ISO 42001 AI Management System Checklist Template

Most organisations start AI governance with a policy and a spreadsheet of models. ISO 42001 asks for more: an impact assessment for each system, a reason for every Annex A control you include or leave out, and records showing the cycle has actually run.

This free ISO 42001 checklist is for AI governance leads, CISOs and ISMS managers adding AI to an existing management system, and compliance teams preparing for certification. It runs one year of an AI management system (AIMS) to ISO/IEC 42001:2023, from scope and AI roles through risk and impact assessment, the Statement of Applicability, internal audit and management review to corrective action, with the certification audits if you seek them. The result is an evidence file an auditor can follow from scope to a signed management review.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

What ISO 42001 Adds to a Management System

ISO/IEC 42001:2023, published on 18 December 2023, is the first certifiable management system standard for AI. It follows the same Harmonized Structure as ISO/IEC 27001 and ISO 9001, so clauses 4 to 10 will look familiar. What is new sits in clause 6.1 and the annexes. Annex A lists 38 controls in nine areas, A.2 to A.10. Annex B gives implementation guidance for each control, Annex C lists potential AI objectives and risk sources, and Annex D covers use across sectors.

Clause 4.1 also asks you to determine your role for each AI system. The standard draws on the ISO/IEC 22989 vocabulary of AI providers, producers, customers and partners, which does not line up exactly with the provider and deployer roles in the EU AI Act. A company that trains its own model and also buys a recruitment screening tool holds two roles, and its scope has to show both.

AI risk assessment (6.1.2)

What could stop the AIMS meeting its objectives

Asks: which AI risks matter, how likely they are and how serious, judged against criteria you set in advance.

Guidance: ISO/IEC 23894:2023 on AI risk management; Annex C lists risk sources.

Feeds: risk treatment, the choice of controls and the Statement of Applicability (6.1.3).

AI system impact assessment (6.1.4)

What the system could do to people

Asks: what the potential consequences of an AI system are for individuals, groups of individuals and society, beyond the organisation itself.

Guidance: ISO/IEC 42005:2025, published in May 2025, and the four controls under A.5.

Repeats: at planned intervals and when significant changes are proposed (8.4), with the results kept as documented information.

Accredited certification, 2024 to 2026

Certification bodies now have their own standard

ISO/IEC 42006:2025, published in July 2025, adds AI-specific requirements for bodies that audit and certify an AIMS on top of ISO/IEC 17021-1, including the competence of their auditors. ANAB accredited its first ISO 42001 certification body in September 2024, and UKAS granted its first accreditation, to BSI, on 15 January 2026.

This checklist builds and runs the management system. Classifying each AI system under the law and working through provider and deployer duties belongs to the EU AI Act Compliance Checklist. The AIMS keeps that work owned and reviewed year after year.

What the ISO 42001 Checklist Covers

Six phases run every year. Phase 7 appears only if you are seeking certification.

Phase 1

Phase 1: Context, Scope & AI Roles

The first task records the certification stage and names the two people who sign off the year.

  • Open the cycle and name the AIMS owner and top management sponsor — record whether you are seeking certification, and at which stage
  • List the internal and external issues that shape our use of AI (4.1) — AI strategy, customer contracts that ask for certification, ethics commitments, and laws such as the EU AI Act
  • Record our role for each AI system (4.1) — AI provider, producer, customer or partner in ISO/IEC 22989 terms; many organisations hold more than one
  • Identify interested parties and the requirements we will meet (4.2) — customers, users, regulators, suppliers and the people an AI system affects
  • Set the AIMS scope and justify each exclusion (4.3) — systems, units and sites in scope; leaving out the riskiest system will be questioned at stage 1
Phase 2

Phase 2: Leadership, AI Policy & Support

Clauses 5 and 7, with the Annex A areas on policy, internal organisation and resources.

  • Approve or refresh the AI policy (5.2, A.2) — suited to the organisation’s purpose, framing the AI objectives and aligned with other policies (A.2.3)
  • Assign AIMS roles, responsibilities and authorities (5.3, A.3.2) — who accepts AI risk, signs off impact assessments, releases a model and reports incidents
  • Set up a route for reporting concerns about AI systems (A.3.3) — with an owner, a way to escalate and protection for the person who reports
  • Document the resources and skills each AI system relies on (7.1–7.3, A.4) — data, tooling, computing and people; keep training records for each role
  • Agree communication and document control for the AIMS (7.4, 7.5) — what is said to whom and when; key documents versioned and approved
Phase 3

Phase 3: AI Risk, Impact & Statement of Applicability

The last task is an approval: the AIMS owner accepts the residual risks before the controls are rolled out.

