Photo: Unsplash
ISO 42001 checklist
ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS), published in December 2023. If you have been through ISO 27001, the shape will be familiar: the same Annex SL clause structure, the same certification model, an Annex A of controls you justify.
What is genuinely new is the obligation to assess the impact of your AI systems on individuals and on society, not just on your own organisation. That single requirement is what separates ISO 42001 from every security framework that came before it.
Key takeaways
- ISO 42001 certifies an AI management system, not an AI model or product. You are certified on how you govern AI, not on how good your model is.
- Annex A contains 38 controls across 9 control objectives (A.2 to A.10). Annex B provides implementation guidance, Annex C lists potential objectives and risk sources.
- Clause 6.1.4 requires an AI system impact assessment covering effects on individuals and groups. This has no equivalent in ISO 27001.
- It applies whether you develop, provide, or merely use AI systems. Buying a third-party model does not exempt you.
- It is aligned with, but not a substitute for, the EU AI Act. Certification does not confer legal compliance.
What ISO 42001 is, and what it is not
It is a management system standard. It asks whether you have identified your AI systems, understood their risks and impacts, assigned accountability, controlled the lifecycle, and set up a cycle of review and improvement.
It is not a technical benchmark. There is no accuracy threshold, no bias metric you must hit, no required model architecture. An auditor will not tell you your model is unfair. They will ask how you would know if it were, and what you would do about it.
Who it applies to. The standard deliberately covers organisations across the AI value chain: developers who build systems, providers who supply them, and organisations that simply use AI in their operations. If you have embedded a third-party LLM into your product, you are in scope as a user and as a provider to your own customers.
Part 1: the AIMS requirements (Clauses 4 to 10)
As with ISO 27001, certification is granted against these clauses, not against Annex A. None of them can be excluded.
Clause 4: Context of the organization
- Identify internal and external issues relevant to AI, including regulatory developments
- Identify interested parties: customers, regulated data subjects, affected individuals and groups, regulators, employees
- Define the AIMS scope, naming the AI systems in scope
- Determine your role in the AI value chain (developer, provider, user, or several at once). This determines which Annex A controls are relevant.
Clause 5: Leadership
- Top management commitment, evidenced by resourcing and decisions
- An approved AI policy, distinct from your information security policy
- Roles, responsibilities and authorities for AI governance assigned
Clause 6: Planning
- AI risk assessment, with a documented methodology
- AI system impact assessment (Clause 6.1.4), covering impacts on individuals and society
- AI risk treatment, plus a Statement of Applicability comparing your controls to Annex A
- Measurable AI objectives
- Planning of changes
Clause 7: Support
- Resources, including compute, data and expertise
- Competence: AI-specific skills, which for most organisations means a genuine gap
- Awareness across the organisation about approved and prohibited AI use
- Communication
- Control of documented information
Clause 8: Operation
- Operational planning and control across the AI system lifecycle
- Risk assessments and impact assessments performed at planned intervals and on significant change
- Treatment plans executed with evidence
Clause 9: Performance evaluation
- Monitoring and measurement of AI system performance and of the AIMS
- Internal audit covering the whole AIMS
- Management review with documented inputs, decisions and actions
Clause 10: Improvement
- Continual improvement
- Nonconformity and corrective action, with root cause and verification
The requirement that makes ISO 42001 different
Clause 6.1.4, AI system impact assessment, is the heart of the standard and where most first attempts are weakest.
A security risk assessment asks: what could harm the organisation? An AI system impact assessment asks: what could this system do to the people it affects? Those are different questions with different answers, and reusing your security risk register for this is the most common failure.
An adequate impact assessment considers:
- Affected individuals and groups, including those who never interact with your product directly but are subject to its outputs
- Fairness and discrimination, including proxies for protected characteristics in training data
- Transparency and explainability: can an affected person find out that AI was used, and understand the basis of a decision?
- Human oversight: who can intervene, override or escalate, and are they actually able to
- Accuracy, robustness and failure modes, including behaviour on inputs outside the training distribution
- Privacy, including what personal data entered training and whether it can be extracted
- Societal and environmental effects where relevant to the system's scale and use
- Foreseeable misuse, not just intended use
Practical checklist for this step:
- A documented impact assessment methodology, applied consistently
- One completed assessment per AI system in scope, not one covering all of them
- Assessments reviewed when the model, the data, or the use case changes
- Outputs feeding your risk treatment, not filed and forgotten
- Records retained as evidence, since your auditor will sample them
Part 2: the 38 Annex A controls
Annex A groups 38 controls under nine objectives. Which are applicable depends heavily on your role in the value chain, and you document that decision in a Statement of Applicability exactly as you would for ISO 27001.
| Objective | Focus | What auditors look for |
|---|---|---|
| A.2 Policies related to AI | AI policy and supporting policies | An approved AI policy that is specific, not a paragraph appended to the security policy |
| A.3 Internal organization | Roles, responsibilities, reporting of concerns | Named accountability for each AI system, plus a channel for raising concerns |
| A.4 Resources for AI systems | Data, tooling, compute, human resources documented | An inventory of the resources each system depends on |
| A.5 Assessing impacts of AI systems | Impact assessment process and records | Completed assessments covering individuals and society |
| A.6 AI system life cycle | Responsible development, objectives, design, verification, deployment, operation | Documented lifecycle with gates, including model verification and validation records |
| A.7 Data for AI systems | Data acquisition, quality, provenance, preparation | Provenance for training data, and evidence of quality assessment |
| A.8 Information for interested parties | Documentation, transparency, incident communication | System documentation for users, and disclosure that AI is in use |
| A.9 Use of AI systems | Responsible use, human oversight | Acceptable use rules, and oversight that is genuinely exercisable |
| A.10 Third-party and customer relationships | Supplier and customer responsibilities | Due diligence on model vendors, and allocation of responsibility in contracts |
Two areas that catch teams out:
- A.7 (data). Provenance for training data is a real problem if your models were built on scraped or purchased datasets and nobody recorded where they came from. This cannot be reconstructed later.
