Your readiness ledger
Ten themes, scored from your own answers, with the gaps listed in order.
It gives an organisation a way to set up, run and improve how it governs the AI it builds and uses. The readiness check shows where you already meet it and where the gaps are.
ISO/IEC 42001 is the international standard for an AI management system, published in December 2023. It sets out how an organisation governs the AI it develops and uses, so that the decisions, roles and checks around AI are written down and repeatable.
It is a management system standard, so it asks about how you run AI across the organisation and not about any single model. It shares the harmonised structure used by other ISO management system standards, which is why an organisation already certified to ISO 27001 recognises most of its shape.
It is written for any organisation that develops, provides or uses AI, at any size and in any sector. The standard scales with what you run, so a team using a handful of bought-in tools and a company building its own models both work from the same clauses.
The work sits with whoever owns risk, security and quality, often alongside an existing ISO 27001 or ISO 9001 system. The readiness check is a way to see how far your current practice already goes before you commit to the standard.
The ISO 42001 requirements sit in Clauses 4 to 10, the same seven-part structure ISO uses across its management system standards. Annex A then lists a set of reference controls to consider, with guidance in the annexes that follow.
ISO 27001 governs information security; ISO 42001 governs AI. They use the same clause structure and are built to run together, so the leadership, planning and improvement scaffolding of one carries most of the way into the other.
The difference is subject. ISO 27001 asks how you protect information; ISO 42001 asks how you govern the AI systems that increasingly handle it, including the risks that are specific to AI. An organisation with a working ISO 27001 system is usually closer to ISO 42001 than it expects.
Certification to ISO 42001 is a decision made by an independent, accredited certification body after it audits your management system against the standard. It is not something a self-assessment can grant, and readiness is not the same as being certified.
Most organisations put the management system in place, run it for a while, check it internally, then invite an accredited body to audit it. The readiness check on this site is a self-assessment that shows where your practice already meets the clauses and where it does not. It cannot tell you what an external assessor would conclude, and it never issues a certificate.
The first question most people ask is what it will cost. The honest answer starts with your scope, and how much ISO 42001 certification costs explains why published price ranges mislead.
Start by seeing where you already stand. The readiness check walks through ten themes drawn from the clauses and gives you a ledger of what is in place, what is partial and what is a gap, which you can take away as a PDF.
Prefer to work through it offline? Download the blank readiness gap sheet.
Ten themes across Clauses 4 to 10
Ten themes, scored from your own answers, with the gaps listed in order.
Readiness by theme