An ISO 42001 checklist has to cover two different things, and most of the ones online only cover one. Clauses 4 to 10 are the management system requirements and every one of them applies. Annex A holds 38 AI-specific controls, and which of those apply is your decision, recorded in a Statement of Applicability.
Confusing the two is the most common reason a first certification audit goes badly, and it is why a generic ISO 42001 checklist tends to fail you at stage 2. Below is the checklist split the way an auditor reads it.

Part one: the clauses, all of which apply
ISO/IEC 42001 was published in December 2023 and uses the harmonized structure, so if you already run ISO 9001 or ISO 27001 this skeleton will be familiar. Clauses 1 to 3 carry no requirements. The audit starts at clause 4.
| Clause | What has to exist before the audit |
|---|---|
| 4 Context | Internal and external issues, interested parties, the AIMS scope, and your role in the AI value chain. The role determination is specific to this standard and easy to miss. |
| 5 Leadership | An AI policy, assigned roles and authorities, and evidence top management is actually engaged. |
| 6 Planning | AI risk assessment and treatment, objectives, and the AI system impact assessment. The impact assessment is a distinct requirement, not a section of the risk assessment. |
| 7 Support | Resources, competence, awareness, communication and documented information. |
| 8 Operation | Operational planning and control, and the risk assessment and impact assessment actually being run rather than merely defined. |
| 9 Performance evaluation | Monitoring and measurement, internal audit, management review. |
| 10 Improvement | Nonconformity, corrective action and continual improvement. |
Part two of the ISO 42001 checklist: the 38 Annex A controls
Annex A holds 38 controls grouped under nine objectives, numbered A.2 through A.10. They cover AI policies, internal organisation, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third party relationships.
These are not automatically mandatory. Your AI risk assessment decides which apply, and the Statement of Applicability records the decision with a justification for each inclusion and each exclusion. An auditor reads the SoA before anything else, because it tells them what they are auditing against.
The failure mode here is an SoA that marks everything applicable to look thorough. That commits you to evidencing 38 controls you may not need, and it signals that no real risk assessment happened. The full control list is in our guide to the ISO 42001 controls.
The ISO 42001 checklist, in the order to work through it
1. Define the scope and your role. Provider, producer, user or a combination. This changes which Annex A controls are even plausible for you.
2. Run the gap analysis against clauses 4 to 10 first, not against Annex A. The clauses are where nonconformities are raised.
3. Do the AI risk assessment, then the impact assessment for each AI system in scope. The second is not a subsection of the first, and auditors check for both.
4. Write the Statement of Applicability from the risk assessment output rather than from the Annex A list.
5. Implement, then operate long enough to produce records. A management system with no history cannot demonstrate clause 9. Most organisations need at least a few months of evidence.
6. Internal audit and management review, both of which must have happened before a stage 2 audit.
What is in our ISO 42001 toolkit
The pack works as a complete ISO 42001 checklist in document form. It ships an assessment tool workbook covering the clauses and Annex A, an AI risk assessment form, an AI system impact assessment record, the internal audit plan and nonconformity report forms, and the policy set. The full document list is published on the product page before you buy.
- ISO 42001 controls, all 38 explained
- ISO 42001 policy template, and the rest of the policy set
- Implementation roadmap
- Certification, step by step
- Annex SL, the shared structure behind clauses 4 to 10
The standard is published by ISO as ISO/IEC 42001:2023. The editable document set is in the ISO 42001 Toolkit, or start with the free ISO 42001 templates.
Verified against ISO/IEC 42001:2023 as at 6 September 2026.