Skip to content
← Blog
ArticleSillage

ISO/IEC 42001 readiness checklist: what an AI management system requires

A plain-language readiness guide to ISO/IEC 42001: what an AI management system is, the evidence an auditor expects, and how to have it ready before the audit.

6 min readStallwart

Governance is a layer, built in, not bolted on before an audit.A four-layer stack (intelligence, orchestration, governance, production) with the governance layer highlighted, beside the standards it answers to.IntelligenceOrchestrationGovernanceaudit-readyProductionANSWERS TOSOC 2ISO 42001EU AI Act
Governance is a layer, built in, not bolted on before an audit.

The one-line answer

ISO/IEC 42001 certifies that you run a working AI management system: a defined set of policies, roles, risk assessments, controls, and records that govern how your organization builds, buys, and operates AI, kept current and evidenced over time. Readiness means you can show that system running, not that you wrote a policy the week before the audit.

A quick vocabulary note, because the terms get mixed up. ISO/IEC 42001 is the management-system standard. An AIMS (AI management system) is the thing you actually operate. A certification body, an accredited third party, is what issues the certificate after a two-stage audit. Stallwart is none of those: we do not certify anyone and hold no certificate to grant. What we do is build the inventory, documentation, controls, and evidence trail the auditor asks to see. This guide explains what that auditor is looking for.

What ISO/IEC 42001 actually is

42001 is built on the same high-level structure as ISO 27001 and 9001, so if your team has been through an ISO audit before, the shape is familiar: context, leadership, planning, support, operation, performance evaluation, improvement, plus a set of controls in an annex you justify including or excluding. The subject matter is what is new. Instead of information security or quality, the object of management is the AI systems themselves and the risks they carry to people, not only to the business.

The clauses that carry the most weight in practice are the AI risk assessment and treatment, the AI system impact assessment (the effect on individuals and groups, not just on the organization), and the operational controls over the AI lifecycle. The reference controls list what you might adopt, and you are required to have a defensible reason for each one you leave out, recorded in a Statement of Applicability.

The standard is deliberately technology-neutral and process-heavy. It does not tell you which model to use or set an accuracy threshold. It asks whether you know what AI you run, why you made the decisions you made, who is accountable, how you catch problems, and whether you can prove all of that with records. Treat the following as practical preparation, not legal or certification advice; your certification body's interpretation is what governs your specific audit.

The readiness checklist: what to have ready

An auditor works from evidence, so readiness is best understood as a list of artifacts that exist, are current, and are owned. Each item below maps to the standard's clauses and controls, and each is something that should be a byproduct of the system running rather than a document assembled for the occasion.

  1. AI policy and objectives: a signed AI policy, measurable objectives, and evidence that leadership reviews them, not a template nobody has read.
  2. Live model and system inventory: a current register of every AI system and material model in use, including third-party and embedded ones, with owner, purpose, data sources, and lifecycle stage. A stale spreadsheet fails here; a register the system keeps current passes.
  3. AI risk assessments and treatment plans: documented risk assessments per system, the treatment decisions, and the residual risk someone accepted by name.
  4. AI system impact assessments: the effect of each higher-stakes system on individuals and groups, with the reasoning recorded.
  5. Statement of Applicability: every reference control marked in or out, each with a justification.
  6. Roles and competence records: who is accountable for what across the AI lifecycle, and evidence those people are competent to hold the role.
  7. Operational controls with a written basis: for consequential systems, the recorded reasoning behind design and deployment decisions, plus human oversight, runtime controls, and a rollback path you have actually tested.
  8. A continuous evidence trail: logs, approvals, monitoring output, and change records that show the controls operating over time, not a snapshot from audit week.
  9. Internal audit and management review records: proof you check your own system and that leadership acts on what the checks find.
  10. Supplier and third-party AI governance: due-diligence and contractual evidence for the AI you buy or embed.

Where teams are actually short

The policy layer is rarely the problem. Most teams can write an AI policy in an afternoon. The gap shows up one layer down, in the evidence that the policy is lived.

The most common shortfall is the inventory. Organizations underestimate how much AI they run once you count vendor features, embedded models, and things a team stood up without telling anyone. If the register is not continuously maintained, it is wrong by the time the auditor opens it, and a wrong inventory undermines every risk assessment built on top of it.

The second common gap is the written basis for decisions. Teams make reasonable choices about a model, a threshold, or a human-in-the-loop step, then cannot reconstruct why months later. The third is the evidence trail. Controls may genuinely operate, but if nothing records them operating, the auditor cannot distinguish a working control from an aspiration. Readiness is largely the work of closing these three gaps before someone external looks.

Governance as a byproduct, not a scramble

The expensive way to approach 42001 is to treat the audit as a deadline and assemble a binder against it. The binder is stale the day after it is signed, and you repeat the scramble at every surveillance audit.

The durable approach is to make the evidence a byproduct of the system running. When the model inventory updates itself as systems change, when consequential decisions capture their own written basis, when runtime controls and human oversight leave records as they operate, and when rollback is a tested path rather than a promise, readiness stops being an event. The audit becomes a read of a state you are already in.

That is the posture Stallwart builds toward: the inventory, the documentation, the controls, and the continuous evidence trail an AIMS needs, produced by the system itself. We do not issue your certificate. We make sure that when the certification body arrives, the answer to every evidence request already exists.

The short version

  • ISO/IEC 42001 certifies a working AI management system: policies, risk and impact assessments, controls, roles, and records kept current and evidenced over time.
  • Readiness is a set of artifacts that exist, are current, and are owned, chief among them a live AI system and model inventory.
  • The usual gaps are not the policy but the inventory, the written basis for decisions, and the evidence that controls actually operate.
  • The certificate is issued by an accredited certification body, not a consultant or platform; Stallwart produces the evidence trail the audit asks for, not the certificate.
The short answers

Questions this raises

What is an AI management system under ISO 42001?
It is the set of policies, roles, risk and impact assessments, operational controls, and records your organization uses to govern how it builds, buys, and runs AI. ISO/IEC 42001 certifies that this system exists and operates, not that any single model is safe.
How long does it take to get ready for an ISO 42001 audit?
It depends on how much AI you run and how much evidence already exists. Teams with a current inventory and recorded decisions move quickly; teams starting from an unknown AI footprint spend most of their time building the inventory and the evidence trail first. The policy layer is the fast part.
Does Stallwart certify us for ISO 42001?
No. Certification is issued only by an accredited certification body after a two-stage audit. Stallwart does not certify anyone and holds no certificate to grant. We build the live inventory, documentation, controls, and continuous evidence trail the auditor asks to see.
What evidence does an ISO 42001 auditor ask for?
A current AI system and model inventory, risk and impact assessments with named risk acceptance, a Statement of Applicability, role and competence records, operational controls with a written basis, logs and approvals showing controls operating over time, and internal audit and management-review records.
How is ISO 42001 different from the EU AI Act?
ISO/IEC 42001 is a voluntary, certifiable management-system standard about how you govern AI internally. The EU AI Act is binding law that imposes obligations by risk tier on AI placed on or used in the EU market. A 42001-conformant AIMS can help you meet AI Act duties, but the two are separate and one does not automatically satisfy the other.

Recognize this in your own operation?

Bring us the version of it happening in your business and we will tell you which part a system can take over.

Book a call