- A.10 (third parties). If you build on a third-party foundation model, you need due diligence on that provider and a clear division of responsibility. "We use a major vendor" is not due diligence.
How ISO 42001 differs from ISO 27001
| ISO 27001 | ISO 42001 | |
|---|---|---|
| Protects | The organisation's information | Individuals and society, alongside the organisation |
| Annex A | 93 controls, 4 themes | 38 controls, 9 objectives |
| Distinctive requirement | Risk assessment | AI system impact assessment |
| Scope unit | The ISMS and its information assets | Each AI system, plus your role in the value chain |
| Lifecycle focus | Information lifecycle | AI system lifecycle, including data and model |
| Maturity of ecosystem | Decades of auditors and precedent | New, with auditor experience still developing |
The good news for ISO 27001 holders: Clauses 4 to 10 are structurally identical, so your governance machinery (risk methodology, internal audit programme, management review cadence, document control) transfers directly. Many organisations run a single integrated management system covering both.
The work that does not transfer: the AI inventory, the impact assessments, data provenance, and lifecycle controls. Expect these to be genuinely new.
ISO 42001 and the EU AI Act
These are frequently conflated and should not be.
- The EU AI Act is law. It imposes obligations based on risk classification, with prohibited practices, high-risk system requirements, and transparency duties, phased in over several years.
- ISO 42001 is a voluntary standard. Certification demonstrates you have a governance system, which supports several Act obligations but does not satisfy them by itself.
Work toward the Act has included developing harmonised European standards, and the relationship between those and ISO 42001 has been evolving. Treat ISO 42001 as strong evidence of governance maturity and a useful scaffold, and treat your AI Act obligations as a separate legal analysis with counsel. Do not tell customers that ISO 42001 certification makes you AI Act compliant.
The same logic applies to the NIST AI Risk Management Framework in the US: complementary, voluntary, and mappable to ISO 42001, but a different artefact.
A realistic timeline
For an organisation with an existing ISO 27001 ISMS, six to nine months is achievable. Starting from nothing, nine to fifteen months is more realistic.
- Months 1 to 2: scope, AI system inventory, value chain role, gap analysis
- Months 2 to 4: AI policy approved, risk and impact assessment methodology defined
- Months 3 to 6: impact assessments completed per system, lifecycle and data controls implemented, SoA drafted
- Months 5 to 8: controls generating records, internal audit and management review completed
- Months 7 to 12: Stage 1 and Stage 2 audits
The hardest input to rush is a complete AI system inventory. Shadow AI use across engineering, support, marketing and sales is almost always wider than leadership believes, and you cannot govern a system you have not found.
Where AI governance programmes go wrong
- Reusing the security risk register as the impact assessment. Different question, different answers, and auditors spot it immediately.
- An incomplete AI inventory. Teams adopt tools without approval, and the scope statement becomes untrue.
- Treating it as a documentation exercise. Human oversight has to be genuinely exercisable, not a named role who has never intervened.
- No data provenance. Cannot be reconstructed after the fact.
- Ignoring the user role. Organisations that only consume third-party AI assume they are out of scope. They are not.
- One impact assessment for all systems. The requirement is per system.
- Claiming EU AI Act compliance from certification. A commercial and legal risk.
How SecureSlate helps
SecureSlate maintains your AI system inventory, risk and impact assessments, and control evidence alongside your existing frameworks, so the governance you already run for ISO 27001 or SOC 2 extends to AI rather than duplicating it. Policy acknowledgements, supplier due diligence and review cycles are tracked with dated records an auditor can sample.
Related guides:
- AI governance policy
- What is ISO 42001: everything you need to know
- Who needs ISO 42001 certification
- AI risks in the workplace
- ISO 27001 checklist
FAQ
How many controls are in ISO 42001?
Annex A of ISO/IEC 42001:2023 contains 38 controls organised under 9 control objectives, numbered A.2 through A.10. Annex B gives implementation guidance for them, and Annex C lists potential AI-related objectives and risk sources.
Is ISO 42001 certifiable?
Yes. It is a management system standard with the same Annex SL structure as ISO 27001, and accredited certification bodies audit it in a Stage 1 and Stage 2 process with a three-year cycle.
Does ISO 42001 apply if we only use third-party AI?
Yes. The standard covers organisations that develop, provide or use AI systems. If you have embedded a third-party model in your product, you are in scope, and Annex A.10 on third-party relationships becomes central.
Does ISO 42001 certification mean we comply with the EU AI Act?
No. The AI Act is legislation with its own obligations based on risk classification. ISO 42001 certification is strong evidence of a governance system and supports several of those obligations, but it is not legal compliance and should not be presented as such.
Can we add ISO 42001 to an existing ISO 27001 certification?
Yes, and this is the common path. Clauses 4 to 10 are structurally the same, so your risk methodology, internal audit programme, management review and document control transfer. The new work is the AI inventory, impact assessments, data provenance and lifecycle controls.
What is an AI system impact assessment?
A documented assessment, required by Clause 6.1.4, of the potential consequences of an AI system for individuals and groups of individuals, and where relevant for society. It covers fairness, transparency, human oversight, accuracy, privacy and foreseeable misuse, and it is distinct from an information security risk assessment.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory, or professional advice, and it is not a substitute for the text of ISO/IEC 42001:2023. AI regulation is developing quickly and obligations vary by jurisdiction and use case. Consult an accredited certification body and qualified legal advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
