Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What should be on an ISO 42001 readiness checklist?
Last verifiedAn ISO 42001 readiness checklist maps clauses 4–10 and Annex A themes to checkbox items before Stage 1. Required-by-standard items differ from recommended practice. Not legal advice.
Readiness checklist, last verified 10 September 2026 against ISO/IEC 42001:2023 clauses 4–10 and Annex A. Printable checkbox format. Does not issue certificates. Not legal advice.
Clauses 4–10 — required by the standard
- ☐ [Required] Clause 4 — context, interested parties, AIMS scope documented.
- ☐ [Required] Clause 5 — AI policy approved; roles and responsibilities assigned.
- ☐ [Required] Clause 6 — AI risks and opportunities addressed; objectives set; SoA drafted.
- ☐ [Required] Clause 7 — competence, awareness, communication, documented information.
- ☐ [Required] Clause 8 — impact assessments and lifecycle controls operating.
- ☐ [Required] Clause 9 — monitoring, internal audit, management review completed.
- ☐ [Required] Clause 10 — nonconformities and corrective action process active.
Annex A themes — SoA selections
| Annex A theme | Readiness item | Kind of text |
|---|---|---|
| Policies related to AI | ☐ Overarching AI policy and supporting policies | Standard — if applicable |
| Internal organization | ☐ Roles, responsibilities, reporting lines | Standard — if applicable |
| Resources for AI systems | ☐ Resource plan for data, tooling, people | Standard — if applicable |
| Assessing impacts | ☐ AI system impact assessment process | Standard — if applicable |
| AI system life cycle | ☐ Lifecycle gates from design to retirement | Standard — if applicable |
| Data for AI systems | ☐ Data governance and quality criteria | Standard — if applicable |
| Information for interested parties | ☐ Transparency and documentation for users | Standard — if applicable |
| Use of AI systems | ☐ Operational monitoring and intended use | Standard — if applicable |
| Third-party and customer | ☐ Supplier and customer responsibility allocation | Standard — if applicable |
Recommended practice (not always mandatory documented information)
- ☐ [Recommended] Run a pre-Stage-1 gap review with an independent consultant — not the CB.
- ☐ [Recommended] Map evidence to controls using a crosswalk before audit day.
- ☐ [Recommended] Align AI inventory with AIMS scope boundaries.
What to do now
- Print this checklist and assign an owner per clause.
- Open the evidence-requirements page to map artifacts to each row.
- Schedule internal audit at least four weeks before Stage 1.
Checklist
- ☐ All [Required] clause items have an owner and target date?
- ☐ SoA justifies every Annex A exclusion?
- ☐ Evidence samples show operation over time, not only policy PDFs?
Where this shows up in ShipReady Metrics
Track checklist items against control-mapped evidence and AI risk register entries. Met-verdict overlay records human accept/reject on evidence rows — a preparation artifact, not an audit certificate.