All readiness checks

Readiness for ISO/IEC 42001 — Artificial Intelligence Management

Assess how close your business is to the requirements of ISO/IEC 42001:2023, including the Annex A controls.

27 questions · ~7 min

Anonymous: we don't ask for a name, email or company details. Only the answers are kept, with nothing that identifies you, for statistics.

How to answer

Choose “Yes” only when the requirement is applied in practice and there is documentation or records. “Partly” means it is done informally or not everywhere.

4 Context of the organization

4.1 Have you recorded the internal and external issues (e.g. market, competition, technology, legislation) that affect your AI management system?

4.2 Have you identified the interested parties (customers, employees, authorities, suppliers, etc.) and their requirements?

4.1 Have you determined your role in relation to AI (provider, user, developer) and recorded the AI systems you use or develop?

4.2 Have you examined your obligations under Regulation (EU) 2024/1689 on Artificial Intelligence (the AI Act) and other relevant rules?

4.3–4.4 Has the scope of your AI management system been defined in writing (activities, sites, any exclusions), and have the main processes been mapped?

5 Leadership

5.1 Is top management actively involved in the AI management system, providing resources and building it into business decisions?

5.2 Is there an approved AI policy that suits the business, has been communicated to staff and is available to those who need it?

5.3 Have roles, responsibilities and authorities for the system been defined and communicated?

6 Planning

6.1 Have you assessed the risks and opportunities related to your AI management system and planned actions to address them?

6.1.2–6.1.3 Is there a methodology for assessing and treating AI risks, and a Statement of Applicability for the Annex A controls?

6.1.4 Do you assess the impact of your AI systems on individuals, groups and society?

6.2 Are there measurable AI objectives with owners, resources, a timeline and a way of monitoring them?

6.3 Are changes to the system (organisational, process, infrastructure) planned and controlled before they are made?

7 Support

7.1–7.2 Have you defined the competence required for each relevant role, and do you keep records of training, experience or qualifications?

7.3–7.4 Are staff aware of the AI policy and of their contribution to the system, and is there a defined way of communicating internally and externally?

7.5 Are the system's documents and records controlled (approval, versions, distribution, storage, retention)?

8 Operation

A.4 Have the resources for the AI systems been recorded (data, tools, computing infrastructure, people)?

A.6 Is the AI system life cycle (requirements, design, verification, validation, deployment, operational monitoring) documented?

A.7 Is the data you use controlled (provenance, quality, preparation, possible bias)?

A.8 Is suitable information provided to users and interested parties (transparency, instructions, how to report problems)?

A.9 Are there rules for the responsible use of AI systems and for human oversight?

A.10 Are AI-related suppliers and third parties controlled (models, data, cloud services)?

9 Performance evaluation

9.1 Do you monitor, measure and analyse indicators of AI system performance and evaluate the results?

9.2 Is there an internal audit programme, and has at least one full internal audit of the system been completed by a competent person?

9.3 Has a management review of the system been held and recorded, with decisions and actions?

10 Improvement

10 Are nonconformities recorded, their causes analysed, and corrective actions taken and checked for effectiveness?

10 Are there documented examples of continual improvement of the system?

Answered 0 of 27