Most organisations start AI governance with a policy and a spreadsheet of models. ISO 42001 asks for more: an impact assessment for each system, a reason for every Annex A control you include or leave out, and records showing the cycle has actually run.
This free ISO 42001 checklist is for AI governance leads, CISOs and ISMS managers adding AI to an existing management system, and compliance teams preparing for certification. It runs one year of an AI management system (AIMS) to ISO/IEC 42001:2023, from scope and AI roles through risk and impact assessment, the Statement of Applicability, internal audit and management review to corrective action, with the certification audits if you seek them. The result is an evidence file an auditor can follow from scope to a signed management review.
ISO/IEC 42001:2023, published on 18 December 2023, is the first certifiable management system standard for AI. It follows the same Harmonized Structure as ISO/IEC 27001 and ISO 9001, so clauses 4 to 10 will look familiar. What is new sits in clause 6.1 and the annexes. Annex A lists 38 controls in nine areas, A.2 to A.10. Annex B gives implementation guidance for each control, Annex C lists potential AI objectives and risk sources, and Annex D covers use across sectors.
Clause 4.1 also asks you to determine your role for each AI system. The standard draws on the ISO/IEC 22989 vocabulary of AI providers, producers, customers and partners, which does not line up exactly with the provider and deployer roles in the EU AI Act. A company that trains its own model and also buys a recruitment screening tool holds two roles, and its scope has to show both.
AI risk assessment (6.1.2)
What could stop the AIMS meeting its objectives
Asks: which AI risks matter, how likely they are and how serious, judged against criteria you set in advance.
Guidance: ISO/IEC 23894:2023 on AI risk management; Annex C lists risk sources.
Feeds: risk treatment, the choice of controls and the Statement of Applicability (6.1.3).
AI system impact assessment (6.1.4)
What the system could do to people
Asks: what the potential consequences of an AI system are for individuals, groups of individuals and society, beyond the organisation itself.
Guidance: ISO/IEC 42005:2025, published in May 2025, and the four controls under A.5.
Repeats: at planned intervals and when significant changes are proposed (8.4), with the results kept as documented information.
Accredited certification, 2024 to 2026
Certification bodies now have their own standard
ISO/IEC 42006:2025, published in July 2025, adds AI-specific requirements for bodies that audit and certify an AIMS on top of ISO/IEC 17021-1, including the competence of their auditors. ANAB accredited its first ISO 42001 certification body in September 2024, and UKAS granted its first accreditation, to BSI, on 15 January 2026.
This checklist builds and runs the management system. Classifying each AI system under the law and working through provider and deployer duties belongs to the EU AI Act Compliance Checklist. The AIMS keeps that work owned and reviewed year after year.
What the ISO 42001 Checklist Covers
Six phases run every year. Phase 7 appears only if you are seeking certification.
Phase 1
Phase 1: Context, Scope & AI Roles
The first task records the certification stage and names the two people who sign off the year.
Open the cycle and name the AIMS owner and top management sponsor — record whether you are seeking certification, and at which stage
List the internal and external issues that shape our use of AI (4.1) — AI strategy, customer contracts that ask for certification, ethics commitments, and laws such as the EU AI Act
Record our role for each AI system (4.1) — AI provider, producer, customer or partner in ISO/IEC 22989 terms; many organisations hold more than one
Identify interested parties and the requirements we will meet (4.2) — customers, users, regulators, suppliers and the people an AI system affects
Set the AIMS scope and justify each exclusion (4.3) — systems, units and sites in scope; leaving out the riskiest system will be questioned at stage 1
Phase 2
Phase 2: Leadership, AI Policy & Support
Clauses 5 and 7, with the Annex A areas on policy, internal organisation and resources.
Approve or refresh the AI policy (5.2, A.2) — suited to the organisation’s purpose, framing the AI objectives and aligned with other policies (A.2.3)
Assign AIMS roles, responsibilities and authorities (5.3, A.3.2) — who accepts AI risk, signs off impact assessments, releases a model and reports incidents
Set up a route for reporting concerns about AI systems (A.3.3) — with an owner, a way to escalate and protection for the person who reports
Document the resources and skills each AI system relies on (7.1–7.3, A.4) — data, tooling, computing and people; keep training records for each role
Agree communication and document control for the AIMS (7.4, 7.5) — what is said to whom and when; key documents versioned and approved
Phase 3
Phase 3: AI Risk, Impact & Statement of Applicability
The last task is an approval: the AIMS owner accepts the residual risks before the controls are rolled out.
