7 min read

ISO 42001 Requirements Checklist for Audit Readiness

Featured Image

Quick Answer: This ISO 42001 checklist covers both halves of the standard. The mandatory management system clauses 4 through 10. The 38 Annex A controls across 9 control objectives. Each item names the evidence an auditor asks for, not just the requirement. Work through both halves. Teams routinely prepare one and get caught by the other.

Stage 1 is booked. Somebody asked what the auditor will actually want to see.

The standard answers that question. It does so across clause language and a control annex. That annex is a reference set, not an instruction list.

Print it, share it, work through it. Then read the last section before you assume you are ready.

Key Takeaways

  • ISO 42001 requirements come in two parts. Mandatory clauses 4 to 10, plus the selectable Annex A controls.
  • Annex A holds 38 controls across 9 control objectives, numbered A.2 through A.10.
  • You choose which Annex A controls apply. A Statement of Applicability records every inclusion and exclusion.
  • Auditors sample evidence, not intentions. Every item below names the artifact.
  • BEMO builds and operates the AI management system behind the checklist. Through Stage 2 and beyond.

How the Requirements Are Organized

ISO/IEC 42001:2023 has two halves, and readers routinely miss that both are in scope.

The first half is clauses 4 through 10. These are mandatory requirements for the AI management system itself. Context, leadership, planning, support, operation, performance evaluation, improvement. You do not get to select from these. They follow the same Harmonized Structure ISO uses across management system standards. That is why they feel familiar if you hold ISO 27001.

The second half is Annex A. It contains 38 AI-specific controls grouped under 9 control objectives, numbered A.2 through A.10. Annex A is a reference set. You select the controls that apply based on your risk and impact assessments. Every exclusion goes in a Statement of Applicability with justification.

Annex B is informative implementation guidance for each control. It is not mandatory. Auditors read it, and it shows what good looks like. Annexes C and D add risk-source ideas and sector-specific considerations. Our ISO 42001 requirements reference sets the same ground out by clause.

A note on sourcing: the authoritative text is the standard itself, sold by ISO. New to the standard entirely? Start with what ISO 42001 is and come back. A free ISO 42001 PDF checklist circulating online is a preparation aid, not a substitute. Verify clause numbering and control counts against the published standard first.

Management System Checklist

Clauses 4 through 10. All mandatory. Each item names the evidence.

Context and Scope, Clause 4

Scope is the decision everything else prices off. Get it documented and versioned, then evidence the following:

  • Internal and external issues affecting the AIMS identified and recorded
  • Interested parties listed, including people affected by AI system outputs
  • Scope statement naming AI systems, business units and locations in the boundary
  • Exclusions stated with written justification
  • The organization's role recorded: developer, provider, user, or a combination

Leadership and Policy, Clause 5

Auditors test whether leadership actually engaged, not whether they signed something. Be ready to show:

  • AI policy approved by top management and communicated
  • AI policy consistent with organizational objectives and other policies
  • Roles, responsibilities and authorities assigned and documented
  • A named owner for AI risk, not a committee with no accountability
  • Evidence of leadership involvement: minutes, decisions, resourcing approvals

Planning and Risk, Clause 6

Risk assessment and impact assessment are two separate exercises. Do not collapse them into one document. Clause 6 expects:

  • AI risk assessment process defined, with documented criteria
  • AI risk assessment performed and results recorded
  • AI risk treatment plan with owners and target dates
  • AI system impact assessment process defined and performed
  • Statement of Applicability listing all 38 controls, applicability and justification
  • AI objectives set, measurable, and resourced
  • Change planning documented for changes to the AIMS

Support and Competence, Clause 7

Clause 7 is where most ISO 27001 assets transfer directly. Auditors look for:

  • Resources for the AIMS identified and provided
  • Competence requirements defined per role, with training records
  • Awareness activity evidenced across affected teams
  • Internal and external communication approach documented
  • Document control operating: version, approval, distribution, retention

Operation, Clause 8

Clause 8 covers running the system, not designing it. Evidence should show:

  • Operational planning and control documented for AI processes
  • AI risk assessment performed at planned intervals and after significant change
  • AI risk treatment implemented, with evidence
  • AI system impact assessments performed and kept current
  • Outsourced AI processes identified and controlled

Performance Evaluation, Clause 9

This is the clause that fails audits, because it demands retained output rather than intent:

  • What is monitored and measured defined, with methods and frequency
  • Monitoring output retained for the audit period
  • Internal audit program covering the AIMS, run by independent auditors
  • Internal audit results reported and corrective actions tracked
  • Management review held with documented inputs, decisions and actions

Improvement, Clause 10

Clause 10 asks what you did when something went wrong:

  • Nonconformity process defined, with a working log
  • Corrective actions recorded with root cause and effectiveness check
  • Evidence of continual improvement, not just closed tickets

Those seven clauses are the half teams tend to prepare properly, because they mirror an ISMS. The Annex A half is where the surprises sit.

Annex A Control Checklist

The 38 controls sit in these 9 objectives. Select from them. Justify every exclusion.

