Konfirmity

Part of the ISO 42001 compliance guide

The ISO 42001 Checklist: A Step-by-Step Path to Certification

Tanmay Naik

Tanmay Naik

Updated 2026-09-08

The ISO 42001 Checklist: A Step-by-Step Path to Certification

An ISO 42001 checklist turns the standard into a sequence you can work through: define your AI management system scope, run a gap analysis, write the mandatory documents, implement the applicable Annex A controls, operate the system long enough to generate records, then pass a two-stage certification audit. Five phases, one accredited certificate at the end. ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system (AIMS); its certifiable requirements live in clauses 4 to 10, and Annex A supplies 38 reference controls across 9 objectives you select through a Statement of Applicability. Our ISO 42001 guide explains what the standard is and why buyers ask for it; this page is the do-list, with the ordered steps and the exact inventory of documents and records an auditor expects to see. Every item below is a box you can tick as you go.

TL;DR

  • The checklist runs in five phases: scope and gap analysis, build the AIMS, implement controls, internal audit and management review, then the certification audit.
  • The AIMS scope statement and the Statement of Applicability are the two documents auditors read first.
  • ISO 42001 requires a defined set of documents (policy, scope, risk and impact assessments, data procedures, SoA, audit programme) and a set of retained records that prove the system operates.
  • Certification is a Stage 1 and Stage 2 audit by an accredited body; the certificate is valid for three years.
  • Budget four to nine months, shorter if you already hold ISO 27001, because the management-system machinery already exists.
  • Every step on this page is a tickable checkbox: work through it in the browser, then export your completed checklist.
0 of 42 complete

The ISO 42001 Checklist: Five Phases to Certification

These five phases are the ISO 42001 implementation steps in the order most teams run them. Nothing here reinvents the ISO playbook; it is the same Plan-Do-Check-Act rhythm as ISO 27001, pointed at AI. Most organizations move through it in four to nine months. If you already hold ISO 27001, expect the shorter end, because the risk methodology, the audit cadence, and the leadership structure are already in place and you are mostly extending them to cover AI.

The phases:

  1. Scope and gap analysis - decide what the AIMS covers and find what is missing.
  2. Build the AIMS - write the mandatory documents and stand up the processes.
  3. Implement the controls - apply the Annex A controls your risk work justifies.
  4. Internal audit and management review - test the system yourself before an auditor does.
  5. Certification audit - pass the Stage 1 and Stage 2 assessment.
1

Scope and gap analysis

AIMS scope statement, ranked remediation plan

2

Build the AIMS

Eight mandatory documents

3

Implement the controls

Statement of Applicability, controls in live workflows

4

Internal audit and management review

Audit results, review minutes, corrective actions

5

Certification audit

Stage 1 and Stage 2 passed, three-year certificate

Work them in order. Each phase produces the inputs the next one needs, and skipping ahead is the fastest way to fail a Stage 2 audit.

Phase 1: Scope the AIMS and Run a Gap Analysis

0 of 7 items complete in this phase

The first phase decides how big the job is. A tight, defensible scope and an honest gap analysis are worth more than an ambitious plan you cannot evidence later.

Define the AIMS Scope

The AIMS scope statement is a mandatory document (clause 4.3) and the first thing an auditor reads. It records which AI systems sit inside the management system, the internal and external issues that shape your AI, and the interested parties you answer to. You do not have to put every model in scope on day one; you have to draw a boundary you can actually run and prove.

Run an ISO 42001 Gap Analysis

A gap analysis compares your current AI governance against clauses 4 to 10 and the 38 Annex A controls, then turns the differences into a ranked remediation plan. The output is your project backlog for phases 2 and 3. A usable ISO 42001 gap analysis assesses three things in the same pass: the policies and documented information you hold, the technical controls actually running in your AI systems, and the governance routines that keep both current, which is to say who reviews what, how often, and on what record. Score each line as met, partial or absent rather than pass or fail; partial is where most of the real work sits. The mechanics are the same as an information-security gap assessment, so our ISO 27001 gap assessment guide is a useful model for how to scope and score one.

Phase 2: Build the AIMS and Its Mandatory Documents

0 of 16 items complete in this phase

With the gaps mapped, you build the system. Most of the work in this phase is documentation the standard explicitly requires. An AIMS is the same species of management system as an ISMS, so if you have written information-security documentation before, the format will feel familiar; only the subject matter (AI risk, impact, and lifecycle) is new. For the full clause-by-clause detail behind each item below, see our ISO 42001 requirements breakdown.

