Skip to main content
Orion Five Engineering

10 Jalan Kilang #04-05, Singapore 159410
+65 6100 5505

Resources · Tool

ISO 42001 Readiness Check

Seventeen questions mapped to clauses 4 through 10 of ISO/IEC 42001:2023 and its Annex A controls. It returns a gap list ordered by audit exposure — where a certification body would raise a major — with the specific evidence each clause requires. It is a self-assessment, not a certification opinion, and the difference matters.

A machined steel embossing seal press closed on the corner of a sheet of thick cotton paper, raising a blind-embossed circular impression with nothing written in it.
Takes
8 minutes
You get
A clause-by-clause gap list, ranked by audit exposure
Cost
Free, no sign-up

Everything below runs in your browser. Nothing you enter is sent to us, stored, or logged, and closing the tab discards it. Answer as an auditor would find things, not as you intend them to be. The tool is only useful at the level you would be tested.

ISO/IEC 42001 clause structureFour boxes in a row labelled Plan, Do, Check and Act, following the management system cycle. Plan holds clause 4 context, clause 5 leadership and clause 6 planning. Do holds clause 7 support and clause 8 operation. Check holds clause 9 performance evaluation. Act holds clause 10 improvement. An arrow returns from Act back to Plan to show the cycle repeating. Clause 6.1.4, the AI system impact assessment, is called out separately as the requirement with no ISO 27001 equivalent.Plan4 Context5 Leadership · 6 PlanningDo7 Support8 OperationCheck9 Performance eval.Act10 Improvementand round again — the standard is a cycle, not a project6.1.4 — AI system impact assessmentno ISO 27001 equivalent, and the usual gap
Clauses 4 to 10 in the order an auditor walks them. Clause 8 is where they find out whether clause 6 is real, and clause 9 is where they find out whether anybody has been checking.

Clause 4 · Context of the organisation

UNIT 01

Do you know which of your activities count as AI, who cares about them, and where you have drawn the boundary of the management system?

Is there a written scope saying which AI systems the management system covers?

Including, explicitly, what is outside it. An undefined boundary is the most common opening finding.

Have you identified who is affected by these systems and what they require?

Clause 5 · Leadership and policy

UNIT 02

Has top management actually committed to this, in a policy, with roles and authorities assigned by name?

Is there an approved AI policy, communicated to the people it applies to?
Are responsibilities and authorities for AI assigned to named people?

Named individuals, not functions. "IT owns it" is not an assignment.

Clause 6.1.2–6.1.3 · AI risk assessment and treatment

UNIT 03

Do you have a repeatable way of identifying and treating AI risk, and can two people running it reach the same answer?

Is there a repeatable AI risk assessment process?

Repeatable means two competent people running it on the same system reach comparable conclusions.

Is there a risk treatment plan and a Statement of Applicability?

Clause 6.1.4 · AI system impact assessment

UNIT 04

Have you assessed what your AI systems do to the people and groups affected by them, not just to the organisation?

Do you assess the impact of AI systems on individuals and groups affected by them?

This is 42001's distinctive requirement, and the one most often skipped by organisations arriving from ISO 27001.

Is it defined when an impact assessment is required and when it must be redone?

Clause 7 · Support — competence, awareness, documentation

UNIT 05

Do the people running these systems have demonstrable competence, and is the documented information under control?

Can you demonstrate the competence of the people running these systems?
Is documented information controlled — versioned, approved and retained?

Clause 8 · Operational planning and control

UNIT 06

Is the management system actually operating — are the assessments being run when they should be, and are changes controlled?

Are AI risk and impact assessments actually performed at planned points in the life cycle?

Clause 8 is where an auditor finds out whether Clause 6 is real.

Do you control AI capability provided by third parties?

Model APIs, hosted services, embedded vendor AI, and anything an integrator supplies with equipment.

Clause 9 · Performance evaluation

UNIT 07

Do you measure whether the system works, audit it internally, and put it in front of management on a schedule?

Is there an internal audit programme, with audits completed?
Does top management review the AI management system on a schedule?

Clause 10 · Improvement and nonconformity

UNIT 08

When something goes wrong, is it recorded, corrected at the cause, and closed out?

Are nonconformities recorded, root-caused, and closed out?

Annex A · Annex A controls

UNIT 09

Have you worked through the AI-specific controls — data, life cycle, transparency, third parties, use — and justified what you excluded?

Have you worked through the Annex A controls and recorded a position on each?

Annex A covers policy, internal organisation, resources, impact assessment, life cycle, data, information for interested parties, use, and third parties.

Is there control over the data used by these systems — provenance, quality and preparation?

0 of 17 answered — the result appears when the last one is in

Gap list

UNIT 10

ANSWER ALL 17 QUESTIONS TO SEE THE GAP LIST

What this is and is not

UNIT 11

This is a self-assessment. It is not certification, not a Stage 1 audit, and not a substitute for either. A certification body forms its opinion from evidence — records, interviews, and what it observes on site — and none of that is visible here. What the tool can tell you is which clauses you would struggle to evidence, which is exactly the list worth having before you spend money on an external audit.

The weighting reflects audit exposure rather than effort. Clauses 5, 6.1.2–6.1.3, 6.1.4, 8 and 9 carry the highest weight because they are where major nonconformities are most often raised: leadership and policy, the risk and impact assessment machinery, evidence that the machinery is actually operating, and evidence that somebody is checking it.

One pattern is worth naming in advance. Organisations arriving at 42001 from ISO 27001 tend to score well on clauses 4, 5, 7 and 10, because the harmonised structure is familiar — and then find their gap concentrated at 6.1.4, the AI system impact assessment. That clause has no equivalent in 27001. It asks about consequences for the people affected by the system rather than risks to the organisation, and it is the requirement that makes 42001 a different standard rather than an extension of an existing one.

Orion Five holds an ISO/IEC 42001 Lead Auditor credential, which is why this tool exists in this form. It is also why the paragraph above says plainly what the tool cannot do.

Technical references

UNIT 12

What the reasoning on this page is drawn from. Where a standard costs money to read it is marked, and where a free document covers the same ground better it is listed first.

Links open in a new tab so anything you have entered above survives. Every one was checked at build time; if one has rotted since, tell us and it comes out rather than getting patched from memory.

Every one of these tools is a compressed version of a conversation. If yours turned up something you would rather talk through than read about, that is what the scoping call is for — bring your result with you.

Talk to a certified ISO 42001 lead auditor

Also on the shelf