  • Define the AI risk criteria and assessment method (6.1.2) — likelihood and consequence scales and acceptance thresholds, set before scoring
  • Identify, analyse and evaluate the AI risks for each system in scope — data quality, opacity, level of automation, model drift, misuse and dependence on suppliers
  • Run an AI system impact assessment for each system (6.1.4, A.5) — consequences for individuals, groups of individuals and society, documented and fed into the risk assessment
  • Choose treatment options and the controls they need (6.1.3) — then compare your controls with all 38 in Annex A so nothing necessary is missed
  • Produce the Statement of Applicability — each control included or excluded, with the justification and its implementation status
  • AIMS owner approves the treatment plan and accepts residual risks — every risk has a named owner; the decision is recorded as Approved or Not approved
Phase 4

Phase 4: Objectives, Operation & Life Cycle

Reassess any system that changes significantly, not only at the annual review.

  • Set measurable AI objectives with owners and dates (6.2) — what, with what resources, by whom, by when and how results are evaluated
  • Plan changes to the AIMS before making them (6.3) — a new AI use, a reorganisation or a new supplier goes through the cycle, not around it
  • Apply the life cycle and data controls to each AI system (8.1, A.6, A.7) — verification and validation, deployment, monitoring, event logs, and data quality and provenance
  • Tell users and other interested parties what they need to know (A.8, A.9) — user documentation, incident communication and each system’s intended use
  • Allocate responsibilities with suppliers and customers (A.10) — third-party models, data and APIs, and what customers are told
  • Re-run the risk and impact assessments on significant change (8.2–8.4) — a new model version, new training data, a new purpose or a new group of people affected
Phase 5

Phase 5: Monitoring, Internal Audit & Management Review

The management review is an approval assigned to the top management sponsor named in Phase 1.

  • Monitor and measure how the AIMS performs (9.1) — what is measured, when and by whom: objectives, incidents, concerns and control results
  • Plan the internal audit programme (9.2.2) — frequency, methods and responsibilities, weighted by risk and by the results of earlier audits
  • Audit clauses 4 to 10 and a sample of the applicable controls (9.2.1) — auditors independent of the work, results reported to the managers responsible
  • Prepare the management review inputs (9.3.2) — earlier actions, changed issues, nonconformity trends, monitoring and audit results
  • Top management holds the management review and records decisions (9.3.3) — on improvements, changes and resources; approval by the top management sponsor
Phase 6

Phase 6: Nonconformity & Improvement

Open actions carry into next year’s checklist, which starts on an annual schedule.

  • Log every nonconformity with its source (10.2) — audit findings, incidents, missed objectives, complaints and concerns raised under A.3.3
  • Contain it, find the root cause and look for similar cases — a biased output from one model may trace to a data practice shared by several
  • Agree corrective actions with owners and due dates — and update the risk register, impact assessment or Statement of Applicability where the cause lies there
  • Verify each corrective action worked before closing it — re-test the control and attach the evidence to the finding
  • Record improvements and schedule the next cycle (10.1) — carry open actions forward and set dates for next year’s audit and review
Phase 7

Phase 7: Certification Audits

Shown only when you are seeking certification; the stage on the first task decides which audit tasks appear.

  • Confirm the certification body’s accreditation covers ISO/IEC 42001 — check the scope on the register of ANAB, UKAS or another accreditation body
  • Complete an internal audit and management review before stage 2 — certification bodies expect at least one of each covering the scope
  • Stage 1: send the documented AIMS and close the gaps it finds — scope, policy, assessment methods, Statement of Applicability and audit records
  • Stage 2: support the audit of the AIMS in operation — auditors sample controls and follow the records from risk to evidence
  • Surveillance: prepare the evidence for this year’s visit — audit and review records, objectives, incidents, changes and earlier findings
  • Recertification: prepare for the full reassessment in year three — reviewing performance across the whole three-year cycle
  • Answer findings with a corrective action plan — a major nonconformity holds up the certificate until the certification body has checked the fix

ISO 42001 Clauses Mapped to the Checklist

Clauses 4 to 10 are requirements. Annex A is a reference list you justify your choices against. The table maps each to typical evidence and the phase that produces it. Certification bodies sample differently, so treat it as a starting point, not legal advice.