A.2 Policies Related to AI

The policy layer, and the first thing an auditor asks to see:

  • AI policy documented, approved and reviewed at planned intervals
  • Alignment with other organizational policies demonstrated

A.3 Internal Organization

Who is accountable, and how concerns reach them:

  • AI roles and responsibilities allocated and communicated
  • A process for reporting AI concerns, with records showing it is used

A.4 Resources for AI Systems

Everything your AI systems consume, documented and current:

  • Documented inventory of AI resources: data, tooling, compute, human resources
  • Resource documentation kept current as systems change

A.5 Assessing Impacts of AI Systems

The control area with no ISO 27001 equivalent, and the one that needs product and legal input:

  • AI system impact assessment process documented
  • Assessments performed, covering individuals, groups and societies
  • Assessment records retained and reassessed on material change

A.6 AI System Life Cycle

The largest control group, covering an AI system from design through production:

  • AI development objectives and design documentation
  • Verification and validation records, including evaluation output
  • Deployment approval records
  • Operation and monitoring records across the audit period
  • Technical documentation maintained for each AI system
  • Event and change logs for models in production

A.7 Data for AI Systems

Where provenance lives, and the area most often reconstructed after the fact:

  • Data management process documented for AI systems
  • Training data provenance recorded
  • Data quality criteria defined and evidenced
  • Data preparation steps documented and repeatable

A.8 Information for Interested Parties

What you tell the people affected by your AI systems:

  • System documentation available to users
  • External reporting mechanism for concerns and incidents
  • Information provided about AI system purpose, limits and intended use

A.9 Use of AI Systems

Governance of the systems you operate, whoever built them:

  • Responsible use policy for AI systems the organization operates
  • Defined objectives for each AI system in use
  • Human oversight arrangements documented and operating

A.10 Third-party and Customer Relationships

Your supply chain is in scope, and so are the obligations you pass on:

  • Supplier assessment covering AI-specific risk
  • Responsibilities allocated between you, your suppliers and your customers
  • Customer-facing obligations documented and met

Work the Annex A list against your Statement of Applicability rather than in isolation. An excluded control still needs a written justification, and that justification is what an auditor tests.

Evidence You Will Be Asked For

Auditors sample artifacts. These are the ones they reach for first:

  • AI system inventory. Current, owned, and covering AI features embedded in third-party SaaS tools. A stale inventory is the fastest way to fail a scope question.
  • Statement of Applicability. All 38 controls listed, applicability marked, exclusions justified. Language that answers why not, without hand-waving.
  • AI system impact assessment records. Per system, with dates showing reassessment after material change.
  • Training data provenance. Where the data came from, what it contains, what checks ran. This one is often reconstructed after the fact, and it shows.
  • Model change logs. Retraining events, prompt changes, provider swaps, version history.
  • Monitoring output. Evaluation runs, drift checks, incident records. Covering the whole audit period, not the week before.
  • Supplier assessments. For every third-party model or AI service in scope. With evidence you asked AI-specific questions.
  • Internal audit and management review records. With findings, decisions and closed actions.

Where a Checklist Stops Being Enough

A checklist tells you what is missing. It does not implement anything, and that gap is where programs die.

Look at which items above fail audits. Almost none of them are documents. They are the continuous ones.

  • Monitoring output is the clearest example. Writing a monitoring policy takes an afternoon. Producing six months of evaluation runs takes six months. There is no shortcut and no way to backfill it.
  • Reassessment after model change is the second. Impact assessments are not files. Retrain the model or swap the provider. The assessment now describes a system that no longer exists. Auditors check dates against change logs.
  • Evidence retention is the third. The unified audit log has a retention setting. If the default is shorter than the audit period, the evidence is gone. Documentation does not replace it.
  • Inventory currency is the fourth, and it degrades without anyone doing anything wrong. Teams adopt tools. Vendors ship AI features into products you already pay for. Two months after you finished the inventory it is incomplete again.
  • Then the organizational reality. Impact assessments need product and legal. Provenance needs data engineering. Monitoring needs whoever runs the models. None report to whoever owns ISO 42001 compliance. Getting their time is the actual constraint.

The steady state is a fraction of a role, permanently. Not a project with a finish date.

Turning the Checklist into a Certificate

Working through this list gives you an accurate gap register. That is useful, and it is where most teams stop.

The certification roadmap covers what happens after the register, and the cost breakdown covers what closing it costs.

If you hold ISO 27001 already, the overlap guide shows which items you can tick off today, and the NIST AI RMF comparison settles the framework question if it is still open.

The items that close on their own are the documents. The items that decide the audit need somebody doing them repeatedly, for months before the auditor arrives. That is what BEMO operates through the AI security foundation service. For the equivalent path on the security side, read how to obtain ISO 27001 certification.

That is the difference between knowing what is missing and being ready.

Book a gap assessment to get this scored against your actual AI systems.

Frequently Asked Questions

Are all ISO 42001 Annex A controls mandatory?

No. The clauses 4 through 10 requirements are mandatory. Annex A is a reference set of 38 controls. You select from it using your risk and impact assessments. Every exclusion needs documented justification in the Statement of Applicability.

What is a Statement of Applicability for ISO 42001?

A document listing every Annex A control, whether it applies, and why. Included controls need implementation status. Excluded controls need justification. The concept mirrors ISO 27001. Confirm the expected format with your certification body before reusing your ISMS template.

How much documentation is enough?

Enough that an auditor can sample it and reach the same conclusion you did. Volume is not the test. A short, current, owned record beats a long one nobody has updated.

Can we reuse our ISO 27001 evidence?

Partly. Risk methodology, internal audit program, management review, document control and corrective action all carry across. AI-specific artifacts do not exist in an ISMS. System inventory, impact assessments, provenance and model monitoring are new work.

Leave us a comment!