Checklist

Assess your organization's preparedness for responsible AI governance.

22 questions · 6 sections · Yes / No
Your progress 0 of 22 answered
1

Foundation & Awareness

Have you reviewed the ISO/IEC 42001 standard and understood its scope and objectives?

Have you engaged relevant stakeholders to raise awareness about the importance of responsible AI governance and certification?

Have you identified internal and external resources (people, systems, infrastructure) required to implement the AIMS?

2

Status Check & Risk Perspective

Have you assessed your existing processes against the ISO/IEC 42001 requirements?

Is there a risk management framework in place specifically addressing AI-related risks (e.g., bias, data misuse, unintended outcomes)?

Have you documented your AI policies, risk assessments, and AI impact assessments?

3

System Design & Implementation

Are roles and responsibilities for AI governance clearly defined within the organization?

Have relevant personnel been trained on AI risks, governance practices, and ISO/IEC 42001 expectations?

Are technical controls in place for managing AI systems, including monitoring, updates, and access controls?

4

Internal Audit and Corrective Actions

Have you conducted an internal audit to assess conformity with the standard?

Are non-conformities addressed with corrective actions and follow-up?

5

Controls Based on Annex A (ISO/IEC 42001)

A.2 - Alignment: Are your AI-related policies aligned with organizational policies and periodically reviewed?

A.3 - Responsibility: Are internal responsibilities for AI systems and their lifecycle clearly assigned?

A.4 - Resources: Have you identified and documented all resources relevant to your AI systems (data, tools, infrastructure)?

A.5 - Impact Assessment: Is there a formal process for conducting AI impact assessments on individuals, groups, or society?

A.6 - Lifecycle: Do you have lifecycle management processes for AI systems, including monitoring and ethical design?

A.7 - Data: Are data quality, provenance, and handling procedures defined for AI systems?

A.8 - Transparency: Are stakeholders and users informed about AI system behavior, risks, and reporting channels?

A.9 - Ethical Use: Do you have measures to ensure ethical and responsible use of AI technologies?

A.10 - Supply Chain: Are supplier and partner relationships aligned with your AI governance framework?

6

Certification Preparation

Have you selected an accredited certification body for ISO/IEC 42001?

Are all relevant documents compiled and the team prepared for the certification audit?

Your Readiness Score

0 of 22 points

Results by section

Next steps

Once you have completed this self-check, DQS conducts independent ISO/IEC 42001 certification audits aligned with your organization's scope and the AI systems in use. Contact DQS to confirm the audit approach and to schedule your certification journey.

Talk to us