ISO 42001 Audit Checklist: Pre-Stage-1 Self-Assessment

A structured checklist to verify your AIMS is ready for a Stage 1 certification audit. Use it honestly before you book, any ✗ items translate directly to Stage 1 findings if left unresolved.

How to use this checklist

Score each row honestly: ✓ (in place and working), ⚡ (in place but immature), ✗ (missing or failing). Any ✗ should be closed before booking. Any ⚡ should be specifically discussed with your certification body during pre-audit briefing, they may still produce findings, but at least you'll know them before the auditor does.

This is the public summary. The full 100+ item version, with sub-items for every clause requirement and every Annex A control, is included in the Audit-Ready toolkit ($1,497).

Clause 4, Context

  • Documented AIMS scope is signed and current (AIMS-02)
  • Interested parties register identifies customers, regulators, affected individuals, suppliers
  • Context analysis references EU AI Act, Colorado AI Act, Microsoft SSPA, NIST AI RMF where applicable
  • AIMS scope excludes are explicitly listed and justified

Clause 5, Leadership

  • AI Policy is signed by top management, dated within the last 12 months (AIMS-01)
  • AIMS Owner, AI Risk Lead, AI System Owners are named and accountable
  • Management review cadence is set and at least one cycle has occurred
  • Top management can describe the AI Policy in their own words (spot check)

Clause 6, Planning

  • Risk assessment methodology is documented and internally consistent (AIMS-04)
  • AI Risk Register contains identified risks with ratings and treatment decisions (AIMS-05)
  • Statement of Applicability lists all 38 Annex A controls with status and justification (AIMS-07)
  • Risk Treatment Plan maps treatments to specific risks (AIMS-06)
  • Every treatment action is described in full, with verification method, independent verifier and evidence references (AIMS-06a)
  • AI System Inventory lists every in-scope AI system with owner and lifecycle stage (AIMS-18)
  • Impact Assessment Procedure is documented (AIMS-08)
  • At least one Impact Assessment has been completed for an in-scope AI system (AIMS-09)
  • AI Objectives are documented with targets and review cadence (AIMS-03)

Clause 7, Support

  • Document control procedure is in place and followed (AIMS-10)
  • Competence Matrix identifies required skills and current capability (AIMS-11)
  • Awareness programme includes AI Policy key points
  • Communication Plan addresses internal and external (AIMS-12)
  • Documented information has version control, approval, retention/disposition rules

Clause 8, Operation

  • AI System Lifecycle Procedure covers development, deployment, monitoring, retirement (AIMS-19)
  • Data Management Procedure addresses quality, provenance, bias (AIMS-20)
  • Supplier Management Procedure includes AI-specific due diligence (AIMS-21)
  • Incident Response Procedure implements EU AI Act Article 73 tiered 2/10/15-day reporting (AIMS-22)
  • Operational impact assessments are performed for each in-scope AI system
  • Evidence of system testing before deployment exists for sampled systems

Clause 9, Performance evaluation

  • Internal Audit Programme is documented (AIMS-13)
  • At least one internal audit has been completed with report (AIMS-14)
  • At least one Management Review has occurred with documented inputs and outputs (AIMS-15)
  • Monitoring metrics are defined and values are being collected

Clause 10, Improvement

  • CAPA Procedure is documented (AIMS-16)
  • Nonconformity Register is in use (AIMS-17)
  • At least one CAPA cycle has been closed with effectiveness review

Annex A, Sample controls (representative)

  • A.2.2 AI Policy, signed, current, communicated
  • A.3.2 Roles and responsibilities, assigned and competent
  • A.4.2 Resource documentation, data, tools, infrastructure, people documented
  • A.5.2 Impact Assessment process, operating for each in-scope system
  • A.6.2.4 Verification and validation, evidence of pre-deployment testing
  • A.7.4 Data quality, quality criteria defined, monitored
  • A.8.4 Incident communication, Article 73 timelines implemented
  • A.9.4 Intended use, documented, with foreseeable misuse
  • A.10.3 Supplier governance, AI supplier due diligence in procurement

The full checklist covers all 38 Annex A controls with 2–4 verification sub-items each. Available in the Audit-Ready toolkit.

After the checklist

If every row is ✓, brief your certification body using the Auditor Briefing Pack and book Stage 1. If any row is ✗, remediate first, a Stage 1 finding will either delay your Stage 2 audit (costing weeks) or require a re-audit (costing money). The whole point of running the checklist honestly is to pay the fixing cost on your schedule, not the auditor's.

Start your ISO 42001 implementation

The 22-document Starter pack gets you from purchase to signed AI Policy in 7 days. Professional adds Annex A deep-dives, a 64-formula Gap Analysis workbook, and industry variants. Audit-Ready prepares you for Stage 1.