ISO 42001 checklist
Ten themes, each tied to the clause it comes from. Work through them on paper, or answer them and get a ledger back showing where the gaps are.
An ISO 42001 checklist covers the management system rather than the models: the systems you run and who owns them, your role for each, leadership and policy, objectives and risk, impact on people, competence, operational controls, data governance, suppliers, and review.
The standard is a management-system standard, so most of what it asks about is organisational, not technical (ISO/IEC 42001:2023). That catches people out. Teams arrive expecting questions about models and find questions about who decided, who was told, and what happens when it goes wrong.
The ten themes, and what each is asking
These are the same themes the readiness worksheet walks through, in the same order, so nothing here is a different standard from the one the tool applies.
The AI systems in use and their owners
Can you list the AI in use across the organisation, and name someone answerable for each one?
The organisation's role for each AI system
For each system, are you the provider, the deployer, or both? The duties differ.
Leadership accountability and an approved AI policy
Has leadership approved a policy, and is someone actually accountable for it?
AI objectives and the treatment of AI risks
Are the risks written down, owned and treated, or do they just get discussed?
The impact of AI on the people it affects
Have you assessed what the AI does to the people on the other side of the decision?
Competence, awareness and the AI literacy of staff
Do the people handling AI know enough to handle it, and can you show how they got there?
Documented operational controls for AI use
Is there a written way of working that the people doing the work actually follow?
Data governance for the data AI systems use
Do you know where the data came from, whether you may use it, and what shape it is in?
Suppliers and third parties providing AI systems
What have you asked your suppliers, and what did they commit to in writing?
Monitoring, internal audit, management review and improvement
Does anything check that the system still works, and does anything change when it does not?
What a checklist will not tell you
- Ticking every box is not conformity
- Conformity is a judgement about evidence, made by someone looking at what you actually do, not what you wrote down. A checklist gets you to the point where that conversation is worth having.
- It is not the standard
- The clauses set the requirements and Annex A adds reference controls to consider. A checklist points at them. If you are going for certification you need the text itself, not a summary of it, and the requirements guide explains how the clauses fit together.
- Only a certification body can certify you
- Certification to ISO/IEC 42001 is a decision an independent, accredited body makes (UKAS on the first UK AIMS accreditation). Nothing you fill in yourself, here or anywhere else, changes that, and the certification guide sets out what the process involves.
- The gaps you cannot see are the expensive ones
- Most organisations know their obvious weak spot. The costly gap is usually the theme nobody owns, because there is no one to notice it is missing.
What to do with the answers
Work down the list and mark each theme as in place, partly there, or a gap. Be harder on yourself than feels comfortable: if you cannot point at where something is written down or who did it, it is not in place.
Then put the gaps in order. Not by how hard they look, but by which ones block the others. Ownership and policy usually come first, because half the remaining themes need a named owner before they can move at all.