{
  "name": "ISO/IEC 42001 readiness assessment",
  "version": "1.0.0",
  "reviewed": "2026-08-03",
  "licence": "CC BY 4.0",
  "source": "https://www.pk-sharma.com/tools/iso-42001-readiness",
  "note": "Clause and control-objective numbers and short titles are identifiers used as references. No text from ISO/IEC 42001 is reproduced: the goodLooksLike, whyItMatters and commonGap fields are original writing. Annex A is assessed at control-objective level rather than individual control level. The standard itself must be purchased from ISO or a national standards body.",
  "count": 31,
  "items": [
    {
      "ref": "4.1",
      "slug": "context",
      "title": "Context of the organisation",
      "section": "4. Context",
      "goodLooksLike": "A documented understanding of the internal and external issues that affect your use of AI: your sector, the regulation reaching you, your risk appetite, and the role you play as a developer, provider or deployer.",
      "whyItMatters": "Everything downstream is judged against this. A scope or risk assessment that does not follow from a stated context has nothing to be consistent with.",
      "commonGap": "The context is written generically and could describe any organisation, which tells an assessor it was produced for the file rather than from analysis.",
      "weight": 1
    },
    {
      "ref": "4.2",
      "slug": "interested-parties",
      "title": "Needs and expectations of interested parties",
      "section": "4. Context",
      "goodLooksLike": "An identified set of interested parties and what each requires: customers, regulators, employees, and the people affected by decisions your AI systems influence.",
      "whyItMatters": "AI management systems are distinctive in that affected individuals are interested parties even when they are not your customers. Missing them is a structural error rather than an omission.",
      "commonGap": "The list covers customers and regulators and omits the people the AI system acts upon, which is the group the standard most cares about.",
      "weight": 1
    },
    {
      "ref": "4.3",
      "slug": "scope",
      "title": "Scope of the AI management system",
      "section": "4. Context",
      "goodLooksLike": "A written scope stating which AI systems, functions, locations and roles are covered, with justification for anything excluded.",
      "whyItMatters": "Scope decides the cost of everything that follows. Drawn too narrowly it fails to cover what customers ask about; drawn too widely it commits you to work you cannot sustain.",
      "commonGap": "Scope is defined by legal entity rather than by AI system, so it is impossible to tell whether a given system is inside it.",
      "weight": 2
    },
    {
      "ref": "4.4",
      "slug": "aims",
      "title": "The AI management system itself",
      "section": "4. Context",
      "goodLooksLike": "The processes making up the management system are established and their interactions understood, rather than existing as a folder of documents.",
      "whyItMatters": "This is the clause that asks whether you have a system or a set of artefacts. Assessors test it by following one process end to end.",
      "commonGap": "Documents exist for each requirement with nothing connecting them, so the system cannot be traced from context through to improvement.",
      "weight": 1
    },
    {
      "ref": "5.1",
      "slug": "leadership",
      "title": "Leadership and commitment",
      "section": "5. Leadership",
      "goodLooksLike": "Evidence that top management is accountable: resources allocated, objectives set, decisions taken about AI use, and attention given when something went wrong.",
      "whyItMatters": "Every management system standard tests leadership behaviourally rather than by signature. AI raises the stakes because the decisions are often commercial rather than technical.",
      "commonGap": "A signed policy is offered as the whole evidence, with no record of management deciding anything about AI.",
      "weight": 2
    },
    {
      "ref": "5.2",
      "slug": "ai-policy",
      "title": "AI policy",
      "section": "5. Leadership",
      "goodLooksLike": "An approved policy stating your principles for developing and using AI, appropriate to the organisation, communicated, and specific enough to rule something out.",
      "whyItMatters": "A policy that forbids nothing provides no basis for the decisions the rest of the system has to make.",
      "commonGap": "The policy is a statement of values with no prohibitions, thresholds or escalation points, so no decision can be tested against it.",
      "weight": 2
    },
    {
      "ref": "5.3",
      "slug": "roles",
