An ISO 42001 checklist turns the standard into a sequence you can work through: define your AI management system scope, run a gap analysis, write the mandatory documents, implement the applicable Annex A controls, operate the system long enough to generate records, then pass a two-stage certification audit. Five phases, one accredited certificate at the end. ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system (AIMS); its certifiable requirements live in clauses 4 to 10, and Annex A supplies 38 reference controls across 9 objectives you select through a Statement of Applicability. Our ISO 42001 guide explains what the standard is and why buyers ask for it; this page is the do-list, with the ordered steps and the exact inventory of documents and records an auditor expects to see. Every item below is a box you can tick as you go.
TL;DR
- The checklist runs in five phases: scope and gap analysis, build the AIMS, implement controls, internal audit and management review, then the certification audit.
- The AIMS scope statement and the Statement of Applicability are the two documents auditors read first.
- ISO 42001 requires a defined set of documents (policy, scope, risk and impact assessments, data procedures, SoA, audit programme) and a set of retained records that prove the system operates.
- Certification is a Stage 1 and Stage 2 audit by an accredited body; the certificate is valid for three years.
- Budget four to nine months, shorter if you already hold ISO 27001, because the management-system machinery already exists.
- Every step on this page is a tickable checkbox: work through it in the browser, then export your completed checklist.
The ISO 42001 Checklist: Five Phases to Certification
These five phases are the ISO 42001 implementation steps in the order most teams run them. Nothing here reinvents the ISO playbook; it is the same Plan-Do-Check-Act rhythm as ISO 27001, pointed at AI. Most organizations move through it in four to nine months. If you already hold ISO 27001, expect the shorter end, because the risk methodology, the audit cadence, and the leadership structure are already in place and you are mostly extending them to cover AI.
The phases:
- Scope and gap analysis - decide what the AIMS covers and find what is missing.
- Build the AIMS - write the mandatory documents and stand up the processes.
- Implement the controls - apply the Annex A controls your risk work justifies.
- Internal audit and management review - test the system yourself before an auditor does.
- Certification audit - pass the Stage 1 and Stage 2 assessment.
Scope and gap analysis
AIMS scope statement, ranked remediation plan
Build the AIMS
Eight mandatory documents
Implement the controls
Statement of Applicability, controls in live workflows
Internal audit and management review
Audit results, review minutes, corrective actions
Certification audit
Stage 1 and Stage 2 passed, three-year certificate
Work them in order. Each phase produces the inputs the next one needs, and skipping ahead is the fastest way to fail a Stage 2 audit.
Phase 1: Scope the AIMS and Run a Gap Analysis
0 of 7 items complete in this phase
The first phase decides how big the job is. A tight, defensible scope and an honest gap analysis are worth more than an ambitious plan you cannot evidence later.
Define the AIMS Scope
The AIMS scope statement is a mandatory document (clause 4.3) and the first thing an auditor reads. It records which AI systems sit inside the management system, the internal and external issues that shape your AI, and the interested parties you answer to. You do not have to put every model in scope on day one; you have to draw a boundary you can actually run and prove.
Run an ISO 42001 Gap Analysis
A gap analysis compares your current AI governance against clauses 4 to 10 and the 38 Annex A controls, then turns the differences into a ranked remediation plan. The output is your project backlog for phases 2 and 3. A usable ISO 42001 gap analysis assesses three things in the same pass: the policies and documented information you hold, the technical controls actually running in your AI systems, and the governance routines that keep both current, which is to say who reviews what, how often, and on what record. Score each line as met, partial or absent rather than pass or fail; partial is where most of the real work sits. The mechanics are the same as an information-security gap assessment, so our ISO 27001 gap assessment guide is a useful model for how to scope and score one.
Phase 2: Build the AIMS and Its Mandatory Documents
0 of 16 items complete in this phase
With the gaps mapped, you build the system. Most of the work in this phase is documentation the standard explicitly requires. An AIMS is the same species of management system as an ISMS, so if you have written information-security documentation before, the format will feel familiar; only the subject matter (AI risk, impact, and lifecycle) is new. For the full clause-by-clause detail behind each item below, see our ISO 42001 requirements breakdown.