Define the AI risk criteria and assessment method (6.1.2) — likelihood and consequence scales and acceptance thresholds, set before scoring
Identify, analyse and evaluate the AI risks for each system in scope — data quality, opacity, level of automation, model drift, misuse and dependence on suppliers
Run an AI system impact assessment for each system (6.1.4, A.5) — consequences for individuals, groups of individuals and society, documented and fed into the risk assessment
Choose treatment options and the controls they need (6.1.3) — then compare your controls with all 38 in Annex A so nothing necessary is missed
Produce the Statement of Applicability — each control included or excluded, with the justification and its implementation status
AIMS owner approves the treatment plan and accepts residual risks — every risk has a named owner; the decision is recorded as Approved or Not approved
Phase 4
Phase 4: Objectives, Operation & Life Cycle
Reassess any system that changes significantly, not only at the annual review.
Set measurable AI objectives with owners and dates (6.2) — what, with what resources, by whom, by when and how results are evaluated
Plan changes to the AIMS before making them (6.3) — a new AI use, a reorganisation or a new supplier goes through the cycle, not around it
Apply the life cycle and data controls to each AI system (8.1, A.6, A.7) — verification and validation, deployment, monitoring, event logs, and data quality and provenance
Tell users and other interested parties what they need to know (A.8, A.9) — user documentation, incident communication and each system’s intended use
Allocate responsibilities with suppliers and customers (A.10) — third-party models, data and APIs, and what customers are told
Re-run the risk and impact assessments on significant change (8.2–8.4) — a new model version, new training data, a new purpose or a new group of people affected
The management review is an approval assigned to the top management sponsor named in Phase 1.
Monitor and measure how the AIMS performs (9.1) — what is measured, when and by whom: objectives, incidents, concerns and control results
Plan the internal audit programme (9.2.2) — frequency, methods and responsibilities, weighted by risk and by the results of earlier audits
Audit clauses 4 to 10 and a sample of the applicable controls (9.2.1) — auditors independent of the work, results reported to the managers responsible
Prepare the management review inputs (9.3.2) — earlier actions, changed issues, nonconformity trends, monitoring and audit results
Top management holds the management review and records decisions (9.3.3) — on improvements, changes and resources; approval by the top management sponsor
Phase 6
Phase 6: Nonconformity & Improvement
Open actions carry into next year’s checklist, which starts on an annual schedule.
Log every nonconformity with its source (10.2) — audit findings, incidents, missed objectives, complaints and concerns raised under A.3.3
Contain it, find the root cause and look for similar cases — a biased output from one model may trace to a data practice shared by several
Agree corrective actions with owners and due dates — and update the risk register, impact assessment or Statement of Applicability where the cause lies there
Verify each corrective action worked before closing it — re-test the control and attach the evidence to the finding
Record improvements and schedule the next cycle (10.1) — carry open actions forward and set dates for next year’s audit and review
Phase 7
Phase 7: Certification Audits
Shown only when you are seeking certification; the stage on the first task decides which audit tasks appear.
Confirm the certification body’s accreditation covers ISO/IEC 42001 — check the scope on the register of ANAB, UKAS or another accreditation body
Complete an internal audit and management review before stage 2 — certification bodies expect at least one of each covering the scope
Stage 1: send the documented AIMS and close the gaps it finds — scope, policy, assessment methods, Statement of Applicability and audit records
Stage 2: support the audit of the AIMS in operation — auditors sample controls and follow the records from risk to evidence
Surveillance: prepare the evidence for this year’s visit — audit and review records, objectives, incidents, changes and earlier findings
Recertification: prepare for the full reassessment in year three — reviewing performance across the whole three-year cycle
Answer findings with a corrective action plan — a major nonconformity holds up the certificate until the certification body has checked the fix
Clauses 4 to 10 are requirements. Annex A is a reference list you justify your choices against. The table maps each to typical evidence and the phase that produces it. Certification bodies sample differently, so treat it as a starting point, not legal advice.