Clause or annex Requirement Typical evidence Evidenced in
4.1–4.3Context, AI roles, interested parties, scopeIssues, roles, scope statementPhase 1
5.1–5.3Leadership, AI policy, roles and authoritiesApproved AI policy, responsibility matrixPhase 2
6.1.2AI risk assessmentRisk criteria, risk registerPhase 3
6.1.3AI risk treatment and Statement of ApplicabilityTreatment plan, Statement of Applicability, risk acceptancePhase 3
6.1.4AI system impact assessmentOne documented assessment per systemPhase 3
6.2, 6.3AI objectives; planning of changesObjectives with owners; change recordsPhase 4
7.1–7.5Support, competence and documented informationTraining records, document controlPhase 2
8.1–8.4Operational control; risk and impact assessment in operationLife cycle records, reassessments after changePhase 4
9.1Monitoring, measurement, analysis and evaluationMetrics and their analysisPhase 5
9.2Internal auditAudit programme and reportsPhase 5
9.3Management reviewInputs, minutes and decisionsPhase 5
10.1, 10.2Continual improvement; nonconformity and corrective actionFindings log, root causes, verified actionsPhase 6
Annex A (A.2–A.10)38 reference controlsControl evidencePhases 2 to 4
CertificationISO/IEC 17021-1 and 42006 bind the certification bodyAudit reports, action plansPhase 7

At the time of review, ISO/IEC 42001:2023 was still the first and only edition, with no amendment published. Accreditation bodies were still adding certification bodies to their registers through 2026, so check the scope before you sign a contract. ISO/IEC 42001 is not a harmonised standard under the EU AI Act, so a certificate gives no presumption of conformity with the Act. Nothing on this page is legal advice.

Why Run Your AI Management System in CheckFlow?

1

A Statement of Applicability you can audit

The Statement of Applicability is a table inside its task: one row per Annex A control, with the decision, justification and status. Impact assessments and control evidence are attached to the tasks they prove.

2

The right audit tasks for the year you are in

An annual schedule starts each cycle. Conditional logic shows the certification phase only when you are seeking it, with only the stage 1 and 2, surveillance or recertification tasks that apply this year.

3

Sign-offs that stand up at stage 1

Risk acceptance and the management review are approvals assigned to the AIMS owner and top management sponsor named on the first task. The activity trail shows who decided and when.

CheckFlow is not a GRC platform, a certification body or a legal adviser, and it does not assess your AI systems for you. It runs the cycle and keeps the evidence your auditors sample. CheckFlow’s compliance checklist software applies the same approach to your other standards.

The legal obligations have their own template: the EU AI Act Compliance Checklist classifies each system and works through provider and deployer duties. If you already run an ISMS, the ISO 27001 Compliance Checklist shares the clause structure, and the ISO 27001 Internal Audit Checklist sets out an audit method you can reuse for clause 9.2. Where an AI system processes personal data, run the DPIA Checklist alongside its impact assessment.

Frequently Asked Questions

How many controls are in ISO 42001 Annex A?

+

Thirty-eight, in nine areas from A.2 to A.10: AI policy, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems, and third-party and customer relationships. They are a reference set, not a mandatory list. You choose controls through risk treatment, compare them with Annex A, and justify each inclusion or exclusion in the Statement of Applicability.

Can we add ISO 42001 to our existing ISO 27001 ISMS?

+

Yes, and the shared clause structure makes it the usual route. Document control, internal audit, management review and corrective action can serve both systems. What does not carry over is the AI-specific work: AI roles, AI risk criteria, the impact assessment and the 38 Annex A controls, which are a different set from ISO 27001’s 93. ISO 42001 does not require ISO 27001 certification, so you can also certify it on its own.

Can one impact assessment cover ISO 42001, a DPIA and a FRIA?

+

They overlap, but each answers a different question. The ISO 42001 impact assessment looks at what an AI system could do to individuals, groups and society, whether or not personal data is involved. A DPIA under GDPR Article 35 covers high-risk processing of personal data. A fundamental rights impact assessment under Article 27 of the EU AI Act applies to some deployers of high-risk systems from 2 December 2027. One document with a section for each can work, provided each section meets its own requirements.

What must be in place before the stage 2 audit?

+

The AIMS has to have run, not just been written. Stage 1 reviews the documented system: scope, AI policy, risk and impact assessment methods and the Statement of Applicability. Stage 2 checks that it works in practice, and certification bodies expect at least one internal audit and one management review covering the scope before it. After certification there is usually a surveillance audit each year and a recertification audit every three years.

Does ISO 42001 apply if we only use AI built by others?

+

Yes. The standard is written for organisations that provide or use AI-based products and services, of any size. As an AI customer, your scope covers how you select, deploy, monitor and retire the systems you buy, and the A.10 controls on suppliers carry more weight. Controls about developing models may not apply, but each exclusion still needs a justification in the Statement of Applicability.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

An AI Management System With the Records to Prove It

Free trial — no credit card required.