← Back to blog

ISO 42001 checklist: a step-by-step readiness checklist

ISO 42001 checklist: a step-by-step readiness checklist

Use this ISO 42001 checklist to see how ready you are for certification and what's left to do. It follows the standard's requirements in the practical order you'd actually implement them. Part of our guide to ISO 42001 certification.

AramGRC Team·ISO 42001 & Assurance·September 10, 2026·8 min read

Before you start

Two things make the whole programme easier: executive sponsorship (ISO 42001 needs top-management ownership) and a defined scope (which AI systems and processes the management system covers). Settle both first.

The ISO 42001 readiness checklist

  1. Define scope and contextdecide which AI systems are in scope and document the issues and interested parties.
  2. Secure leadership and write your AI policytop-management commitment, an AI policy, and assigned roles.
  3. Build your AI system inventorya register of every AI system in scope, with owners.
  4. Run AI risk assessmentsidentify and treat the risks each system creates.
  5. Run AI impact assessmentsassess the effect of each system on individuals and groups.
  6. Select and implement Annex A controlschoose the controls that fit your risks and record them in a Statement of Applicability.
  7. Set up data governance and lifecycle controlsdata quality and controls across the AI lifecycle.
  8. Establish monitoring, competence and documentationthe support and operation requirements.
  9. Run an internal audittest yourself against the standard before the certification body does.
  10. Hold a management reviewleadership reviews the system's performance and signs off readiness.

Turn the checklist into evidence

A checklist tells you what to do; certification needs evidence that you did it. As you work through each item, keep the records — assessments, minutes, the Statement of Applicability, audit results — because Stage 2 of the audit is an evidence review. See how to get ISO 42001 certified and the full requirements.

How AramGRC helps

AramGRC runs this as a formal ISO/IEC 42001 gap assessment — scoring you against every requirement and Annex A control and handing you a prioritised, certification-ready roadmap, so the checklist becomes a plan.

Frequently asked questions

What is an ISO 42001 checklist?+

A practical list of the steps to become ISO 42001-ready — scope, AI policy, inventory, risk and impact assessments, Annex A controls, internal audit and management review.

How do I prepare for ISO 42001 certification?+

Define scope and get leadership sign-off, inventory and risk-assess your AI, implement the relevant Annex A controls, document everything, then run an internal audit before the certification body's audit.

What is a Statement of Applicability?+

A document that records which Annex A controls you've applied and why — a core ISO 42001 artefact the auditor reviews.

Do I need an internal audit for ISO 42001?+

Yes — clause 9 requires an internal audit and a management review before certification, and doing them well is how you avoid surprises in the certification audit.

ISO 42001ChecklistCertification
WhatsApp