Clause or annex
Requirement
Typical evidence
Evidenced in
4.1–4.3
Context, AI roles, interested parties, scope
Issues, roles, scope statement
Phase 1
5.1–5.3
Leadership, AI policy, roles and authorities
Approved AI policy, responsibility matrix
Phase 2
6.1.2
AI risk assessment
Risk criteria, risk register
Phase 3
6.1.3
AI risk treatment and Statement of Applicability
Treatment plan, Statement of Applicability, risk acceptance
Phase 3
6.1.4
AI system impact assessment
One documented assessment per system
Phase 3
6.2, 6.3
AI objectives; planning of changes
Objectives with owners; change records
Phase 4
7.1–7.5
Support, competence and documented information
Training records, document control
Phase 2
8.1–8.4
Operational control; risk and impact assessment in operation
Life cycle records, reassessments after change
Phase 4
9.1
Monitoring, measurement, analysis and evaluation
Metrics and their analysis
Phase 5
9.2
Internal audit
Audit programme and reports
Phase 5
9.3
Management review
Inputs, minutes and decisions
Phase 5
10.1, 10.2
Continual improvement; nonconformity and corrective action
Findings log, root causes, verified actions
Phase 6
Annex A (A.2–A.10)
38 reference controls
Control evidence
Phases 2 to 4
Certification
ISO/IEC 17021-1 and 42006 bind the certification body
Audit reports, action plans
Phase 7
At the time of review, ISO/IEC 42001:2023 was still the first and only edition, with no amendment published. Accreditation bodies were still adding certification bodies to their registers through 2026, so check the scope before you sign a contract. ISO/IEC 42001 is not a harmonised standard under the EU AI Act, so a certificate gives no presumption of conformity with the Act. Nothing on this page is legal advice.
Why Run Your AI Management System in CheckFlow?
1
A Statement of Applicability you can audit
The Statement of Applicability is a table inside its task: one row per Annex A control, with the decision, justification and status. Impact assessments and control evidence are attached to the tasks they prove.
2
The right audit tasks for the year you are in
An annual schedule starts each cycle. Conditional logic shows the certification phase only when you are seeking it, with only the stage 1 and 2, surveillance or recertification tasks that apply this year.
3
Sign-offs that stand up at stage 1
Risk acceptance and the management review are approvals assigned to the AIMS owner and top management sponsor named on the first task. The activity trail shows who decided and when.
CheckFlow is not a GRC platform, a certification body or a legal adviser, and it does not assess your AI systems for you. It runs the cycle and keeps the evidence your auditors sample. CheckFlow’s compliance checklist software applies the same approach to your other standards.
The legal obligations have their own template: the EU AI Act Compliance Checklist classifies each system and works through provider and deployer duties. If you already run an ISMS, the ISO 27001 Compliance Checklist shares the clause structure, and the ISO 27001 Internal Audit Checklist sets out an audit method you can reuse for clause 9.2. Where an AI system processes personal data, run the DPIA Checklist alongside its impact assessment.
Thirty-eight, in nine areas from A.2 to A.10: AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party and customer relationships. They are a reference set, not a mandatory list. You choose controls through risk treatment, compare them with Annex A, and justify each inclusion or exclusion in the Statement of Applicability.
Can we add ISO 42001 to our existing ISO 27001 ISMS?
+
Yes, and the shared clause structure makes it the usual route. Document control, internal audit, management review and corrective action can serve both systems. What does not carry over is the AI-specific work: AI roles, AI risk criteria, the impact assessment and the 38 Annex A controls, which are a different set from ISO 27001’s 93. ISO 42001 does not require ISO 27001 certification, so you can also certify it on its own.
Can one impact assessment cover ISO 42001, a DPIA and a FRIA?
+
They overlap, but each answers a different question. The ISO 42001 impact assessment looks at what an AI system could do to individuals, groups and society, whether or not personal data is involved. A DPIA under GDPR Article 35 covers high-risk processing of personal data. A fundamental rights impact assessment under Article 27 of the EU AI Act applies to some deployers of high-risk systems from 2 December 2027. One document with a section for each can work, provided each section meets its own requirements.
What must be in place before the stage 2 audit?
+
The AIMS has to have run, not just been written. Stage 1 reviews the documented system: scope, AI policy, risk and impact assessment methods and the Statement of Applicability. Stage 2 checks that it works in practice, and certification bodies expect at least one internal audit and one management review covering the scope before it. After certification there is usually a surveillance audit each year and a recertification audit every three years.
Does ISO 42001 apply if we only use AI built by others?
+
Yes. The standard is written for organisations that provide or use AI-based products and services, of any size. As an AI customer, your scope covers how you select, deploy, monitor and retire the systems you buy, and the A.10 controls on suppliers carry more weight. Controls about developing models may not apply, but each exclusion still needs a justification in the Statement of Applicability.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
An AI Management System With the Records to Prove It
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more