Free resource
ISO 42001 Readiness Checklist
ISO/IEC 42001:2023 is the first certifiable standard for AI management systems. Below are all 38 Annex A controls across 9 objectives. Tick each one as you confirm the evidence exists. To keep a copy, use your browser's Print → Save as PDF.
Control titles are summarised for readiness purposes; refer to the official ISO/IEC 42001:2023 text for normative wording.
A.2 Policies Related to AI
A.2.2AI policy
Establish a management-approved policy for responsible development, provision, and use of AI systems, aligned with organizational objectives and applicable requirements.
A.2.3Alignment with other organizational policies
Ensure the AI policy is consistent with existing organizational policies covering security, privacy, ethics, data governance, and risk management.
A.2.4Review of the AI policy
Review the AI policy at planned intervals and after significant changes to ensure its continuing suitability, adequacy, and effectiveness.
A.3 Internal Organization
A.3.2AI roles and responsibilities
Define, assign, and communicate roles, responsibilities, and authorities for AI governance, development, deployment, and monitoring.
A.3.3Reporting of concerns
Establish confidential channels for personnel and stakeholders to report AI-related concerns, incidents, or ethical issues without fear of reprisal.
A.4 Resources for AI Systems
A.4.2Resource documentation
Maintain an inventory of resources required for AI systems, including data, models, tools, compute infrastructure, and human expertise.
A.4.3Data resources
Document and manage data resources used in AI systems, including provenance, quality characteristics, and lifecycle management.
A.4.4Tooling resources
Record and manage AI development tools, algorithms, libraries, and frameworks used across the AI system lifecycle.
A.4.5System and computing resources
Document computing infrastructure, hosting environments, and deployment platforms supporting AI systems.
A.4.6Human resources
Ensure personnel involved in AI activities possess appropriate competencies, and maintain records of training and qualifications.
A.5 Assessing Impacts of AI Systems
A.5.2AI system impact assessment process
Establish a repeatable, documented methodology for assessing the potential impacts of AI systems on individuals, groups, communities, and society.
A.5.3Documentation of AI system impact assessments
Maintain records of impact assessment results, including identified risks, affected parties, severity ratings, and mitigation decisions.
A.5.4Assessing impact on individuals or groups
Evaluate the effects of AI systems on individuals and groups, including fairness, bias, discrimination, privacy, and autonomy impacts.
A.5.5Assessing societal impacts
Evaluate broader societal consequences of AI systems, including economic, environmental, cultural, and democratic impacts.
A.6 AI System Life Cycle
A.6.1.2Objectives for responsible development
Set measurable objectives for responsible AI development, covering fairness, transparency, safety, and accountability at each lifecycle stage.
A.6.1.3Processes for responsible design and development
Document the design and development workflow, including decision rationale, trade-offs, and ethical considerations at each stage.
A.6.2.2AI system requirements and specification
Capture functional, performance, ethical, and regulatory requirements for AI systems in formal specifications.
A.6.2.3Documentation of design and development
Maintain traceable records of design decisions, model architecture choices, training configurations, and iteration history.
A.6.2.4Verification and validation
Define and execute testing methodologies, performance thresholds, and acceptance criteria to verify AI systems meet their specifications.
A.6.2.5AI system deployment
Manage release criteria, deployment approval processes, rollback procedures, and transition to operations.
A.6.2.6Operation and monitoring
Implement continuous monitoring of AI system performance, data drift, model degradation, and operational anomalies in production.
A.6.2.7Technical documentation
Provide clear, audience-appropriate documentation covering system purpose, architecture, limitations, and usage guidance.
A.6.2.8Recording of event logs
Implement logging of AI system events, decisions, and actions to ensure traceability and support auditability.
A.7 Data for AI Systems
A.7.2Data management for development and enhancement
Manage data used for AI system development, including security, privacy protection, and appropriate retention and disposal.
A.7.3Acquisition of data
Document data sources, acquisition methods, and legal rights/licenses for all data used in AI systems.
A.7.4Quality of data
Define and apply data quality criteria including accuracy, completeness, representativeness, and timeliness for AI training and operational data.
A.7.5Data provenance
Track and document data lineage, transformations, and processing history throughout the AI data pipeline.
A.7.6Data preparation
Document data preparation methods including labelling, cleaning, augmentation, and feature engineering processes.
A.8 Information for Interested Parties
A.8.2System documentation and information for users
Provide users with clear information about AI system capabilities, limitations, intended use, and instructions for appropriate interaction.
A.8.3External reporting
Enable external stakeholders and affected parties to submit complaints, feedback, or inquiries regarding AI system impacts.
A.8.4Communication of incidents
Establish procedures for timely notification of AI-related incidents, failures, or significant performance deviations to affected parties.
A.8.5Information for interested parties
Maintain transparency by keeping stakeholders informed about AI system purposes, changes, and known limitations.
A.9 Use of AI Systems
A.9.2Processes for responsible use
Define operational boundaries, usage policies, and escalation procedures for AI system deployment contexts.
A.9.3Objectives for responsible use
Align AI system use with organizational values and responsible AI objectives, ensuring ongoing compliance with intended purpose.
A.9.4Intended use of the AI system
Document the intended purpose, foreseeable misuse scenarios, and usage constraints for each AI system.
A.10 Third-Party & Customer Relationships
A.10.2Allocation of responsibilities
Clarify and document responsibilities, obligations, and liabilities across the AI value chain between the organization, suppliers, and customers.
A.10.3Suppliers
Implement procurement controls for AI components, models, and data from third-party suppliers, including due diligence and contractual safeguards.
A.10.4Customers
Define and communicate customer obligations for responsible use of AI systems provided by the organization.
