help (at) seqmtraining.co.uk [ help (at) seqmtraining.co.uk ]

ISO 42001 Checklist

Organisations developing, deploying, or using artificial intelligence systems face growing pressure to demonstrate responsible governance. ISO 42001 provides the framework for establishing an AI management system (AIMS) that addresses ethical considerations, risk management, and regulatory compliance. This ISO 42001 checklist provides a step-by-step guide to help you meet every requirement, from initial project planning through to external certification. If you are new to the standard, our guide on what is ISO 42001 explains the fundamentals, and our ISO 42001 lead auditor course can prepare your team for implementation and auditing.

This article covers the requirements you need to understand, how to prepare, and 14 steps to achieve and maintain compliance.

Contents

Understanding ISO 42001 Requirements to Stay Compliant

ISO 42001 sets out the requirements for establishing, implementing, maintaining, and continually improving an AI management system. The standard follows the harmonised structure shared across ISO management system standards, with core clauses covering context of the organisation (Clause 4), leadership (Clause 5), planning (Clause 6), support (Clause 7), operation (Clause 8), performance evaluation (Clause 9), and improvement (Clause 10). What distinguishes ISO 42001 from other management system standards is its focus on AI-specific considerations, including AI impact assessments, data governance, transparency, fairness, and the responsible use of AI throughout the system life cycle. For a full breakdown, see our guide to ISO 42001 requirements.

Preparing for ISO 42001 Implementation

Before working through your ISO 42001 checklist, take time to prepare your organisation. Key preparation steps include:

  • Secure leadership commitment – Top management must demonstrate accountability for the AIMS and allocate resources for implementation, including expertise in AI governance and ethics
  • Define the scope – Determine which AI systems, processes, departments, and activities the AIMS will cover. Consider all stages of the AI life cycle, from design and development to deployment and decommissioning
  • Understand your context – Identify internal and external issues relevant to AI use, including regulatory requirements, ethical expectations, stakeholder concerns, and the societal impact of your AI systems
  • Map your AI landscape – Document which AI systems your organisation develops, provides, or uses, along with their purposes, data sources, and decision-making roles

14 Steps to Stay Compliant in ISO 42001

The following ISO 42001 checklist outlines the key steps to implement and maintain your AIMS effectively.

  • Build your ISO 42001 Project Plan – Create a detailed project plan with timelines, milestones, and responsibilities. Define your target certification date and work backwards to set realistic deadlines for each stage of implementation.
  • Define your Artificial Intelligence Management System – Document the scope, boundaries, and applicability of your AIMS. Clearly state which AI systems, processes, locations, and technologies are included, along with any exclusions and their justification.
  • Create an AIMS Team and Allocate Responsibilities – Appoint an AIMS lead and assign roles covering risk assessment, AI impact assessment, policy development, data governance, training, and audit activities.
  • Identify and Catalogue Information Assets – Create an inventory of all AI-related assets, including datasets, models, algorithms, training data, hardware infrastructure, and supporting documentation. Assign ownership to each asset.
  • Carry out a Comprehensive Risk Assessment – Identify risks associated with your AI systems, considering potential harms to individuals, groups, and society. Assess the likelihood and impact of each risk, including bias, privacy violations, lack of transparency, and unintended outcomes.
  • Create and Maintain a Risk Register – Record all identified AI risks, their current status, risk owners, and the controls in place. Update the register as AI systems evolve or new risks are identified.
  • Prepare and Document a Risk Treatment Plan – For each unacceptable risk, decide whether to mitigate, transfer, avoid, or accept it. Document the controls you will apply, including technical safeguards, human oversight mechanisms, and monitoring procedures.
  • Complete the Statement of Applicability (SoA) – The SoA lists all Annex A controls and states whether each is applicable, with justification. This is a mandatory document that auditors will review during certification.
  • Implement AIMS Policies – Develop and implement the required policies, including your AI policy, responsible AI use policy, data management policy, and any others relevant to your scope. Ensure policies address fairness, transparency, and accountability.
  • Establish Ongoing Employee Training – Ensure all relevant personnel understand their AIMS responsibilities, the ethical considerations of AI use, and the organisation’s AI policies. Provide role-specific training for developers, operators, and decision-makers.
  • Conduct an AIMS Internal Audit – Perform internal audits against an ISO 42001 audit checklist to verify your AIMS meets the standard’s requirements before your certification audit. Use findings to drive corrective actions and continual improvement.
  • Perform Management Reviews of the AIMS – Top management must review the AIMS at planned intervals to assess its continuing suitability, adequacy, and effectiveness. Record decisions and actions from each review, including any changes to AI risk appetite or policy.
  • Maintain Required Records – Keep documented evidence of AIMS activities, including AI impact assessments, risk assessments, training records, audit results, management review minutes, and records of AI system performance monitoring.
  • Complete an External Certification Audit for ISO 42001 Compliance – Engage an accredited certification body to conduct your Stage 1 (documentation review) and Stage 2 (implementation audit) assessments. Address any nonconformities to achieve certification.

Enrol in an ISO 42001 Course

Working through an ISO 42001 checklist is more effective when your team has the right training and understanding of AI governance principles. SEQM Training offers a CQI and IRCA certified ISO 42001 Lead Auditor Course to equip auditors and AI professionals with the knowledge and skills needed for AIMS implementation and certification auditing. Use this ISO 42001 checklist alongside professional training to give your organisation the best foundation for compliance.

Frequently Asked Questions

The key steps include defining your AIMS scope, conducting an AI risk assessment, documenting a risk treatment plan and Statement of Applicability, implementing AI governance policies, training personnel, performing internal audits and management reviews, and completing an external certification audit with an accredited body.