Free Readiness Assessment
ISO 42001 AI Governance Readiness Checklist
Score your AI Management System (AIMS) against ISO 42001 in 15 minutes. Tell us about your environment, answer 18 focused questions, and download a branded PDF roadmap with your top AI governance gaps and recommended next steps.
18 focused questions across 6 AIMS domains, plus a quick environment context block.
Calibrated to the AIMS requirements — the same criteria AI governance auditors assess.
Score breakdown, top AI governance gaps, and a prioritised action plan. Emailed copy + instant download.
Tell us about your environment
A few details to tailor your AI governance roadmap. Required fields are marked *.
AIMS Governance
Scope, roles, policy set and AI objectives.
Scope defines what is covered by governance and what is explicitly out of scope.
View evidence examples ->
- A documented scope statement listing AI use cases (e.g. clinical decision support, chatbots, analytics models).
- Systems and models in scope — vendor AI, internally developed models, GenAI tools.
- Geographic and regulatory boundaries (e.g. Australia-only deployment; GDPR-relevant use cases).
Clear accountability for AI decisions, oversight and escalation must be documented.
View evidence examples ->
- Named AIMS owner, AI risk owner, and individual model or use-case owners.
- A defined governance or ethics review committee with terms of reference.
- RACI covering design, approval, monitoring, incident handling and retirement of AI systems.
Policies guide safe, ethical and compliant AI use across the organisation.
View evidence examples ->
- AI Acceptable Use Policy covering staff and contractor use of AI tools.
- AI Risk Management or AI Governance Policy aligned to ISO 42001.
- Transparency and disclosure policy for customers or end users.
Leadership should see whether AI is delivering value safely and within defined risk tolerance.
View evidence examples ->
- Defined KPIs such as model accuracy, false positives, bias indicators or incident rates.
- Targets and thresholds approved by leadership.
- Periodic review of AI performance and risk metrics reported to the board or executive.
Risk & Impact Assessment
AI inventory, impact assessment methodology and data ethics.
A single source of truth for all AI systems enables consistent risk management.
View evidence examples ->
- An AI inventory or register with each use case, business owner and technical owner.
- Associated datasets, model types and deployment environments documented.
- Initial risk classification (low / medium / high impact) assigned for each AI system.
A consistent method for AI Impact and Risk Assessment (AIRA) ensures material risks are identified and treated.
View evidence examples ->
- A documented AIRA or AI Impact Assessment template applied to each AI use case.
- Assessment criteria covering safety, bias, legal, ethical and reputational risks.
- Completed AIRA records for each material AI use case, reviewed and approved.
Data quality and ethics are foundational to responsible AI.
View evidence examples ->
- Bias and representativeness assessments for training datasets.
- Documented data provenance and sourcing decisions.
- Confirmation of consent, licensing or lawful basis for training or input data.
Design, Controls & Oversight
Preventative controls, human oversight and evaluation.
Design-level controls reduce harm and misuse before problems occur.
View evidence examples ->
- Prompt filtering, output moderation or content safety controls for generative AI.
- PII detection, masking or minimisation in prompts and model outputs.
- Security controls protecting models, APIs and inference endpoints.
Humans must remain accountable for impactful AI outcomes.
View evidence examples ->
- Defined thresholds requiring human review before an AI-driven action is taken.
- Clear escalation paths for unsafe, unexpected or disputed outputs.
- A documented ability to disable, pause or override AI systems when required.
Testing AI before and after release ensures it behaves as expected.
View evidence examples ->
- Pre-deployment testing for accuracy, bias and robustness documented.
- Adversarial or red-teaming exercises for misuse and edge-case scenarios.
- Test results and go/no-go decisions recorded and retained.
Operations & Monitoring
Runtime monitoring, incident handling and records.
Monitoring AI behaviour in production detects degradation and misuse early.
View evidence examples ->
- Monitoring for model drift, performance drops or abnormal output patterns.
- Logging of prompts, outputs and key decisions (within applicable privacy limits).
- Alerts for misuse, abuse patterns or outputs that breach policy thresholds.
AI issues are treated as formal incidents with documented learning outcomes.
View evidence examples ->
- AI incident categories included in the organisation's incident response plan.
- Documented handling of bias events, harmful outputs or hallucination incidents.
- Post-incident reviews with corrective actions tracked to closure.
Traceability for how AI systems were designed and operated is essential for audits.
View evidence examples ->
- Version history of models, prompts, configurations and datasets.
- Decision logs for approvals, changes and risk acceptances.
- Records retained with defined periods aligned to regulatory and audit requirements.
Suppliers & Transparency
Third-party AI due diligence and user transparency.
External AI providers introduce risk that must be managed through due diligence and contracts.
View evidence examples ->
- Vendor due diligence covering security, privacy, bias and explainability.
- Review of model cards, SOC/ISO reports or published assurance statements.
- Contractual controls: usage limits, data handling, breach notification and liability.
Transparency builds trust and meets regulatory expectations in many jurisdictions.
View evidence examples ->
- User-facing disclosures explaining AI purpose, data used and limitations.
- Clear contact points for human review, complaints or escalation.
- Documented opt-out or alternative pathways where AI decisions are material.
Evidence & Improvement
Evidence management, audits and management reviews.
Audit-ready evidence must be organised, retained and accessible.
View evidence examples ->
- An AIMS evidence library in SharePoint or equivalent with version control.
- Monitoring logs and incident records retained in a governed system.
- Retention policies applied to AI governance records.
Regular assurance confirms that AI governance controls are operating as intended.
View evidence examples ->
- Internal AI governance or AIMS audits aligned to ISO 42001 requirements.
- Findings logged with corrective actions, owners and due dates.
- Evidence of verification that corrective actions were completed.
Management reviews ensure ongoing accountability and strategic direction for AI governance.
View evidence examples ->
- Management review minutes covering AI risks, incidents and performance KPIs.
- Decisions on risk acceptance, resourcing and policy updates.
- Tracked actions arising from AIMS management reviews.
Available once all questions are answered
Your report is ready
Your PDF has downloaded automatically. A copy of your responses has been sent to our team — we'll follow up if you'd like to discuss the results.