ISO 42001 checklist: a step-by-step readiness checklist
Use this ISO 42001 checklist to see how ready you are for certification and what's left to do. It follows the standard's requirements in the practical order you'd actually implement them. Part of our guide to ISO 42001 certification.
AramGRC Team·ISO 42001 & Assurance·September 10, 2026·8 min read
Before you start
Two things make the whole programme easier: executive sponsorship (ISO 42001 needs top-management ownership) and a defined scope (which AI systems and processes the management system covers). Settle both first.
The ISO 42001 readiness checklist
Define scope and context — decide which AI systems are in scope and document the issues and interested parties.
Secure leadership and write your AI policy — top-management commitment, an AI policy, and assigned roles.
Build your AI system inventory — a register of every AI system in scope, with owners.
Run AI risk assessments — identify and treat the risks each system creates.
Run AI impact assessments — assess the effect of each system on individuals and groups.
Select and implement Annex A controls — choose the controls that fit your risks and record them in a Statement of Applicability.
Set up data governance and lifecycle controls — data quality and controls across the AI lifecycle.
Establish monitoring, competence and documentation — the support and operation requirements.
Run an internal audit — test yourself against the standard before the certification body does.
Hold a management review — leadership reviews the system's performance and signs off readiness.
Turn the checklist into evidence
A checklist tells you what to do; certification needs evidence that you did it. As you work through each item, keep the records — assessments, minutes, the Statement of Applicability, audit results — because Stage 2 of the audit is an evidence review. See how to get ISO 42001 certified and the full requirements.
How AramGRC helps
AramGRC runs this as a formal ISO/IEC 42001 gap assessment — scoring you against every requirement and Annex A control and handing you a prioritised, certification-ready roadmap, so the checklist becomes a plan.
Frequently asked questions
What is an ISO 42001 checklist?+
A practical list of the steps to become ISO 42001-ready — scope, AI policy, inventory, risk and impact assessments, Annex A controls, internal audit and management review.
How do I prepare for ISO 42001 certification?+
Define scope and get leadership sign-off, inventory and risk-assess your AI, implement the relevant Annex A controls, document everything, then run an internal audit before the certification body's audit.
What is a Statement of Applicability?+
A document that records which Annex A controls you've applied and why — a core ISO 42001 artefact the auditor reviews.
Do I need an internal audit for ISO 42001?+
Yes — clause 9 requires an internal audit and a management review before certification, and doing them well is how you avoid surprises in the certification audit.