ISO 42001 Mandatory Documents and Records
The standard distinguishes documents you maintain (living artefacts an auditor can inspect) from records you retain (evidence that the system actually ran). You need both. Here are the ISO 42001 mandatory documents to author:
| Where the standard asks for it | What the auditor checks | |
|---|---|---|
| Clause 5.2, Annex A.2 | That top management owns it, that it has been reviewed, and that it says something specific about your AI rather than restating the standard | |
| Clause 4.3 | That the boundary is explicit, that it names the systems in and out, and that you can run everything inside it | |
| Not named as its own clause; it is how you evidence the scope at 4.3 | That every system in the scope statement appears, with an owner and a lifecycle stage | |
| Clause 6.1.2 | That the method is written down before the results, and that the same method was applied to every system | |
| Clauses 6.1.4 and 8.4 | That impacts on individuals and society are assessed, not just risks to the business | |
| Annex A.7 | That provenance, quality and preparation are covered for the data each in-scope system uses | |
| Clause 6.1.3 | That every one of the 38 controls carries an include or exclude decision with a reason tied back to the risk work | |
| Clause 9.2 | That the programme exists as a plan, with scope, frequency and independence, separately from the audit results |
And the records to retain as proof the AIMS operates:
| Where the standard asks for it | What it proves | |
|---|---|---|
| Clause 6.1.2 | The method was actually run, not just written | |
| Clause 6.1.3 | Each accepted risk has a decision behind it | |
| Clauses 6.1.4 and 8.4 | Impact assessments happened at the point the lifecycle required them | |
| Clause 7.2 | The people running the AIMS are qualified to run it | |
| Clause 9.1 | The system is being watched between audits | |
| Clause 9.2 | You tested yourself before the certification body did | |
| Clause 9.3 | Leadership reviewed the AIMS and made decisions | |
| Clause 10.2 | Problems were found, logged and closed |
The Statement of Applicability deserves special attention: it is the bridge between your risk work and Annex A, and auditors treat it as the map of your whole control set.
Free download: XLSX-ready checklist and PDF
The ISO 42001 Implementation Checklist
All five phases, the eight mandatory documents and eight retained records with their clause references, and the 38 Annex A controls, in a printable checklist you can assign owners in and hand to an auditor.
Phase 3: Implement the Annex A Controls
0 of 4 items complete in this phase
Annex A lists 38 controls grouped into 9 objectives (A.2 to A.10). You do not implement all 38 by default. You select the ones your risk and impact assessments justify, record every include-or-exclude decision with its rationale in the Statement of Applicability, then put the selected controls into real workflows rather than into a document nobody follows. For the full catalogue and what each control asks for, see our guide to the ISO 42001 Annex A controls.
Phase 4: Internal Audit and Management Review
0 of 4 items complete in this phase
An auditor cannot certify a system that has never run. Before Stage 1, the AIMS has to operate long enough to produce genuine records, then you test it against itself. Clause 9 makes both the internal audit and the management review mandatory, and this phase is where readiness is actually earned rather than assumed.
Phase 5: The Two-Stage Certification Audit
0 of 4 items complete in this phase
ISO 42001 certification follows the same accredited, two-stage path as any ISO management system. Stage 1 is a documentation and readiness review; Stage 2 tests whether the AIMS operates as designed, with the auditor sampling evidence across your controls. A clean result earns a certificate valid for three years, with annual surveillance audits in between. The details of choosing a body and what each stage samples are in our ISO 42001 certification walkthrough.
Export my completed checklist
Download your own progress (0 of 42 ticked) as a CSV you can open in Excel or Sheets and hand to your team. Nothing is sent anywhere -- the file is built in your browser from what you've ticked above.
Get the ISO 42001 Checklist for Your Role
The five phases above apply to every organization pursuing ISO 42001, but what the AIMS actually has to govern differs by what you do with AI. Pick the checklist that matches your role:
For AI builders
ISO 42001 Implementation Checklist for AI Builders
For companies designing, training, or fine-tuning their own models: data provenance, reproducibility, model lifecycle documentation, and deployment monitoring, mapped to clause or Annex A control.