ISO 42001 Mandatory Documents and Records

The standard distinguishes documents you maintain (living artefacts an auditor can inspect) from records you retain (evidence that the system actually ran). You need both. Here are the ISO 42001 mandatory documents to author:

Where the standard asks for itWhat the auditor checks
Clause 5.2, Annex A.2That top management owns it, that it has been reviewed, and that it says something specific about your AI rather than restating the standard
Clause 4.3That the boundary is explicit, that it names the systems in and out, and that you can run everything inside it
Not named as its own clause; it is how you evidence the scope at 4.3That every system in the scope statement appears, with an owner and a lifecycle stage
Clause 6.1.2That the method is written down before the results, and that the same method was applied to every system
Clauses 6.1.4 and 8.4That impacts on individuals and society are assessed, not just risks to the business
Annex A.7That provenance, quality and preparation are covered for the data each in-scope system uses
Clause 6.1.3That every one of the 38 controls carries an include or exclude decision with a reason tied back to the risk work
Clause 9.2That the programme exists as a plan, with scope, frequency and independence, separately from the audit results

And the records to retain as proof the AIMS operates:

Where the standard asks for itWhat it proves
Clause 6.1.2The method was actually run, not just written
Clause 6.1.3Each accepted risk has a decision behind it
Clauses 6.1.4 and 8.4Impact assessments happened at the point the lifecycle required them
Clause 7.2The people running the AIMS are qualified to run it
Clause 9.1The system is being watched between audits
Clause 9.2You tested yourself before the certification body did
Clause 9.3Leadership reviewed the AIMS and made decisions
Clause 10.2Problems were found, logged and closed

The Statement of Applicability deserves special attention: it is the bridge between your risk work and Annex A, and auditors treat it as the map of your whole control set.

Free download: XLSX-ready checklist and PDF

The ISO 42001 Implementation Checklist

All five phases, the eight mandatory documents and eight retained records with their clause references, and the 38 Annex A controls, in a printable checklist you can assign owners in and hand to an auditor.

Phase 3: Implement the Annex A Controls

0 of 4 items complete in this phase

Annex A lists 38 controls grouped into 9 objectives (A.2 to A.10). You do not implement all 38 by default. You select the ones your risk and impact assessments justify, record every include-or-exclude decision with its rationale in the Statement of Applicability, then put the selected controls into real workflows rather than into a document nobody follows. For the full catalogue and what each control asks for, see our guide to the ISO 42001 Annex A controls.

Phase 4: Internal Audit and Management Review

0 of 4 items complete in this phase

An auditor cannot certify a system that has never run. Before Stage 1, the AIMS has to operate long enough to produce genuine records, then you test it against itself. Clause 9 makes both the internal audit and the management review mandatory, and this phase is where readiness is actually earned rather than assumed.

Phase 5: The Two-Stage Certification Audit

0 of 4 items complete in this phase

ISO 42001 certification follows the same accredited, two-stage path as any ISO management system. Stage 1 is a documentation and readiness review; Stage 2 tests whether the AIMS operates as designed, with the auditor sampling evidence across your controls. A clean result earns a certificate valid for three years, with annual surveillance audits in between. The details of choosing a body and what each stage samples are in our ISO 42001 certification walkthrough.

Export my completed checklist

Download your own progress (0 of 42 ticked) as a CSV you can open in Excel or Sheets and hand to your team. Nothing is sent anywhere -- the file is built in your browser from what you've ticked above.

Get the ISO 42001 Checklist for Your Role

The five phases above apply to every organization pursuing ISO 42001, but what the AIMS actually has to govern differs by what you do with AI. Pick the checklist that matches your role:

For AI builders

ISO 42001 Implementation Checklist for AI Builders

For companies designing, training, or fine-tuning their own models: data provenance, reproducibility, model lifecycle documentation, and deployment monitoring, mapped to clause or Annex A control.

For AI deployers

ISO 42001 Implementation Checklist for AI Deployers

For companies embedding frontier or third-party models: provider due diligence, data boundaries, runtime guardrails, and the split of responsibility with your model provider.

For auditors and advisors

ISO 42001 Audit Checklist for Certification Providers

For assessors and advisory teams running an ISO 42001 engagement: a clause-mapped path from scoping through Stage 1 and Stage 2 to a defensible certification recommendation.

Want us to map your AI systems to this checklist?

Share your work email and we'll walk your AI inventory against the five phases and flag where you're already covered by existing ISO 27001 or SOC 2 work.

We check that your email domain is real and can receive mail before sending. If we can't verify it, we won't be able to follow up — so please use a work address rather than a forwarding or temporary one.

We'd like to know who we're talking to. By submitting this form you agree that we may contact you about Konfirmity — no more than six emails a year, and we won't ask again each time. You can unsubscribe from any of them, and we'll stop. See our Privacy Policy.

Are You Ready? An ISO 42001 Readiness Check

0 of 7 items complete in this phase

Before you book Stage 1, run this ISO 42001 readiness self-check. If you can answer yes to every line, you are audit-ready; a no is a gap to close first.

The most common reason teams fail this check is the last mile of Phase 4: the documents exist, but the system has not run long enough to leave a trail. Give yourself a real operating window before you invite an auditor in.

Frequently Asked Questions

There is no single magic number, and published counts differ widely, but the practical core is the eight documents in Phase 2 (AI policy, AIMS scope statement, AI system inventory, risk assessment, impact assessment, data procedures, Statement of Applicability, and the internal audit programme), plus the eight retained records that prove each of those processes actually ran. Documents show the system was designed; records show it operated. Treat them as one set, because auditors check for both, and a complete document set with no records behind it is the most common way to fail a Stage 2 audit.

