Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What should be on an ISO 42001 readiness checklist?

Last verified

An ISO 42001 readiness checklist maps clauses 4–10 and Annex A themes to checkbox items before Stage 1. Required-by-standard items differ from recommended practice. Not legal advice.

Readiness checklist, last verified 10 September 2026 against ISO/IEC 42001:2023 clauses 4–10 and Annex A. Printable checkbox format. Does not issue certificates. Not legal advice.

Clauses 4–10 — required by the standard

  • ☐ [Required] Clause 4 — context, interested parties, AIMS scope documented.
  • ☐ [Required] Clause 5 — AI policy approved; roles and responsibilities assigned.
  • ☐ [Required] Clause 6 — AI risks and opportunities addressed; objectives set; SoA drafted.
  • ☐ [Required] Clause 7 — competence, awareness, communication, documented information.
  • ☐ [Required] Clause 8 — impact assessments and lifecycle controls operating.
  • ☐ [Required] Clause 9 — monitoring, internal audit, management review completed.
  • ☐ [Required] Clause 10 — nonconformities and corrective action process active.

Annex A themes — SoA selections

Annex A readiness themes (objective required if applicable in SoA)
Annex A themeReadiness itemKind of text
Policies related to AI☐ Overarching AI policy and supporting policiesStandard — if applicable
Internal organization☐ Roles, responsibilities, reporting linesStandard — if applicable
Resources for AI systems☐ Resource plan for data, tooling, peopleStandard — if applicable
Assessing impacts☐ AI system impact assessment processStandard — if applicable
AI system life cycle☐ Lifecycle gates from design to retirementStandard — if applicable
Data for AI systems☐ Data governance and quality criteriaStandard — if applicable
Information for interested parties☐ Transparency and documentation for usersStandard — if applicable
Use of AI systems☐ Operational monitoring and intended useStandard — if applicable
Third-party and customer☐ Supplier and customer responsibility allocationStandard — if applicable

What to do now

  • Print this checklist and assign an owner per clause.
  • Open the evidence-requirements page to map artifacts to each row.
  • Schedule internal audit at least four weeks before Stage 1.

Checklist

  • ☐ All [Required] clause items have an owner and target date?
  • ☐ SoA justifies every Annex A exclusion?
  • ☐ Evidence samples show operation over time, not only policy PDFs?

Where this shows up in ShipReady Metrics

Track checklist items against control-mapped evidence and AI risk register entries. Met-verdict overlay records human accept/reject on evidence rows — a preparation artifact, not an audit certificate.

Frequently asked questions