ISO 42001 Compliance Checklist | Certifyi
Compliance checklist

ISO 42001 Compliance Checklist

ISO 42001 is the first international standard for AI management systems. Here's how to build an AI Management System (AIMS) that satisfies it.

Book a 20-min deal readiness call
  1. Inventory your AI systems

    List every AI or ML system you build, buy, or embed, including third-party models you call via API. You can't govern what isn't on the list.

  2. Define your AIMS scope

    Decide which AI systems, teams, and use cases fall inside your management system boundary.

  3. Assess AI-specific risk

    Evaluate risks unique to AI: bias, explainability, data provenance, model drift, and misuse, on top of standard security risk.

  4. Map to your risk appetite

    Set thresholds for acceptable AI risk by use case. A recommendation engine and a hiring-decision model carry very different stakes.

  5. Build AI governance policies

    Document how models get approved, monitored, retrained, and retired, plus who owns each decision.

  6. Implement lifecycle controls

    Add controls at each stage of the AI lifecycle: data sourcing, training, validation, deployment, and monitoring in production.

  7. Run internal audits

    Test your AIMS against ISO 42001 requirements before the external audit, the same way you would for ISO 27001.

  8. Certification audit

    An accredited certification body reviews your AIMS in a two-stage audit, similar in structure to ISO 27001.

  9. Monitor and iterate

    AI systems change faster than most compliance cycles. Continuous monitoring of model behavior and drift keeps your AIMS accurate between audits.

← Back to all checklists

What auditors actually ask for

  • Do you have a complete inventory of AI systems, including third-party models?
  • Can you show AI-specific risks were assessed, not just security risks?
  • Is there a documented approval gate before a model reaches production?
  • Can you evidence ongoing monitoring for model drift and bias?
  • Who is the accountable owner for each AI system?

Where teams most often trip up

  • Inventorying only models you built, missing embedded vendor AI
  • Reusing the ISO 27001 risk method without adding AI-specific risk types
  • No defined retirement path for deprecated models
  • Governance that exists on paper but is bypassed at deployment
  • Treating AI governance as a security problem alone rather than including fairness and explainability

Realistic timeline

Typically 4-8 months for a first AIMS, structured like ISO 27001 with a two-stage certification audit.

Scroll to Top