ISO 42001 Compliance Checklist
ISO 42001 is the first international standard for AI management systems. Here's how to build an AI Management System (AIMS) that satisfies it.
Book a 20-min deal readiness callInventory your AI systems
List every AI or ML system you build, buy, or embed, including third-party models you call via API. You can't govern what isn't on the list.
Define your AIMS scope
Decide which AI systems, teams, and use cases fall inside your management system boundary.
Assess AI-specific risk
Evaluate risks unique to AI: bias, explainability, data provenance, model drift, and misuse, on top of standard security risk.
Map to your risk appetite
Set thresholds for acceptable AI risk by use case. A recommendation engine and a hiring-decision model carry very different stakes.
Build AI governance policies
Document how models get approved, monitored, retrained, and retired, plus who owns each decision.
Implement lifecycle controls
Add controls at each stage of the AI lifecycle: data sourcing, training, validation, deployment, and monitoring in production.
Run internal audits
Test your AIMS against ISO 42001 requirements before the external audit, the same way you would for ISO 27001.
Certification audit
An accredited certification body reviews your AIMS in a two-stage audit, similar in structure to ISO 27001.
Monitor and iterate
AI systems change faster than most compliance cycles. Continuous monitoring of model behavior and drift keeps your AIMS accurate between audits.
What auditors actually ask for
- Do you have a complete inventory of AI systems, including third-party models?
- Can you show AI-specific risks were assessed, not just security risks?
- Is there a documented approval gate before a model reaches production?
- Can you evidence ongoing monitoring for model drift and bias?
- Who is the accountable owner for each AI system?
Where teams most often trip up
- Inventorying only models you built, missing embedded vendor AI
- Reusing the ISO 27001 risk method without adding AI-specific risk types
- No defined retirement path for deprecated models
- Governance that exists on paper but is bypassed at deployment
- Treating AI governance as a security problem alone rather than including fairness and explainability
Realistic timeline
Typically 4-8 months for a first AIMS, structured like ISO 27001 with a two-stage certification audit.