Free resource

ISO 42001 Readiness Checklist

ISO/IEC 42001:2023 is the first certifiable standard for AI management systems. Below are all 38 Annex A controls across 9 objectives. Tick each one as you confirm the evidence exists. To keep a copy, use your browser's Print → Save as PDF.

Control titles are summarised for readiness purposes; refer to the official ISO/IEC 42001:2023 text for normative wording.

A.2 Policies Related to AI

  • A.2.2AI policy

    Establish a management-approved policy for responsible development, provision, and use of AI systems, aligned with organizational objectives and applicable requirements.

  • A.2.3Alignment with other organizational policies

    Ensure the AI policy is consistent with existing organizational policies covering security, privacy, ethics, data governance, and risk management.

  • A.2.4Review of the AI policy

    Review the AI policy at planned intervals and after significant changes to ensure its continuing suitability, adequacy, and effectiveness.

A.3 Internal Organization

  • A.3.2AI roles and responsibilities

    Define, assign, and communicate roles, responsibilities, and authorities for AI governance, development, deployment, and monitoring.

  • A.3.3Reporting of concerns

    Establish confidential channels for personnel and stakeholders to report AI-related concerns, incidents, or ethical issues without fear of reprisal.

A.4 Resources for AI Systems

  • A.4.2Resource documentation

    Maintain an inventory of resources required for AI systems, including data, models, tools, compute infrastructure, and human expertise.

  • A.4.3Data resources

    Document and manage data resources used in AI systems, including provenance, quality characteristics, and lifecycle management.

  • A.4.4Tooling resources

    Record and manage AI development tools, algorithms, libraries, and frameworks used across the AI system lifecycle.

  • A.4.5System and computing resources

    Document computing infrastructure, hosting environments, and deployment platforms supporting AI systems.

  • A.4.6Human resources

    Ensure personnel involved in AI activities possess appropriate competencies, and maintain records of training and qualifications.

A.5 Assessing Impacts of AI Systems

  • A.5.2AI system impact assessment process

    Establish a repeatable, documented methodology for assessing the potential impacts of AI systems on individuals, groups, communities, and society.

  • A.5.3Documentation of AI system impact assessments

    Maintain records of impact assessment results, including identified risks, affected parties, severity ratings, and mitigation decisions.

  • A.5.4Assessing impact on individuals or groups

    Evaluate the effects of AI systems on individuals and groups, including fairness, bias, discrimination, privacy, and autonomy impacts.

  • A.5.5Assessing societal impacts

    Evaluate broader societal consequences of AI systems, including economic, environmental, cultural, and democratic impacts.

A.6 AI System Life Cycle

  • A.6.1.2Objectives for responsible development

    Set measurable objectives for responsible AI development, covering fairness, transparency, safety, and accountability at each lifecycle stage.

  • A.6.1.3Processes for responsible design and development

    Document the design and development workflow, including decision rationale, trade-offs, and ethical considerations at each stage.

  • A.6.2.2AI system requirements and specification

    Capture functional, performance, ethical, and regulatory requirements for AI systems in formal specifications.

  • A.6.2.3Documentation of design and development

    Maintain traceable records of design decisions, model architecture choices, training configurations, and iteration history.

  • A.6.2.4Verification and validation

    Define and execute testing methodologies, performance thresholds, and acceptance criteria to verify AI systems meet their specifications.

  • A.6.2.5AI system deployment

    Manage release criteria, deployment approval processes, rollback procedures, and transition to operations.

  • A.6.2.6Operation and monitoring

    Implement continuous monitoring of AI system performance, data drift, model degradation, and operational anomalies in production.

  • A.6.2.7Technical documentation

    Provide clear, audience-appropriate documentation covering system purpose, architecture, limitations, and usage guidance.

  • A.6.2.8Recording of event logs

    Implement logging of AI system events, decisions, and actions to ensure traceability and support auditability.

A.7 Data for AI Systems

  • A.7.2Data management for development and enhancement

    Manage data used for AI system development, including security, privacy protection, and appropriate retention and disposal.

  • A.7.3Acquisition of data

    Document data sources, acquisition methods, and legal rights/licenses for all data used in AI systems.

  • A.7.4Quality of data

    Define and apply data quality criteria including accuracy, completeness, representativeness, and timeliness for AI training and operational data.

  • A.7.5Data provenance

    Track and document data lineage, transformations, and processing history throughout the AI data pipeline.

  • A.7.6Data preparation

    Document data preparation methods including labelling, cleaning, augmentation, and feature engineering processes.

A.8 Information for Interested Parties

  • A.8.2System documentation and information for users

    Provide users with clear information about AI system capabilities, limitations, intended use, and instructions for appropriate interaction.

  • A.8.3External reporting

    Enable external stakeholders and affected parties to submit complaints, feedback, or inquiries regarding AI system impacts.

  • A.8.4Communication of incidents

    Establish procedures for timely notification of AI-related incidents, failures, or significant performance deviations to affected parties.

  • A.8.5Information for interested parties

    Maintain transparency by keeping stakeholders informed about AI system purposes, changes, and known limitations.

A.9 Use of AI Systems

  • A.9.2Processes for responsible use

    Define operational boundaries, usage policies, and escalation procedures for AI system deployment contexts.

  • A.9.3Objectives for responsible use

    Align AI system use with organizational values and responsible AI objectives, ensuring ongoing compliance with intended purpose.

  • A.9.4Intended use of the AI system

    Document the intended purpose, foreseeable misuse scenarios, and usage constraints for each AI system.

A.10 Third-Party & Customer Relationships

  • A.10.2Allocation of responsibilities

    Clarify and document responsibilities, obligations, and liabilities across the AI value chain between the organization, suppliers, and customers.

  • A.10.3Suppliers

    Implement procurement controls for AI components, models, and data from third-party suppliers, including due diligence and contractual safeguards.

  • A.10.4Customers

    Define and communicate customer obligations for responsible use of AI systems provided by the organization.

Run this checklist for every client — without the spreadsheet

All 38 controls are pre-loaded in NovaGRC, alongside NIST AI RMF and the EU AI Act. Assign owners, attach evidence, and produce a white-label readiness report per client.