ChecklistArtificial Intelligence
Implementing ISO/IEC 42001: a clause-by-clause checklist with the evidence auditors expect
ISO/IEC 42001 sets requirements for an AI management system: the policies, roles, risk processes and controls an organization uses to develop, provide or use AI responsibly1. This checklist works through the management-system clauses in order, lists the evidence an auditor will ask for at each, explains how to plan Annex A controls and reuse an existing ISO/IEC 27001 system, and shows where certification helps and where it stops.
On this page
- Setting the scope of the AI management system
- Clause 4 and Clause 5: context, policy and leadership
- Clause 6: risk, impact assessment and the Statement of Applicability
- Planning Annex A controls by objective
- Clause 7 and Clause 8: support and operation across the AI life cycle
- Clause 9 and Clause 10: monitoring, audit, review and improvement
- Reusing ISO/IEC 27001 and mapping to the NIST AI RMF
- The route to certification, from readiness review to surveillance
- What ISO/IEC 42001 certification does not prove
- Questions and answers
- Sources
Setting the scope of the AI management system
Scope decides both the cost and the credibility of the effort. List the AI systems the organization develops, provides or uses, and record the role it plays for each: the standard asks you to determine your roles, such as developer, provider or user, as part of understanding your context1. A bank that builds its own fraud models and also uses a vendor's chatbot holds different roles for each, with different controls.
Then decide which business units, sites and systems are in scope. A narrow first scope, such as the AI systems of one product line, is easier to evidence and can be widened later. Leaving out the systems that carry the most risk makes a certificate easier to obtain and far less useful to the customers who ask for it.
Clause 4 and Clause 5: context, policy and leadership
Auditors look for decisions on paper with named owners, not for completed templates.
Clause 6: risk, impact assessment and the Statement of Applicability
Planning Annex A controls by objective
Annex A groups its reference controls under objectives numbered A.2 to A.101. Decide applicability per objective first, then per control, based on the risk treatment plan.
| Control objective | What it covers | Typical evidence |
|---|---|---|
| Policies related to AI | The AI policy, its fit with other policies and its review | Approved policy and review records |
| Internal organization | Roles, responsibilities and the reporting of concerns | Responsibility matrix and a concern-reporting route |
| Resources for AI systems | Data, tooling, computing and human resources, documented per system | Resource records for each AI system |
| Assessing impacts of AI systems | The impact assessment process and its documentation | Completed and current impact assessments |
| AI system life cycle | Requirements, design, verification, deployment, operation and monitoring | Requirements, test and release records |
| Data for AI systems | Acquisition, quality, provenance and preparation of data | Provenance and data quality records |
| Information for interested parties | System documentation, user information and incident communication | User documentation and external reports |
| Use of AI systems | Processes and objectives for responsible, intended use | Usage procedures and monitoring logs |
| Third-party and customer relationships | How responsibilities are allocated with suppliers and customers | Contracts and supplier assessments |
Objective names are paraphrased here. Use the standard's own wording in your Statement of Applicability.
Clause 7 and Clause 8: support and operation across the AI life cycle
Clause 9 and Clause 10: monitoring, audit, review and improvement
Reusing ISO/IEC 27001 and mapping to the NIST AI RMF
Organizations with a certified information security or quality system already run most of the management machinery. The AI content is what needs building.
| Area | Reusable from ISO/IEC 27001 or ISO 9001 | New for AI | Closest NIST AI RMF function |
|---|---|---|---|
| Governance and roles | Policy framework, management review, leadership commitment | AI-specific roles, approval of AI deployments, reporting of concerns | Govern |
| Risk | Risk methodology and treatment process | Harm to individuals and society, impact assessment, AI-specific risk sources | Map and Measure |
| Operations | Change management, supplier management, document control | Data provenance, model verification, life cycle controls, human oversight | Manage |
| Assurance | Internal audit, corrective action, competence records | Monitoring AI system performance and drift | Measure |
NIST AI RMF 1.0 and its Generative AI Profile, NIST AI 600-1, are voluntary US frameworks; many organizations use them as a source of practices inside an ISO/IEC 42001 system23.
The route to certification, from readiness review to surveillance
- Readiness review
A gap check against every clause and the draft Statement of Applicability.
- Internal audit and review
A full internal audit and management review before inviting the certification body.
- Stage 1 audit
The certification body reviews documentation and readiness.
- Stage 2 audit
Auditors test whether the system works in practice across the scope.
- Certificate issued
Granted by an accredited body once major nonconformities are closed.
- Surveillance audits
Periodic audits during the certification cycle, followed by recertification.
What ISO/IEC 42001 certification does not prove
Questions and answers
Is ISO/IEC 42001 certification mandatory?
No. The standard is voluntary, and no EU or US law currently requires certification. Organizations pursue it because customers, tenders or partners ask for evidence of AI governance, or because a management system is a practical way to organize the work that regulation requires. You can implement it fully without certifying and decide on certification later.
How does ISO/IEC 42001 differ from ISO/IEC 27001?
ISO/IEC 27001 manages information security risk: confidentiality, integrity and availability of information. ISO/IEC 42001 manages the risks and impacts of AI systems, including harm to individuals and society, data quality and provenance, life cycle controls and responsible use. Both share the same management-system structure, so an organization with ISO/IEC 27001 can extend existing processes rather than start again.
Does ISO/IEC 42001 apply if we only use AI that others build?
Yes. The standard covers organizations that use AI systems as well as those that develop or provide them. For a user, the scope centers on responsible use, supplier relationships, impact assessment of how the system is applied and information for affected people. Controls for model development may be excluded in the Statement of Applicability, with the reason recorded.
Who should lead an ISO/IEC 42001 implementation?
Someone with the authority to change processes across teams, often the owner of an existing management system working with AI product, data and risk leads. ColdAI's AI governance work covers governance frameworks, bias and fairness testing, explainability and regulatory compliance5, and can help design the system and prepare evidence. Certification itself must come from an accredited certification body.
Sources
- ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system — International Organization for Standardization
- AI Risk Management Framework — National Institute of Standards and Technology · checked 10 October 2026
- NIST AI 600-1: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — National Institute of Standards and Technology · checked 10 October 2026
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Artificial Intelligence capability: AI Governance and Safety offering — ColdAI