ChecklistArtificial Intelligence

Implementing ISO/IEC 42001: a clause-by-clause checklist with the evidence auditors expect

ISO/IEC 42001 sets requirements for an AI management system: the policies, roles, risk processes and controls an organization uses to develop, provide or use AI responsibly1. This checklist works through the management-system clauses in order, lists the evidence an auditor will ask for at each, explains how to plan Annex A controls and reuse an existing ISO/IEC 27001 system, and shows where certification helps and where it stops.

Reviewed 7 min read

On this page
  1. Setting the scope of the AI management system
  2. Clause 4 and Clause 5: context, policy and leadership
  3. Clause 6: risk, impact assessment and the Statement of Applicability
  4. Planning Annex A controls by objective
  5. Clause 7 and Clause 8: support and operation across the AI life cycle
  6. Clause 9 and Clause 10: monitoring, audit, review and improvement
  7. Reusing ISO/IEC 27001 and mapping to the NIST AI RMF
  8. The route to certification, from readiness review to surveillance
  9. What ISO/IEC 42001 certification does not prove
  10. Questions and answers
  11. Sources

Setting the scope of the AI management system

Scope decides both the cost and the credibility of the effort. List the AI systems the organization develops, provides or uses, and record the role it plays for each: the standard asks you to determine your roles, such as developer, provider or user, as part of understanding your context1. A bank that builds its own fraud models and also uses a vendor's chatbot holds different roles for each, with different controls.

Then decide which business units, sites and systems are in scope. A narrow first scope, such as the AI systems of one product line, is easier to evidence and can be widened later. Leaving out the systems that carry the most risk makes a certificate easier to obtain and far less useful to the customers who ask for it.

Clause 4 and Clause 5: context, policy and leadership

Auditors look for decisions on paper with named owners, not for completed templates.

0 of 6 checked

Clause 6: risk, impact assessment and the Statement of Applicability

0 of 6 checked

Planning Annex A controls by objective

Annex A groups its reference controls under objectives numbered A.2 to A.101. Decide applicability per objective first, then per control, based on the risk treatment plan.

Control objectiveWhat it coversTypical evidence
Policies related to AIThe AI policy, its fit with other policies and its reviewApproved policy and review records
Internal organizationRoles, responsibilities and the reporting of concernsResponsibility matrix and a concern-reporting route
Resources for AI systemsData, tooling, computing and human resources, documented per systemResource records for each AI system
Assessing impacts of AI systemsThe impact assessment process and its documentationCompleted and current impact assessments
AI system life cycleRequirements, design, verification, deployment, operation and monitoringRequirements, test and release records
Data for AI systemsAcquisition, quality, provenance and preparation of dataProvenance and data quality records
Information for interested partiesSystem documentation, user information and incident communicationUser documentation and external reports
Use of AI systemsProcesses and objectives for responsible, intended useUsage procedures and monitoring logs
Third-party and customer relationshipsHow responsibilities are allocated with suppliers and customersContracts and supplier assessments

Objective names are paraphrased here. Use the standard's own wording in your Statement of Applicability.

Clause 7 and Clause 8: support and operation across the AI life cycle

0 of 5 checked

Clause 9 and Clause 10: monitoring, audit, review and improvement

0 of 5 checked

Reusing ISO/IEC 27001 and mapping to the NIST AI RMF

Organizations with a certified information security or quality system already run most of the management machinery. The AI content is what needs building.

AreaReusable from ISO/IEC 27001 or ISO 9001New for AIClosest NIST AI RMF function
Governance and rolesPolicy framework, management review, leadership commitmentAI-specific roles, approval of AI deployments, reporting of concernsGovern
RiskRisk methodology and treatment processHarm to individuals and society, impact assessment, AI-specific risk sourcesMap and Measure
OperationsChange management, supplier management, document controlData provenance, model verification, life cycle controls, human oversightManage
AssuranceInternal audit, corrective action, competence recordsMonitoring AI system performance and driftMeasure

NIST AI RMF 1.0 and its Generative AI Profile, NIST AI 600-1, are voluntary US frameworks; many organizations use them as a source of practices inside an ISO/IEC 42001 system23.

The route to certification, from readiness review to surveillance

01Readiness review02Internal audit and review03Stage 1 audit04Stage 2 audit05Certificate issued06Surveillance audits
  1. Readiness review

    A gap check against every clause and the draft Statement of Applicability.

  2. Internal audit and review

    A full internal audit and management review before inviting the certification body.

  3. Stage 1 audit

    The certification body reviews documentation and readiness.

  4. Stage 2 audit

    Auditors test whether the system works in practice across the scope.

  5. Certificate issued

    Granted by an accredited body once major nonconformities are closed.

  6. Surveillance audits

    Periodic audits during the certification cycle, followed by recertification.

Conceptual route to certification; timing depends on scope and on the certification body.

What ISO/IEC 42001 certification does not prove

Questions and answers

Is ISO/IEC 42001 certification mandatory?

No. The standard is voluntary, and no EU or US law currently requires certification. Organizations pursue it because customers, tenders or partners ask for evidence of AI governance, or because a management system is a practical way to organize the work that regulation requires. You can implement it fully without certifying and decide on certification later.

How does ISO/IEC 42001 differ from ISO/IEC 27001?

ISO/IEC 27001 manages information security risk: confidentiality, integrity and availability of information. ISO/IEC 42001 manages the risks and impacts of AI systems, including harm to individuals and society, data quality and provenance, life cycle controls and responsible use. Both share the same management-system structure, so an organization with ISO/IEC 27001 can extend existing processes rather than start again.

Does ISO/IEC 42001 apply if we only use AI that others build?

Yes. The standard covers organizations that use AI systems as well as those that develop or provide them. For a user, the scope centers on responsible use, supplier relationships, impact assessment of how the system is applied and information for affected people. Controls for model development may be excluded in the Statement of Applicability, with the reason recorded.

Who should lead an ISO/IEC 42001 implementation?

Someone with the authority to change processes across teams, often the owner of an existing management system working with AI product, data and risk leads. ColdAI's AI governance work covers governance frameworks, bias and fairness testing, explainability and regulatory compliance5, and can help design the system and prepare evidence. Certification itself must come from an accredited certification body.

Sources

  1. ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system — International Organization for Standardization
  2. AI Risk Management Framework — National Institute of Standards and Technology · checked 10 October 2026
  3. NIST AI 600-1: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — National Institute of Standards and Technology · checked 10 October 2026
  4. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  5. Artificial Intelligence capability: AI Governance and Safety offering — ColdAI

More in Artificial Intelligence

Back to Artificial Intelligence

Next step

Ask for a gap review against ISO/IEC 42001

Tell us which AI systems would be in scope and which management systems you already run. We will suggest a scope, the clauses likely to need the most work and whether certification is worth pursuing now.

Discuss ISO 42001 readiness