Is your AI Management System actually ready for an ISO 42001 audit?
36 checks across the seven AIMS clauses and the Annex A controls, built from the ISO/IEC 42001:2023 standard itself. Check off what you have in place and get a live readiness score, no email required to see it.
Listen to this briefing
Passing Your ISO 42001 AI Audit
Why an AIMS, and why now
ISO/IEC 42001 does not certify a model. It certifies the management system an organization runs around every AI system it develops, provides, or uses: the policy that sets direction, the risk process that catches problems before they reach customers, and the evidence trail that proves it was all done on purpose rather than by accident.
That distinction matters because the properties that make AI risky are different from classical IT risk. The standard itself flags three: AI can make automated decisions in ways that are not transparent or explainable; AI systems are built from data and statistical inference rather than human-coded logic, which changes how they are designed, justified, and deployed; and AI systems that keep learning change their own behaviour after they go live. A management system built for conventional software will not catch any of that. An AIMS is designed to.
For enterprise leaders, the AIMS is also the answer to a harder question than "does our AI work?" — it is the answer to "can we prove, to a regulator, a customer, or a board, that we are using AI responsibly?" That is the artefact an auditor is there to test, and it is the artefact most organizations discover, too late, that they have never actually built. The checklist below is organized exactly the way an ISO 42001 auditor will work through your evidence: clause by clause, starting with leadership and ending with the controls in Annex A.
Not started
Start checking off items below to see where your AIMS stands.
Context of the Organization
0 / 4Leadership
0 / 3Planning and Risk
0 / 6Support
0 / 5Operation
0 / 4Performance Evaluation
0 / 3Improvement
0 / 2Statement of Applicability Readiness
0 / 9Opens a 4-page report with your checked items, calculated below. Print or save it as a PDF from there.
What the AIMS actually requires, and where enterprises usually get stuck.

The Seven Clauses an Auditor Tests
ISO 42001 shares its structure with ISO 27001, 9001, and other management system standards: Context (4), Leadership (5), Planning (6), Support (7), Operation (8), Performance Evaluation (9), and Improvement (10). An auditor moves through them in order, checking that each one produces documented evidence, not just intentions.
- Clause 6 (risk assessment, treatment, and the Statement of Applicability) is where most first-time audits stall, because it requires evidence that Annex A controls were deliberately included or excluded, not silently ignored
- Clause 9 (internal audit and management review) is the second most common gap: organizations run the AIMS but never formally review it
- Leadership (Clause 5) is a prerequisite, not a formality. Without a signed AI Policy and assigned roles, every downstream clause lacks the authority to function
- Work the checklist in clause order. Later clauses assume earlier ones are already in place
- Treat any unchecked item in Clauses 5 or 6 as a blocker: fix these before spending effort elsewhere
- Re-run the checklist after each management review to track drift, not just once before certification

Annex A Is Not Optional Homework
Annex A lists reference controls: AI policy, resourcing, impact assessment, life cycle management, data quality, transparency, responsible use, and third-party accountability. You do not have to implement every control, but you must document a justified reason for every one you exclude in your Statement of Applicability.
- An incomplete or missing Statement of Applicability is one of the fastest ways to fail a Stage 1 audit, regardless of how mature the rest of the AIMS is
- Data provenance and quality (A.7) is frequently assumed rather than documented. Auditors ask for the document, not the assumption
- AI system impact assessment (A.5, and Clause 6.1.4) is the control most enterprises have never formally performed, even when they believe they have considered the risks informally
- For every Annex A item you leave unchecked, write down whether you are excluding it and why, or whether it is simply not built yet
- Prioritise A.5, A.6, and A.7. These three carry the most audit evidence weight per item
- Use the checklist output as the first draft of your Statement of Applicability, not a replacement for it

From Checklist to Certification
This checklist tells you where your AIMS stands today. It does not replace an internal audit, a gap assessment against your specific risk context, or the judgement of a certification body. Treat a high score as permission to schedule a formal audit, not as certification itself.
- Enterprises that go straight from "mostly checked" to booking Stage 1 without an internal audit cycle routinely surface nonconformities they could have caught themselves
- A single internal audit cycle (Clause 9.2) before the external audit is the highest-leverage step between "ready on paper" and "ready in practice"
- Leadership sign-off on the AI Policy and the Statement of Applicability should happen before, not during, the audit process
- Once you cross roughly 85%, run one full internal audit cycle before contacting a certification body
- Share the unchecked items with the specific role owner, not just top management. Clause 5.3 exists because accountability has to be distributed
- If you want a facilitated gap assessment against your specific AI systems and jurisdiction, that is a conversation worth having before Stage 1, not during it
About This Checklist
This checklist was built by Terence Kok, a certified ISO/IEC 42001 Lead Auditor (BSI). Lead Auditor training does not teach the standard's text; it teaches the ISO 19011 audit methodology certification bodies actually use: how to plan a Stage 1 documentation review and a Stage 2 certification audit, how auditors sample evidence rather than reading every page, and how findings get classified as a major nonconformity, a minor nonconformity, or an observation. That is the perspective this checklist is built from: not "does our AIMS look complete on paper," but "would this survive an auditor asking for the evidence behind it." It is also why the checklist is sequenced clause by clause in the order an auditor actually works through a management system, rather than the order topics happen to appear in the standard.
See the full certification list →Want a facilitated gap assessment against your own AI systems?
This checklist tells you where the gaps are. Closing them against your specific risk context, AI systems, and jurisdiction is a structured engagement I run directly.
Learn about working with me