ISO 42001 checklist

ISO 42001 checklist for small teams

How small teams can evaluate AI management-system gaps before deeper ISO 42001 certification or assurance work.

For teams ready to implement rather than only compare options, the related template is ISO 42001 Gap Checklist for Small Teams and the public sample is available in the sample library.

Buyer

AI governance owners, SaaS companies, operations teams, and risk managers

Problem

Companies interested in AI management systems often jump to certification conversations before knowing which policy, role, risk, and evidence gaps exist.

What to look for

  • Checklist items for AI policy, roles, inventory, risk assessment, vendor review, monitoring, incident response, and management review.
  • Evidence readiness prompts that show whether controls are documented or merely intended.
  • Prioritization guidance for closing gaps before formal assurance work.

Red flags

  • The company has no AI inventory but wants a certification timeline.
  • Management review receives no AI risk, incident, exception, or training information.
  • Policies exist but no operating records show use, approval, monitoring, or improvement.

Compare related options

ISO 42001 gap checklist

Use when: The team wants to understand management-system gaps before certification or assurance work.

Next step: Review governance ownership, inventory, risk, supplier, training, monitoring, and corrective-action evidence.

EU AI Act readiness checklist

Use when: The team needs a practical inventory and evidence base before legal classification work.

Next step: Organize systems, owners, training, restricted uses, vendor evidence, and escalation triggers.

AI risk register

Use when: The team needs to turn identified AI use cases into risk decisions and controls.

Next step: Score risk, assign owners, record controls, and set review cadence.

Implementation steps

  1. Define the scope of AI use that the first gap review will cover.
  2. Name an AI governance owner and supporting reviewers for risk, IT, HR, procurement, and legal operations.
  3. Create or update the AI system inventory before scoring gaps.
  4. Review whether policies, roles, supplier evidence, training records, incidents, and management review notes exist.
  5. Turn high-priority gaps into corrective actions with owners, evidence expectations, and review dates.

Template preview

Gap area: AI inventory records system, owner, purpose, data category, vendor, output use, and review date.
Gap area: supplier evidence covers training use, retention, deletion, subprocessors, access controls, and contract status.
Gap area: management review receives open risks, overdue actions, incidents, exceptions, training status, and improvement priorities.

What the paid product adds

Gap checklist: Prompts for scope, ownership, policy, AI inventory, risk review, supplier evidence, training, monitoring, management review, and corrective action.
Evidence status: Fields to separate documented evidence from intended controls, missing records, stale evidence, and open actions.
Action tracker: Owner, priority, target date, evidence expected, dependency, status, and review date for closing management-system gaps.

Gap review versus certification work

An initial ISO 42001 gap checklist helps a small team understand whether it has the basic management-system ingredients: scope, ownership, policy, inventory, risk review, supplier evidence, training records, monitoring, management review, and improvement tracking. It is not certification, audit assurance, or legal advice.

ISO 42001 audit checklist versus gap checklist

An ISO 42001 audit checklist is usually used to test whether management-system requirements are implemented and evidenced. A gap checklist is earlier and more practical for small teams: it identifies missing owners, records, policies, reviews, and corrective actions before the organization speaks with an auditor or certification body.

  • Use a gap checklist when the team is still building its AI management evidence base.
  • Use an audit checklist when the management system is already operating and evidence can be sampled.
  • Do not describe the company as ISO 42001 certified or audit-ready unless a qualified process has confirmed it.

Governance ownership and evidence

The first practical question is who owns the AI management work. Without ownership, policies age, inventories become stale, supplier evidence is not refreshed, and management review does not happen. Evidence should be dated and attached to a decision, not stored as undated screenshots or unreviewed trust-center links.

  • AI policy owner and backup owner
  • AI inventory owner
  • Risk and impact reviewer
  • Supplier or vendor evidence owner
  • Training and competence owner
  • Management review sponsor

Records small teams should inspect first

A useful checklist starts with operating records the team can actually maintain. Look for an AI system inventory, risk register, vendor evidence matrix, approved-tools list, training attendance, exception log, incident path, management review agenda, and corrective-action tracker.

When specialist support is needed

Bring in qualified certification, legal, privacy, security, or regulatory support when the organization is pursuing formal certification, deploying high-impact AI systems, handling regulated data, making employment or eligibility decisions, or making customer-facing claims about compliance readiness.

Supplier and vendor evidence

Supplier evidence belongs in the gap review because many AI systems are delivered through external tools. Small teams should capture whether the vendor explains model-training use, prompt and file retention, deletion rights, subprocessors, enterprise controls, audit evidence, security documentation, and contract terms. The checklist should not treat a trust-center link as enough unless someone reviewed and dated the evidence.

Corrective-action tracking

A useful checklist ends with actions, not a score alone. Each gap should become an owner-backed action with priority, target date, evidence expected, dependency, and review status. This creates an improvement record that management can revisit without claiming that the team is certified or fully compliant.

Monitoring and management review

The checklist should ask whether management receives enough information to make decisions about AI use. Useful inputs include new AI systems, open risk items, supplier issues, training completion, incidents, exceptions, overdue corrective actions, and changes in company AI use. This keeps the checklist connected to an operating rhythm instead of a one-time document exercise.

FAQ

Does a checklist make us ISO 42001 ready?

No. It helps identify gaps before certification, consulting, or formal assurance.

Is ISO 42001 only for AI product companies?

No. It can apply to organizations that provide or use AI systems, depending on scope and objectives.

Related next steps

AI risk register template

How to create an AI risk register that shows use cases, owners, data categories, decision impact, controls, and residual risk.

Read the related guide

AI vendor questionnaire

Questions to ask AI vendors about prompts, files, outputs, training use, retention, deletion, subprocessors, and enterprise controls.

Read the related guide

AI literacy training for employees

What baseline AI literacy training should cover for employees using generative AI in everyday work.

Read the related guide

AI Governance Readiness Pack

Risk, readiness, vendor review, and management-system checklists for teams moving beyond first policy rollout.

Review the pack