For AI deployers
ISO 42001 Implementation Checklist for AI Deployers
For companies embedding frontier or third-party models: provider due diligence, data boundaries, runtime guardrails, and the split of responsibility with your model provider.
For auditors and advisors
ISO 42001 Audit Checklist for Certification Providers
For assessors and advisory teams running an ISO 42001 engagement: a clause-mapped path from scoping through Stage 1 and Stage 2 to a defensible certification recommendation.
Want us to map your AI systems to this checklist?
Share your work email and we'll walk your AI inventory against the five phases and flag where you're already covered by existing ISO 27001 or SOC 2 work.
Are You Ready? An ISO 42001 Readiness Check
0 of 7 items complete in this phase
Before you book Stage 1, run this ISO 42001 readiness self-check. If you can answer yes to every line, you are audit-ready; a no is a gap to close first.
The most common reason teams fail this check is the last mile of Phase 4: the documents exist, but the system has not run long enough to leave a trail. Give yourself a real operating window before you invite an auditor in.
Frequently Asked Questions
There is no single magic number, and published counts differ widely, but the practical core is the eight documents in Phase 2 (AI policy, AIMS scope statement, AI system inventory, risk assessment, impact assessment, data procedures, Statement of Applicability, and the internal audit programme), plus the eight retained records that prove each of those processes actually ran. Documents show the system was designed; records show it operated. Treat them as one set, because auditors check for both, and a complete document set with no records behind it is the most common way to fail a Stage 2 audit.
No. The standard does not name a gap analysis as a required document. In practice it is the sensible first move, because it tells you exactly which clauses and controls you still have to build before you spend money on an audit.
No. Annex A is a reference set, not a mandatory list. You select the controls your risk and impact assessments justify and document every inclusion and exclusion in the Statement of Applicability. Ticking all 38 without reasoning is a red flag to an auditor, not a shortcut.
Largely, yes. Both standards use the same Harmonized Structure, so your risk methodology, internal-audit programme, management-review cadence, and competence records carry over. You extend them to cover AI risk, impact, and lifecycle rather than starting from a blank page, which is why holding ISO 27001 compresses the timeline. Our ISO 27001 documentation toolkit shows how that document set is structured.
Four to nine months for most organizations. Teams already certified to ISO 27001 tend to land at the shorter end; teams building a management system for the first time should plan for the longer end, since the foundation has to be built before the AI-specific work begins.
At Stage 2 the auditor samples rather than reads everything, so the evidence has to survive being picked at random: completed impact assessments with dates, risk treatment decisions traceable to the Statement of Applicability, monitoring output from the period under review, competence records for the named AIMS owners, internal audit findings with their corrective actions closed out, and management review minutes showing decisions rather than attendance. Evidence generated in the week before the audit reads as exactly that, which is why Phase 4 asks you to run the system for a real operating window first.
Yes. The checklist on this page is free to work through in the browser, and the same content is available as a free PDF: the five phases as a tracker, the mandatory documents and records with their clause references, and all 38 Annex A controls set up as a Statement of Applicability. Use the download block above, or export your own ticked progress as a CSV directly from this page.
Turn this checklist into a certificate
Book a demo and we'll map your AI systems to the checklist together, self-serve or with our CISO-led team running the AIMS build for you.
Book a demo
Conclusion
The ISO 42001 checklist is not complicated, but it is unforgiving about order and evidence: scope it, find the gaps, write the documents, apply the controls your risk work justifies, run the system until it leaves a trail, and only then invite the auditor. The teams that struggle are the ones that document without operating.
Konfirmity is a security-driven compliance platform for AI governance and the frameworks around it: ISO 27001, SOC 2 and HIPAA out of the box, and ISO 42001 through the custom-framework engine, run self-serve or with the fully-managed service where our team runs the program for you. The team behind Konfirmity has supported more than 6,000 security audits, and with managed delivery we build the AIMS inside your stack, write the mandatory documents, and collect the records with you, so your team spends hours rather than months.







