1. Internal & External Factors (4.1)
Has the organization identified and evaluated the internal and external factors – including legal, regulatory, ethical, societal, and technological considerations – that are relevant to the development, provision, or use of AI systems and that may influence the AIMS?
2. Interested Parties' Needs (4.2)
Has the organization determined the needs and expectations of relevant interested parties (such as employees, customers, regulators, and affected communities) in relation to AI governance, and identified which of those requirements are applicable to the AIMS?
3. Scope of AIMS (4.3)
Has the organization clearly defined the scope of its AI Management System, specifying which AI systems, organizational units, locations, functions, and processes are included, and documented this scope in a formally maintained statement?
4. AIMS Processes & Ownership (4.4)
Has the organization defined and implemented the processes, roles, responsibilities, and continual improvement mechanisms necessary to establish, implement, maintain, and continually improve the AIMS in accordance with ISO/IEC 42001:2023?
5. Leadership & Commitment (5.1)
Has top management demonstrated active commitment to the AI Management System by integrating AI governance into the organization’s strategic direction, ensuring adequate resources, and championing a responsible AI culture across all relevant functions?
6. AI Policy (5.2)
Has the organization established a documented AI policy that states its objectives and commitment to responsible AI, aligns with the organization’s purpose and strategic context, and has been communicated to all personnel and relevant stakeholders?
7. Roles, Responsibilities & Authorities (5.3)
Have roles, responsibilities, and authorities for AI governance been clearly defined, assigned, and communicated, including accountability for ensuring the AIMS conforms to ISO/IEC 42001:2023 requirements and for reporting AIMS performance to top management?
8. Operational Awareness & Leadership (5.3)
Has leadership ensured that AI objectives and responsible AI principles are understood and applied at the operational level, and that personnel are aware of how their roles contribute to the effectiveness of the AIMS and to ethical AI outcomes?
9. Risks and Opportunities (6.1)
Has the organization identified the risks and opportunities associated with its AI systems – including risks to fairness, transparency, safety, privacy, and security – and determined actions to address them in a manner proportionate to their potential impact?
10. AI Risk Assessment Methodology (6.1.2)
Has the organization established and implemented a defined methodology for AI risk assessment that includes criteria for evaluating the likelihood and severity of harm, covers the full AI system lifecycle, and produces consistent and reproducible results?
11. AI Impact Assessments (6.1.3)
Has the organization conducted AI impact assessments for its AI systems, and are the outcomes of these assessments used to inform risk treatment decisions, design choices, and operational controls?
12. Risk Treatment & Controls (6.1.4)
Have risk treatment options been selected and applied for AI-related risks, including the identification and implementation of appropriate controls from ISO/IEC 42001 Annex A, and has a Statement of Applicability been documented to justify the inclusion or exclusion of applicable controls?
13. AI Management Objectives (6.2)
Have measurable AI management objectives been established, documented, and communicated across the organization, with defined plans specifying what will be done, who is responsible, the resources required, timelines, and how results will be evaluated?
14. Resources Allocation (7.1)
Has the organization determined and provided the resources – including personnel, infrastructure, technology, data, and financial resources – needed to establish, implement, maintain, and continually improve the AIMS, including resources specific to responsible AI development and governance?
15. Competency & Development (7.2)
Are individuals performing AI-related roles – including AI development, deployment, procurement, and oversight functions – competent on the basis of appropriate education, training, or experience, and are competency gaps identified and addressed through targeted development actions?
16. Awareness of AI Policy & Principles (7.3)
Are personnel and relevant stakeholders made aware of the AI policy, AI objectives, the ethical principles underpinning the organization’s AI approach, their individual responsibilities in supporting the AIMS, and the potential consequences of non-conformance?
17. Communication & Documented Information (7.4 & 7.5)
Is documented information required by ISO/IEC 42001:2023 properly created, maintained, protected, distributed, and controlled, and are internal and external communication requirements for AI governance clearly defined, including the audience, content, timing, and channels?
18. Operational Planning & Controls (8.1)
Has the organization planned, implemented, and controlled the processes needed to meet AI management requirements and deliver on its AI objectives, ensuring that these processes are executed as planned and that documented evidence of operational activities is maintained?
19. AI System Lifecycle Management (8.2)
Does the organization manage the full AI system lifecycle – from requirements definition and data acquisition through to development, testing, deployment, monitoring, and decommissioning – with defined controls applied at each stage to ensure responsible and ethical outcomes?
20. Control of AI Changes (8.2)
When changes to AI systems, their operational context, or the data they rely upon are planned, are these changes assessed, reviewed, and controlled to identify and mitigate any new or changed risks prior to implementation?
21. Third-Party AI Suppliers & Partners (8.3)
Are third-party AI suppliers, partners, and providers of AI-related products or services subject to defined governance requirements, including contractual obligations relating to responsible AI, transparency, data handling, and conformance with the organization’s AI policy and applicable controls?
22. Risk Treatment Plan Implementation (8.4)
Are AI risk treatment plans actively implemented and monitored, are residual risks formally accepted by authorized personnel, and are periodic AI risk assessments conducted with documented records maintained to demonstrate accountability and enable management review?
23. Monitoring, Measurement & Analysis (9.1)
Has the organization determined what needs to be monitored and measured in relation to the AIMS and its AI systems, including the methods to be used, the frequency of monitoring, who is responsible, and how results are documented, analyzed, and acted upon?
24. Operational Behavior & Incident Monitoring (9.1)
Are AI system performance and behavior monitored in operation to detect unintended outputs, model drift, fairness degradation, or safety incidents, and are monitoring results used to trigger corrective actions and feed into AIMS improvement activities?
25. AIMS Internal Audits (9.2)
Are internal audits of the AIMS conducted at planned intervals by competent and impartial auditors, with audit scope, criteria, findings, and corrective actions properly documented and reported to top management?
26. Management Reviews (9.3)
Does top management conduct periodic management reviews of the AIMS, taking into account audit results, performance data, changes in context, stakeholder feedback, and progress against AI objectives, and are review outcomes documented with decisions and actions clearly recorded?
27. Nonconformities & Remediation (9.4)
Is a formal process in place to identify, record, and manage nonconformities and issues detected through monitoring or audit activities, and are corrective actions taken, root causes investigated, and effectiveness of remediation verified and documented?
28. Incident Investigation & Root Cause (10.1)
When a nonconformity or AI-related incident occurs, does the organization take prompt corrective action, investigate and address the root cause to prevent recurrence, verify the effectiveness of the corrective action taken, and retain documented evidence of the investigation and outcome?
29. Improvement Actions Tracking (10.2)
Does the organization identify opportunities to improve the suitability, adequacy, and effectiveness of the AIMS on an ongoing basis, and are improvement actions prioritized, planned, and tracked through to completion?
30. AIMS Continual Improvement (10.3)
Is the AIMS subject to continual improvement informed by performance evaluation outcomes, lessons learned from AI incidents, changes in the external AI regulatory and ethical landscape, and evolving stakeholder expectations, so that the organization’s AI governance practices advance over time?