DoAIRight
ISO/IEC 42001

ISO 42001 Checklist: Clauses 4–10 & Annex A Controls

PUBLISHED 06 AUG 2026

An ISO 42001 checklist provides a structured roadmap for establishing, implementing, and maintaining an artificial intelligence management system (AIMS) compliant with ISO/IEC 42001:2023. It synthesizes the core management system requirements found in Clauses 4 through 10 with the tactical safeguards outlined in Annex A control domains. By addressing both high-level governance and operational control implementations, organizations can systematically manage AI risks, fulfill regulatory expectations, and safeguard individuals, groups, and society from potential AI impacts.

The Core Management System: Clauses 4–10

The standard requirements follow the standard High-Level Structure (HLS) common to modern management system standards. To comply, organizations must establish policies, processes, and governance across seven key clauses:

  • Clause 4: Context of the Organization — Understand your world, your AI, and your role in it. Define internal and external factors influencing your AI initiatives, identify key stakeholders (interested parties), and clearly delineate the scope of your AIMS.
  • Clause 5: Leadership — Top management owns responsible AI — and proves it. Executive leadership must commit resources, establish an overarching AI policy, assign roles and responsibilities, and integrate responsible AI governance into core strategic objectives.
  • Clause 6: Planning — Turn risks, impacts, and objectives into a concrete plan. Identify specific risks and societal impacts associated with your AI use cases. Set measurable AI objectives and establish actionable pathways to achieve them.
  • Clause 7: Support — Resource it, staff it, communicate it, document it. Provide the necessary infrastructure, financial backing, and skilled personnel. Maintain comprehensive awareness programs, internal and external communication channels, and clear documented information.
  • Clause 8: Operation — Run the controls, keep risk & impact current. Execute operational plans, complete AI risk and impact assessments routinely, and implement chosen controls throughout daily workflows.
  • Clause 9: Performance Evaluation — Measure it, audit it, review it. Track performance metrics, conduct internal audits, evaluate system efficacy, and report management reviews to executive leaders.
  • Clause 10: Improvement — Fix root causes; get better continually. Address nonconformities, implement corrective actions, and foster ongoing enhancements to adapt to evolving AI capabilities and threats.

Technical and Operational Safeguards: Annex A Controls

While Clauses 4–10 set up governance, Annex A provides specific control objectives and controls categorized into nine distinct domains (A.2 through A.10). Organizations select controls based on their applicability statement and risk assessments.

A.2 Policies Related to AI

Establish organizational policies specifically tailored to artificial intelligence. Ensure regular reviews and alignment with legal, regulatory, and ethical guidelines.

A.3 Internal Organization

Define structural roles and responsibilities to ensure accountability. Establish clear segregation of duties and governance committees to oversee AI decision-making.

A.4 Resources for AI Systems

Allocate adequate technological, human, and data infrastructure resources. Provide training to staff operating or managing AI environments.

A.5 Assessing Impacts of AI Systems

Conduct formal assessments evaluating how AI systems affect stakeholders. ISO 42001 explicitly requires evaluating potential harm or bias against individuals, groups, and broader society.

A.6 AI System Life Cycle

Govern the entire end-to-end lifecycle, including concept, design, development, deployment, verification, operation, and retirement of AI systems.

A.7 Data for AI Systems

Implement robust data governance. Manage data quality, provenance, acquisition, preprocessing, labeling, and privacy across training, validation, and testing sets.

A.8 Information for Interested Parties

Promote transparency by providing accurate, clear, and relevant information about AI capabilities, limitations, and operational behaviors to external users, regulators, and affected parties.

A.9 Use of AI Systems

Establish guidance for responsible user deployment. Monitor usage patterns, define acceptable use policies, and maintain mechanisms for human oversight and intervention.

A.10 Third-Party and Customer Relationships

Manage risks associated with external AI vendors, pre-trained model providers, and third-party data sources through vendor risk management and contractual safeguards.

Practical Checklist for Certification Readiness

To prepare for formal auditing, your organization should work through these actionable steps:

  1. Define Scope & Context: Map out all AI systems, operational boundaries, and regulatory obligations.
  2. Conduct Impact & Risk Assessments: Evaluate AI threats to individuals, groups, and society.
  3. Draft a Statement of Applicability (SoA): Select relevant controls from Annex A domains A.2–A.10 and justify exclusions.
  4. Implement Controls & Documentation: Establish operational processes, data governance policies, and technical safeguards.
  5. Perform Internal Audits: Conduct independent internal reviews and management evaluations to verify compliance.
  6. Engage Accredited Certification Bodies: Certification is granted by an independent accredited certification body under auditor evaluation (following ISO/IEC 42006 guidelines).

Platforms like DoAIRight offer a free readiness assessment to help you evaluate your implementation progress, identify control gaps, and prepare your documentation before bringing in an external auditor.

Frequently asked

What is the main difference between Clauses 4–10 and Annex A controls?

Clauses 4–10 establish the overarching management system framework (governance, planning, leadership, and continuous improvement), while Annex A controls provide operational and technical safeguards specifically designed to manage AI risks.

Who awards ISO 42001 certification?

Certification is granted by an accredited independent third-party certification body following an audit. Management software or readiness platforms prepare your organization for the audit but do not issue official certificates.

What scope of impact must be assessed under ISO 42001?

ISO 42001 requires organizations to evaluate potential AI impacts broadly, specifically assessing consequences for individuals, targeted groups, and society as a whole.

How does DoAIRight help with ISO 42001 compliance?

DoAIRight provides tools and a free readiness assessment to analyze control gaps, streamline documentation, and structure your AI Management System so you are ready for a formal certification audit.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score