No. The standard does not name a gap analysis as a required document. In practice it is the sensible first move, because it tells you exactly which clauses and controls you still have to build before you spend money on an audit.

No. Annex A is a reference set, not a mandatory list. You select the controls your risk and impact assessments justify and document every inclusion and exclusion in the Statement of Applicability. Ticking all 38 without reasoning is a red flag to an auditor, not a shortcut.

Largely, yes. Both standards use the same Harmonized Structure, so your risk methodology, internal-audit programme, management-review cadence, and competence records carry over. You extend them to cover AI risk, impact, and lifecycle rather than starting from a blank page, which is why holding ISO 27001 compresses the timeline. Our ISO 27001 documentation toolkit shows how that document set is structured.

Four to nine months for most organizations. Teams already certified to ISO 27001 tend to land at the shorter end; teams building a management system for the first time should plan for the longer end, since the foundation has to be built before the AI-specific work begins.

At Stage 2 the auditor samples rather than reads everything, so the evidence has to survive being picked at random: completed impact assessments with dates, risk treatment decisions traceable to the Statement of Applicability, monitoring output from the period under review, competence records for the named AIMS owners, internal audit findings with their corrective actions closed out, and management review minutes showing decisions rather than attendance. Evidence generated in the week before the audit reads as exactly that, which is why Phase 4 asks you to run the system for a real operating window first.

Yes. The checklist on this page is free to work through in the browser, and the same content is available as a free PDF: the five phases as a tracker, the mandatory documents and records with their clause references, and all 38 Annex A controls set up as a Statement of Applicability. Use the download block above, or export your own ticked progress as a CSV directly from this page.

Turn this checklist into a certificate

Book a demo and we'll map your AI systems to the checklist together, self-serve or with our CISO-led team running the AIMS build for you.

Book a demo

Conclusion

The ISO 42001 checklist is not complicated, but it is unforgiving about order and evidence: scope it, find the gaps, write the documents, apply the controls your risk work justifies, run the system until it leaves a trail, and only then invite the auditor. The teams that struggle are the ones that document without operating.

Konfirmity is a security-driven compliance platform for AI governance and the frameworks around it: ISO 27001, SOC 2 and HIPAA out of the box, and ISO 42001 through the custom-framework engine, run self-serve or with the fully-managed service where our team runs the program for you. The team behind Konfirmity has supported more than 6,000 security audits, and with managed delivery we build the AIMS inside your stack, write the mandatory documents, and collect the records with you, so your team spends hours rather than months.

Tools

Put your ISO 42001 plan into numbers

More ISO 42001 guides

Related Articles

ISO 42001 Controls: The 38 Annex A Controls, Explained

Security Controls & Practices

samkit-jain

2026-07-11

ISO 42001 Controls: The 38 Annex A Controls, Explained

arrow

A reference to the ISO 42001 controls: all 38 Annex A controls across nine objectives (A.2 to A.10), what each requires, and the evidence auditors expect.

The ISO 42001 AI Impact Assessment: The Control With the Least Precedent

Risk & Incidents

amit-gupta

2026-10-05

The ISO 42001 AI Impact Assessment: The Control With the Least Precedent

arrow

An ISO 42001 AI impact assessment asks what your system does to people, not to your business. What separates it from risk assessment, and when to re-run it.

ISO 42001 Internal Audit: Auditing an AIMS That Keeps Changing

Audit & Readiness

amit-gupta

2026-10-05

ISO 42001 Internal Audit: Auditing an AIMS That Keeps Changing

arrow

How to run an ISO 42001 internal audit: plan the audit programme, staff it independently, and sample an AI estate that changes between audit and report.

The ISO 42001 Statement of Applicability: Decisions and Reasons

Audit & Readiness

amit-gupta

2026-10-05

The ISO 42001 Statement of Applicability: Decisions and Reasons

arrow

The ISO 42001 Statement of Applicability records each Annex A control as applicable or not, with a reason an auditor can test. How to build one that holds up.

ISO 42001 and the EU AI Act: A Compliance Guide for the August 2026 Deadline

Legal & Contracts

amit-gupta

2026-07-14

ISO 42001 and the EU AI Act: A Compliance Guide for the August 2026 Deadline

arrow

ISO 42001 will not make you EU AI Act compliant on its own, but it builds the AI governance the Act demands. See what changes on 2 August 2026.

ISO 42001 vs ISO 27001: How the AI and Security Standards Compare

Comparisons

niranjan-rajendran

2026-07-10

ISO 42001 vs ISO 27001: How the AI and Security Standards Compare

arrow

ISO 42001 vs ISO 27001 compared: AIMS vs ISMS, 38 vs 93 controls, where they overlap, whether you need both, and how to certify them as one program.

How Real Security Becomes Compliance

Built by the CTO who scaled NIUM to $2 billion. 10 years building security and compliance for regulated fintechs. 4.5 years running Konfirmity profitably.

Book a call