ISO 42001 Audit Checklist: Pre-Stage-1 Self-Assessment
A structured checklist to verify your AIMS is ready for a Stage 1 certification audit. Use it honestly before you book, any ✗ items translate directly to Stage 1 findings if left unresolved.
How to use this checklist
Score each row honestly: ✓ (in place and working), ⚡ (in place but immature), ✗ (missing or failing). Any ✗ should be closed before booking. Any ⚡ should be specifically discussed with your certification body during pre-audit briefing, they may still produce findings, but at least you'll know them before the auditor does.
This is the public summary. The full 100+ item version, with sub-items for every clause requirement and every Annex A control, is included in the Audit-Ready toolkit ($1,497).
Clause 4, Context
- Documented AIMS scope is signed and current (AIMS-02)
- Interested parties register identifies customers, regulators, affected individuals, suppliers
- Context analysis references EU AI Act, Colorado AI Act, Microsoft SSPA, NIST AI RMF where applicable
- AIMS scope excludes are explicitly listed and justified
Clause 5, Leadership
- AI Policy is signed by top management, dated within the last 12 months (AIMS-01)
- AIMS Owner, AI Risk Lead, AI System Owners are named and accountable
- Management review cadence is set and at least one cycle has occurred
- Top management can describe the AI Policy in their own words (spot check)
Clause 6, Planning
- Risk assessment methodology is documented and internally consistent (AIMS-04)
- AI Risk Register contains identified risks with ratings and treatment decisions (AIMS-05)
- Statement of Applicability lists all 38 Annex A controls with status and justification (AIMS-07)
- Risk Treatment Plan maps treatments to specific risks (AIMS-06)
- Every treatment action is described in full, with verification method, independent verifier and evidence references (AIMS-06a)
- AI System Inventory lists every in-scope AI system with owner and lifecycle stage (AIMS-18)
- Impact Assessment Procedure is documented (AIMS-08)
- At least one Impact Assessment has been completed for an in-scope AI system (AIMS-09)
- AI Objectives are documented with targets and review cadence (AIMS-03)
Clause 7, Support
- Document control procedure is in place and followed (AIMS-10)
- Competence Matrix identifies required skills and current capability (AIMS-11)
- Awareness programme includes AI Policy key points
- Communication Plan addresses internal and external (AIMS-12)
- Documented information has version control, approval, retention/disposition rules
Clause 8, Operation
- AI System Lifecycle Procedure covers development, deployment, monitoring, retirement (AIMS-19)
- Data Management Procedure addresses quality, provenance, bias (AIMS-20)
- Supplier Management Procedure includes AI-specific due diligence (AIMS-21)
- Incident Response Procedure implements EU AI Act Article 73 tiered 2/10/15-day reporting (AIMS-22)
- Operational impact assessments are performed for each in-scope AI system
- Evidence of system testing before deployment exists for sampled systems
Clause 9, Performance evaluation
- Internal Audit Programme is documented (AIMS-13)
- At least one internal audit has been completed with report (AIMS-14)
- At least one Management Review has occurred with documented inputs and outputs (AIMS-15)
- Monitoring metrics are defined and values are being collected
Clause 10, Improvement
- CAPA Procedure is documented (AIMS-16)
- Nonconformity Register is in use (AIMS-17)
- At least one CAPA cycle has been closed with effectiveness review
Annex A, Sample controls (representative)
- A.2.2 AI Policy, signed, current, communicated
- A.3.2 Roles and responsibilities, assigned and competent
- A.4.2 Resource documentation, data, tools, infrastructure, people documented
- A.5.2 Impact Assessment process, operating for each in-scope system
- A.6.2.4 Verification and validation, evidence of pre-deployment testing
- A.7.4 Data quality, quality criteria defined, monitored
- A.8.4 Incident communication, Article 73 timelines implemented
- A.9.4 Intended use, documented, with foreseeable misuse
- A.10.3 Supplier governance, AI supplier due diligence in procurement
The full checklist covers all 38 Annex A controls with 2–4 verification sub-items each. Available in the Audit-Ready toolkit.
After the checklist
If every row is ✓, brief your certification body using the Auditor Briefing Pack and book Stage 1. If any row is ✗, remediate first, a Stage 1 finding will either delay your Stage 2 audit (costing weeks) or require a re-audit (costing money). The whole point of running the checklist honestly is to pay the fixing cost on your schedule, not the auditor's.