MEMO · TO anyone preparing for a certification audit · RE 36 checks against ISO/IEC 42001:2023

Free tool · Governance

Is your AI management system actually ready for an ISO 42001 audit?

36 checks across the seven AIMS clauses and the Annex A controls, taken from the ISO/IEC 42001:2023 standard itself. Check off what you have in place and the readiness score updates as you go. No email required, and nothing you enter leaves your browser.

Why an AIMS, and why the distinction matters

ISO/IEC 42001 does not certify a model. It certifies the management system an organisation runs around every AI system it develops, provides or uses: the policy that sets direction, the risk process that catches problems before they reach customers, and the evidence trail that proves it was done deliberately rather than by accident.

That distinction matters because the properties making AI risky are not the properties of classical IT risk. The standard names three: AI makes automated decisions in ways that are not always transparent or explainable; AI systems are built from data and statistical inference rather than human-coded logic, which changes how they are designed, justified and deployed; and systems that keep learning change their own behaviour after go-live. A management system built for conventional software catches none of that.

The checklist below is ordered the way an auditor works: clause by clause, starting with context and leadership and ending with the Annex A controls that your Statement of Applicability has to account for.

  1. Section 1 of 8

    Context of the Organization

    0 / 4

    Decision rule

    This clause sets scope. If you can't yet name which AI systems and business units the AIMS covers, nothing below is auditable.

  2. Section 2 of 8

    Leadership

    0 / 3

    Decision rule

    This is the prerequisite clause. Without a signed AI Policy and assigned roles, every clause after this one lacks the authority to function.

  3. Section 3 of 8

    Planning and Risk

    0 / 6

    Decision rule

    This is where most first-time audits stall and it carries the most evidence weight of the seven clauses. Complete it fully before moving on.

  4. Section 4 of 8

    Support

    0 / 5

    Decision rule

    This clause is evidence of capacity, not intention. Auditors ask for training records and resourcing decisions, not stated commitments.

  5. Section 5 of 8

    Operation

    0 / 4

    Decision rule

    This clause tests whether Clause 6's plans actually ran. If risk and impact assessments only ever happened at launch, this clause fails.

  6. Section 6 of 8

    Performance Evaluation

    0 / 3

    Decision rule

    The second most common gap after Clause 6. An AIMS that has never been internally audited or formally reviewed cannot demonstrate it works.

  7. Section 7 of 8

    Improvement

    0 / 2

    Decision rule

    Short clause, easy to skip, hard to fake. Auditors want evidence that a nonconformity was found, corrected, and the fix verified.

  8. Section 8 of 8

    Statement of Applicability Readiness

    0 / 9

    Decision rule

    Every unchecked item here needs a documented reason, excluded or not yet built. A missing Statement of Applicability fails Stage 1 regardless of AIMS maturity elsewhere.

Where audits actually stall

Three things worth knowing before you book Stage 1

Clause 6 carries the most evidence weight

Risk assessment, risk treatment and the Statement of Applicability are where most first-time audits stall, because the clause requires evidence that each Annex A control was deliberately included or excluded, not silently passed over. An incomplete or missing Statement of Applicability fails a Stage 1 review regardless of how mature everything else is.

Clause 9 is the second most common gap

Organisations run the management system and never formally review it. One complete internal audit cycle, with an auditor independent of what they are auditing, plus a documented management review, is the step that does most to move an organisation from ready on paper to ready in practice.

Impact assessment is the control most often assumed

AI system impact assessment is the Annex A control most organisations have never formally performed, even where the risks have been considered informally. ISO/IEC 42005:2025, a companion standard published after 42001, now gives auditors a documented methodology for exactly this. If your impact assessments predate it, expect to be asked whether the process itself has been reviewed against it, not only whether an assessment exists.

Where this leads

Closing the gaps is a scoped engagement

This tells you where the evidence trail thins out. Closing it against your own AI systems, risk context and jurisdiction is the ISO/IEC 42001 Certification Support line in the Governance & Assurance consulting track, led by the same Lead Auditor who wrote the checks.

Dr. Jayarethanam Pillai

Before you go

I insisted on the no-email condition, over some internal objection, because a lead-generation form dressed up as a diagnostic is a small dishonesty I did not want attached to a practice with my name on it. These tools score you honestly and tell you where the gap sits, whether or not you ever speak to us afterward. That is closer to how I think a genuine assessment should behave, in a classroom or a boardroom. If the result tells you your organisation is not ready, believe it before you believe anything a vendor tells you next.

Signature, Jayarethanam Pillai