Compyl
GRC Your Way

ISO 42001 Checklist: How to Prepare for Certification Step by Step

Last updated: July 23, 2026

An ISO 42001 checklist walks your organization through every requirement it must satisfy before pursuing certification of its artificial intelligence management system (AIMS): defining scope, securing leadership commitment, assessing AI risks and impacts, implementing the applicable Annex A controls, and completing an internal audit and management review. Working through these items in sequence is the most reliable way to reach audit readiness without gaps. Below is the full checklist, organized into six phases that mirror how successful implementations actually run.

Key takeaways

  • ISO/IEC 42001:2023 certification requires conformity with clauses 4 to 10 of the standard plus every Annex A control you declare applicable in your Statement of Applicability.
  • Annex A contains 38 controls organized under 9 control objectives (A.2 through A.10).
  • Most organizations need 3 to 9 months of preparation before the two-stage certification audit.
  • An internal audit and a management review must both be completed before the certification body arrives.
  • Regulatory pressure, including the EU AI Act, is making ISO 42001 the default evidence of responsible AI governance.

What should an ISO 42001 checklist cover?

A complete checklist mirrors the structure of the standard itself. Clauses 4 to 10 define the mandatory management system requirements: organizational context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A then supplies 38 AI-specific controls that you evaluate for applicability and justify in a Statement of Applicability. If you are new to the standard, start with our overview of what ISO 42001 is and how an AIMS fits into a broader AI governance program.

The checklist below is sequenced deliberately. Skipping ahead to controls before scoping and risk assessment is the single most common cause of audit findings, because auditors trace every control decision back to a documented risk or impact rationale.

Phase 1: How do you scope the AIMS and run a gap analysis?

  • Build an inventory of every AI system you develop, deploy, or consume, including third-party models and AI features embedded in vendor tools.
  • Define the AIMS scope: which entities, products, teams, and AI systems are covered, and which are excluded and why.
  • Identify interested parties (customers, regulators, employees, affected individuals) and document their requirements.
  • Document internal and external context: your role in the AI value chain (provider, deployer, or both), applicable regulation, and organizational climate.
  • Run a gap analysis against clauses 4 to 10 and all 38 Annex A controls, and record current-state evidence for each.
  • Secure executive sponsorship and assign an owner for the certification effort.

Phase 2: What governance and documentation must be in place?

  • Publish an AI policy approved by top management that sets direction for responsible AI development and use.
  • Assign and document roles, responsibilities, and authorities for AI governance, including escalation paths.
  • Set measurable AIMS objectives and plans to achieve them.
  • Allocate resources: budget, tooling, and the people needed to operate the AIMS.
  • Define competence requirements, deliver role-based training, and retain records of both.
  • Stand up an awareness and communication plan covering internal teams and external stakeholders.
  • Implement document control: versioning, ownership, review cadence, and retention for all AIMS documentation.

These items map directly to the leadership, planning, and support requirements in the ISO 42001 requirements, so a completed Phase 2 doubles as evidence for clauses 5, 6, and 7.

Phase 3: How do you assess AI risks and impacts?

  • Adopt and document an AI risk assessment methodology with defined criteria for likelihood, severity, and acceptance.
  • Perform a risk assessment for each in-scope AI system, covering technical, ethical, legal, and operational risk.
  • Perform AI impact assessments that consider consequences for individuals, groups, and society, not just the business.
  • Produce a risk treatment plan that ties every unacceptable risk to a control or mitigation with an owner and deadline.
  • Draft the Statement of Applicability: for each of the 38 Annex A controls, record whether it applies and justify any exclusion.

Phase 4: Which Annex A controls do you implement?

Annex A groups its 38 controls under 9 objectives. Your Statement of Applicability determines which apply, but most organizations implement the large majority. Work through them by domain:

  • A.2: AI policies, including review and alignment with other organizational policies.
  • A.3: Internal organization, covering roles, responsibilities, and reporting of concerns.
  • A.4: Resources for AI systems, including data, tooling, system, computing, and human resources documentation.
  • A.5: AI impact assessment processes and their documentation.
  • A.6: AI system life cycle controls, from requirements and design through verification, deployment, operation, and monitoring.
  • A.7: Data for AI systems, covering acquisition, quality, provenance, and preparation.
  • A.8: Information for interested parties, including system documentation, incident reporting, and communication of impacts.
  • A.9: Responsible use of AI systems, including intended use and human oversight objectives.
  • A.10: Third-party and customer relationships, allocating responsibility across the AI supply chain.

Phase 5: Are you ready for internal audit and management review?

  • Plan and execute an internal audit covering the full AIMS scope, performed by someone independent of the work being audited.
  • Record nonconformities, root causes, and corrective actions, and track them to closure.
  • Hold a management review covering audit results, objective performance, risk status, and improvement opportunities, with documented minutes and decisions.
  • Close or credibly plan remediation for every open gap before scheduling the certification audit.

Phase 6: How do you prepare for the certification audit?

  • Select a certification body accredited for ISO/IEC 42001 (ISO/IEC 42006:2025 defines the requirements these bodies must meet).
  • Schedule the Stage 1 audit: a documentation and readiness review of your scope, policy, Statement of Applicability, and assessment methodology.
  • Remediate any areas of concern raised at Stage 1 before Stage 2.
  • Prepare an evidence pack for Stage 2: records, logs, training files, assessments, meeting minutes, and control evidence.
  • Brief interviewees so process owners can speak to their responsibilities in their own words.

Why is ISO 42001 readiness urgent in 2026?

Regulators are converging on the same expectations the standard codifies. Under the EU AI Act, transparency obligations for chatbots, synthetic media, and emotion recognition apply from August 2, 2026, while the Digital Omnibus agreed in mid-2026 moved most Annex III high-risk obligations to December 2, 2027. Organizations using that extra runway to build a certified AIMS will be in a far stronger position than those starting from zero next year. See our breakdown of EU AI Act compliance for GRC teams for the full timeline.

Frequently asked questions

How long does ISO 42001 implementation take?

Most organizations need 3 to 9 months from gap analysis to audit readiness. Smaller scopes with mature ISO 27001 programs land at the short end; enterprises with many AI systems and no existing management system take longer.

Do we have to implement all 38 Annex A controls?

No, but you must evaluate all 38 and justify any exclusion in your Statement of Applicability. Auditors challenge weak justifications, so exclude a control only when it clearly does not apply to your role or systems.

Can we build on an existing ISO 27001 program?

Yes. ISO 42001 uses the same harmonized management system structure, so document control, internal audit, and management review processes can be extended rather than rebuilt, and many certification bodies offer integrated audits.

What documents will auditors ask for first?

Expect requests for the AIMS scope, AI policy, Statement of Applicability, risk and impact assessments, risk treatment plan, internal audit report, and management review minutes.

Is ISO 42001 certification mandatory under the EU AI Act?

No. Certification is voluntary, but it provides structured evidence of the governance, risk management, and documentation practices the Act expects, and it signals credibility to customers and regulators while harmonized standards are still being finalized.

Turn the checklist into a program

A checklist tells you what to do; keeping it current across dozens of AI systems, owners, and deadlines is the hard part. Compyl gives GRC teams a single platform to manage ISO 42001 readiness end to end, from AI system inventory and risk assessments to control evidence and audit preparation, so certification becomes a byproduct of a governance program that actually runs.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies