ISO 42001 is the first international standard built specifically for AI management systems. If your company builds, deploys, or resells AI-enabled products, and a customer, regulator, or procurement team has started asking how you govern that AI, this standard is the reference point they're increasingly working from. It's new, it's growing fast, and most organizations approaching it have no idea what "compliant" actually requires in practice.
This checklist breaks ISO 42001 down into the concrete requirements auditors and customers will actually ask about. It won't replace a full readiness assessment, but it will tell you where you stand and what to fix first.
What ISO 42001 Actually Covers
ISO 42001 sets requirements for an Artificial Intelligence Management System, or AIMS. Like ISO 27001 does for information security, it asks you to prove that AI risk is identified, governed, and continuously managed, not just documented once and forgotten. It sits alongside, and increasingly overlaps with, obligations under the EU AI Act and the NIST AI Risk Management Framework. None of those three requires the exact same paperwork, but organizations that get ISO 42001 right are usually most of the way toward satisfying the other two as well.
The Checklist
1. AI Policy Signed Off by Leadership
You need a documented AI policy that leadership has actually reviewed and approved, not a boilerplate statement pulled from a template. It should state your organization's stance on acceptable AI use, risk tolerance, and who owns AI-related decisions.
2. Defined Scope of the AI Management System
Which AI systems, teams, and processes fall inside your AIMS. Auditors will ask you to justify what's excluded as much as what's included, so vague scoping is one of the fastest ways to fail an audit.
3. Roles and Responsibilities Assigned
Someone needs to own AI governance day-to-day. This doesn't have to be a full-time hire, but it does have to be a named person or role with real authority to enforce the policy, not just report on it.
4. AI System Inventory
A living list of every AI system in scope: what it does, what data it touches, who built it (in-house or third-party), and what decisions or outputs it produces. Most companies underestimate this list badly the first time they build it, especially once embedded models and vendor tools get counted.
5. Risk Assessment Process
A repeatable method for identifying and scoring AI-specific risks, things like bias, model drift, data quality, misuse, and downstream harm to individuals. This has to be a process you run on a schedule, not a one-time exercise you point to during the audit.
6. Impact Assessments for High-Risk Systems
For AI systems that could meaningfully affect people (hiring decisions, credit decisions, health outcomes, and similar), you need a documented assessment of the potential impact before and during deployment. This is also where ISO 42001 overlaps heavily with EU AI Act high-risk system obligations.
7. Data Governance Controls
Where training and operational data comes from, how it's vetted for quality and bias, and how it's protected. If you're already SOC 2 or ISO 27001 certified, you have a head start here, but AI-specific data controls (like training data provenance) go beyond typical security controls.
8. Third-Party and Supply Chain Management
Most companies don't build their own foundation models, they license, fine-tune, or wrap someone else's. ISO 42001 requires you to assess and manage the AI-specific risk that comes with those vendors, not just their security posture.
9. Human Oversight Mechanisms
A documented way for humans to review, override, or stop an AI system's output or decision. Auditors want to see this is actually usable in practice, not a checkbox that exists on paper only.
10. Incident Response for AI-Specific Failures
Your existing security incident response plan probably doesn't cover a model producing biased outputs, hallucinating in a customer-facing context, or drifting out of spec. ISO 42001 expects a defined process for detecting, logging, and responding to these failure modes specifically.
11. Performance and Continuous Monitoring
Ongoing monitoring of how deployed AI systems actually perform against their intended purpose, including tracking model drift over time. This is a control you run continuously, not something you can produce as a snapshot document.
12. Internal Audit Program
Like other ISO management system standards, 42001 requires periodic internal audits of the AIMS itself, checking that the controls above are operating as designed, not just documented.
13. Management Review Cycle
Leadership needs to formally review the AIMS on a set cadence: what's working, what risks have changed, what needs investment. This is the governance loop that proves the system is alive, not a binder on a shelf.
14. Corrective Action Process
A documented way to track findings (from audits, incidents, or monitoring) through to resolution. Auditors will sample this trail, so gaps between "we found a problem" and "we fixed it" need to be traceable.
Where Most Companies Get Stuck
The controls that trip people up aren't the policy documents, those are straightforward to write. It's the operational pieces: building a complete AI system inventory, running risk assessments on a real cadence, and proving human oversight actually functions rather than exists in a slide deck. These require you to understand how AI is actually used across your organization, which is often murkier than leadership expects.
If you're evaluating whether your organization is ready for a formal ISO 42001 audit, a gap assessment against this checklist is the fastest way to find out where the real work is. Our ISO 42001 readiness assessment maps your current AI governance against the standard's requirements and gives you a prioritized list of what to fix before an auditor sees it. It also fits naturally alongside a broader compliance program if you're managing ISO 42001 next to SOC 2, ISO 27001, or other frameworks at the same time.
If you want to talk through where your AI governance stands today, get in touch and we'll walk you through what a readiness assessment would look like for your systems.