Is your AI Management System ready for an ISO 42001 audit?
36 requirements across the seven AIMS clauses and the Annex A controls, broken into the 103 evidence questions an auditor asks underneath them, built from the ISO/IEC 42001:2023 standard itself. Tick every evidence question you can answer yes to and get a live readiness score, no email required to see it.
Listen to this briefing
Passing Your ISO 42001 AI Audit
Why an AIMS now
ISO/IEC 42001 does not certify a model. It certifies the management system an organization runs around every AI system it develops, provides, or uses: the policy that sets direction, the risk process that catches problems before they reach customers, and the evidence trail that proves it was all done on purpose rather than by accident.
That distinction matters because the properties that make AI risky are different from classical IT risk. The standard itself flags three: AI can make automated decisions in ways that are not transparent or explainable; AI systems are built from data and statistical inference rather than human-coded logic, which changes how they are designed, justified, and deployed; and AI systems that keep learning change their own behaviour after they go live. A management system built for conventional software will not catch any of that. An AIMS is designed to.
For enterprise leaders, the AIMS is also the answer to a harder question than "does our AI work?": it is the answer to "can we prove, to a regulator, a customer, or a board, that we are using AI responsibly?" That is the artefact an auditor is there to test, and it is the artefact most organizations discover, too late, that they have never built. The checklist below is organized exactly the way an ISO 42001 auditor will work through your evidence: clause by clause, starting with leadership and ending with the controls in Annex A.
Not started
Evidence questions answered yes. Requirements fully met, meaning every evidence question underneath them is answered: 0 of 36.
Start checking off items below to see where your AIMS stands.
This is a self-assessment against the ISO/IEC 42001:2023 standard for your own planning purposes. It is not a certification, an accredited audit, or legal advice, and the recommended steps below are a starting point, not a substitute for a facilitated gap assessment or the judgement of an accredited certification body. Your answers stay in your browser and are not sent to Terence Kok or reviewed by anyone.
Context of the Organization
0 / 11This clause sets scope. If you can't yet name which AI systems and business units the AIMS covers, nothing below is auditable.
Have you documented the internal and external issues that affect your AI management system, including whether climate change is relevant to your context?
0 / 3Evidence an auditor will ask for
Have you identified the interested parties relevant to your AI systems (regulators, customers, employees, AI subjects) and their requirements?
0 / 3Evidence an auditor will ask for
Is the scope of your AI management system written down: which business units, AI systems, and roles it covers, and which it does not?
0 / 3Evidence an auditor will ask for
Does the AIMS exist as a working system rather than a binder, with structure, roles, and processes running day to day and not only at audit time?
0 / 2Evidence an auditor will ask for
Opens a full report with every requirement and evidence question, your answers, recommended next steps, and your calculated score. Print or save it as a PDF from there.
What the AIMS requires and where enterprises get stuck.

The Seven Clauses an Auditor Tests
ISO 42001 shares its structure with ISO 27001, 9001, and other management system standards: Context (4), Leadership (5), Planning (6), Support (7), Operation (8), Performance Evaluation (9), and Improvement (10). An auditor moves through them in order, checking that each one produces documented evidence.
- Clause 6 (risk assessment, treatment, and the Statement of Applicability) is where most first-time audits stall, because it requires evidence that Annex A controls were deliberately included or excluded, not silently ignored
- Clause 9 (internal audit and management review) is the second most common gap: organizations run the AIMS but never formally review it
- Leadership (Clause 5) is a prerequisite. Without a signed AI Policy and assigned roles, every downstream clause lacks the authority to function
- Work the checklist in clause order. Later clauses assume earlier ones are already in place
- Treat any unchecked item in Clauses 5 or 6 as a blocker: fix these before spending effort elsewhere
- Re-run the checklist after each management review to track drift, not just once before certification

Annex A Is Not Optional Homework
Annex A lists reference controls: AI policy, resourcing, impact assessment, life cycle management, data quality, transparency, responsible use, and third-party accountability. You do not have to implement every control, but you must document a justified reason for every one you exclude in your Statement of Applicability.
- An incomplete or missing Statement of Applicability is one of the fastest ways to fail a Stage 1 audit, regardless of how mature the rest of the AIMS is
- Data provenance and quality (A.7) is frequently assumed rather than documented. Auditors ask for the document, not the assumption
- AI system impact assessment (A.5, and Clause 6.1.4) is the control most enterprises have never formally performed, even when they believe they have considered the risks informally
- ISO/IEC 42005:2025, a companion standard published after 42001, now gives auditors a documented methodology for exactly this control. If your impact assessments predate 2025, expect an auditor to ask whether the process itself has been reviewed against it, not just whether an assessment exists
- For every Annex A item you leave unchecked, write down whether you are excluding it and why, or whether it is simply not built yet
- Prioritise A.5, A.6, and A.7. These three carry the most audit evidence weight per item
- Use the checklist output as the first draft of your Statement of Applicability, not a replacement for it

From Checklist to Certification
This checklist tells you where your AIMS stands today. It does not replace an internal audit, a gap assessment against your specific risk context, or the judgement of a certification body. Treat a high score as permission to schedule a formal audit, not as certification itself.
- Enterprises that go straight from "mostly checked" to booking Stage 1 without an internal audit cycle routinely surface nonconformities they could have caught themselves
- A single internal audit cycle (Clause 9.2) before the external audit is the highest-leverage step between "ready on paper" and "ready in practice"
- Leadership sign-off on the AI Policy and the Statement of Applicability should happen before, not during, the audit process
- Once you cross roughly 85%, run one full internal audit cycle before contacting a certification body
- Share the unchecked items with the specific role owner. Clause 5.3 exists because accountability has to be distributed
- If you want a facilitated gap assessment against your specific AI systems and jurisdiction, that is a conversation worth having before Stage 1, not during it
About This Checklist
This checklist was built by Terence Kok, a certified ISO/IEC 42001 Lead Auditor (BSI). Lead Auditor training does not teach the standard's text; it teaches the ISO 19011 audit methodology certification bodies use: how to plan a Stage 1 documentation review and a Stage 2 certification audit, how auditors sample evidence rather than reading every page, and how findings get classified as a major nonconformity, a minor nonconformity, or an observation. That is the perspective this checklist is built from: not "does our AIMS look complete on paper," but "would this survive an auditor asking for the evidence behind it." It is also why the checklist is sequenced clause by clause in the order an auditor works through a management system, rather than the order topics happen to appear in the standard.
See the full certification list →This checklist tests whether your management system can survive an ISO 42001 audit. It is not the same question as whether your board can answer for an AI incident (see theBoard AI Oversight Checklist), or whether your live systems are passing specific bias, privacy, and security thresholds day to day (see theAI Trust, Risk & Governance Dashboard). For the clause 6 risk assessment of each AI agent in scope, with the Annex A controls each tier requires, use theAgent Risk Assessment Matrix. All four cover adjacent ground from a different altitude, and most organisations need more than one.
Want a facilitated gap assessment against your own AI systems?
This checklist tells you where the gaps are. Closing them against your specific risk context, AI systems, and jurisdiction is a structured engagement I run directly.
Learn about working with me
I wrote this checklist the way an auditor works through an AIMS, clause by clause, because I've sat on both sides of that review as a Lead Auditor. Most organisations don't fail because they lack good intentions. They fail because Clause 6 and the Statement of Applicability got written once and never revisited. Checking a box here won't get you certified, but it will show you exactly where the evidence trail thins out before someone else finds it first.

