Bern, Lisbon, New York info@ai-ei.org +351 93 832 8533
Assessment Platform

ISO/IEC 42001 Readiness Assessment

Scope, AI policy, planning, lifecycle controls, suppliers, internal audit and improvement, against clauses 4 to 10 and Annex A.

ISO Management System 30 questions About 15 minutes Free, no account
Step 1 of 2 Organisation context
Organisation context

This shapes the recommendations you get at the end. Nothing here changes your score.

Please enter your organisation name.

Please enter a valid email address.

Please choose an option.

Please choose an option.

Please choose an option.

Please choose an option.

Choose another framework

Self-assessment only. Not legal advice, not an audit opinion, and not certification.

Readiness questions

Answer all 30 questions as honestly as you can. There are no right or wrong answers; an honest picture produces a useful action plan.

01

Context and Scope

01 Have you defined the scope of your AI management system (AIMS), including which AI systems and business units it covers?

Critical requirement, weight 3

02 Have you identified internal and external issues, and interested parties (stakeholders), relevant to your use of AI?

Important requirement, weight 2

03 Have you determined your organisation’s role(s) with respect to each AI system (provider, deployer, user, developer)?

Critical requirement, weight 3

02

Leadership and AI Policy

04 Has top management formally approved an AI policy appropriate to the organisation’s purpose and AI activities?

Critical requirement, weight 3

05 Are AI governance roles, responsibilities, and authorities assigned and communicated?

Critical requirement, weight 3

06 Does top management review AI objectives and demonstrate visible commitment to the AIMS?

Important requirement, weight 2

03

Planning

07 Is there a documented process to identify AI-related risks and opportunities for the AIMS?

Critical requirement, weight 3

08 Are measurable AI objectives established, with plans, owners, and timelines to achieve them?

Important requirement, weight 2

09 Is there a defined AI risk assessment methodology with criteria for evaluating and prioritising AI risks?

Critical requirement, weight 3

10 Are AI system impact assessments performed to evaluate consequences for individuals, groups, and society?

Critical requirement, weight 3

04

Support and Competence

11 Are resources (people, budget, tools) allocated for establishing and maintaining the AIMS?

Important requirement, weight 2

12 Are competence requirements defined for personnel working on AI, with training records maintained?

Important requirement, weight 2

13 Is there an awareness programme so staff understand the AI policy and their role in the AIMS?

Important requirement, weight 2

14 Is documented information for the AIMS controlled (creation, update, versioning, access)?

Important requirement, weight 2

05

AI System Lifecycle

15 Are processes defined for the responsible design and development of AI systems (requirements, design criteria, verification)?

Critical requirement, weight 3

16 Are data used in AI systems managed for provenance, quality, and fitness for purpose across the lifecycle?

Critical requirement, weight 3

17 Are AI systems verified and validated against defined acceptance criteria before deployment?

Critical requirement, weight 3

18 Are deployment, operation, and monitoring procedures documented for AI systems in production?

Important requirement, weight 2

19 Are technical documentation and event logs maintained for AI systems throughout their lifecycle?

Important requirement, weight 2

20 Is there a defined process for decommissioning or retiring AI systems safely?

Important requirement, weight 2

06

Third Parties and Suppliers

21 Are AI-related responsibilities allocated between your organisation and suppliers/partners (e.g., model or API providers)?

Critical requirement, weight 3

22 Do you evaluate third-party AI components, models, and datasets against your AIMS requirements before use?

Important requirement, weight 2

23 Are customer and end-user obligations (transparency, support, reporting channels) defined for the AI systems you provide?

Important requirement, weight 2

07

Performance Evaluation

24 Are AIMS performance metrics defined, monitored, measured, and analysed at planned intervals?

Important requirement, weight 2

25 Are internal audits of the AIMS conducted by competent, impartial auditors on a planned schedule?

Critical requirement, weight 3

26 Does management review the AIMS at planned intervals, with documented outputs and decisions?

Important requirement, weight 2

08

Improvement

27 Is there a nonconformity and corrective action process for AIMS and AI system failures?

Critical requirement, weight 3

28 Are incidents and near-misses involving AI systems recorded, investigated, and lessons applied?

Important requirement, weight 2

29 Is there evidence of continual improvement of the AIMS (updated controls, refined objectives)?

Important requirement, weight 2

30 Have you performed a gap analysis or pre-audit against ISO/IEC 42001 requirements and Annex A controls?

Important requirement, weight 2

Results are generated instantly. Self-assessment only, not an audit.