      "title": "Roles, responsibilities and authorities",
      "section": "5. Leadership",
      "goodLooksLike": "Named accountability for AI governance, with the authority attached to it, and the people named able to describe what they own.",
      "whyItMatters": "AI responsibility routinely falls between data protection, security and the product team. Where it is unassigned, nothing operates.",
      "commonGap": "Responsibility sits with a committee rather than a person, so no individual can be asked what they decided.",
      "weight": 1
    },
    {
      "ref": "6.1.2",
      "slug": "risk-assessment",
      "title": "AI risk assessment",
      "section": "6. Planning",
      "goodLooksLike": "A repeatable method for assessing AI risk, applied to your actual systems, producing rated risks with owners rather than a generic register.",
      "whyItMatters": "This is the engine of the management system. Controls that do not follow from assessed risk cannot be justified, and an assessor will ask you to make that link explicitly.",
      "commonGap": "The risk assessment lists risks common to all AI rather than risks arising from the systems this organisation actually runs.",
      "weight": 2
    },
    {
      "ref": "6.1.3",
      "slug": "risk-treatment",
      "title": "AI risk treatment",
      "section": "6. Planning",
      "goodLooksLike": "A treatment plan tracing each assessed risk to the controls addressing it, with residual risk accepted at the right level.",
      "whyItMatters": "The traceability from risk to control to acceptance is the single most examined chain in a certification audit.",
      "commonGap": "Controls were selected first and the risk assessment written afterwards to justify them, which is visible immediately in the numbering.",
      "weight": 2
    },
    {
      "ref": "6.1.4",
      "slug": "impact-assessment",
      "title": "AI system impact assessment",
      "section": "6. Planning",
      "goodLooksLike": "A process for assessing the impact of AI systems on individuals and society, applied and documented for the systems in scope.",
      "whyItMatters": "This is what most distinguishes ISO 42001 from an information security management system. It considers harm to people rather than harm to the organisation, and it is where AI-specific expectations concentrate.",
      "commonGap": "The impact assessment is a data protection impact assessment relabelled, so it examines privacy and not fairness, contestability or the consequences of being wrong.",
      "weight": 2
    },
    {
      "ref": "6.2",
      "slug": "objectives",
      "title": "AI objectives and planning",
      "section": "6. Planning",
      "goodLooksLike": "Measurable objectives for AI governance, with the plan to reach them: who, by when, with what resource, and how success is measured.",
      "whyItMatters": "Objectives are what performance evaluation later measures against. Without them clause 9 has nothing to assess.",
      "commonGap": "Objectives are aspirational statements with no measure attached, so no monitoring can determine whether they were met.",
      "weight": 1
    },
    {
      "ref": "6.3",
      "slug": "change-planning",
      "title": "Planning of changes",
      "section": "6. Planning",
      "goodLooksLike": "Changes to the management system are planned rather than made ad hoc, with consideration of consequences and resource.",
      "whyItMatters": "AI systems change fast: new models, new capability, new suppliers. A management system without change planning falls out of date between audits.",
      "commonGap": "The system was designed once at implementation and no process exists for changing it deliberately.",
      "weight": 1
    },
    {
      "ref": "7.2",
      "slug": "competence",
      "title": "Competence",
      "section": "7. Support",
      "goodLooksLike": "The competence needed for AI governance is defined, the gap against it assessed, and training or recruitment evidenced.",
      "whyItMatters": "AI governance requires understanding both the technology and the harm. Very few organisations have that combination and can show it.",
      "commonGap": "Competence is assumed because the team is technical, with no assessment of whether anyone understands AI-specific risk.",
      "weight": 1
    },
    {
      "ref": "7.3",
      "slug": "awareness",
      "title": "Awareness",
      "section": "7. Support",
      "goodLooksLike": "People know the AI policy, what it requires of them, and the consequences of not following it, including staff using AI tools rather than building them.",
      "whyItMatters": "Most AI risk in an organisation now arrives through ordinary staff using ordinary tools, not through a development team.",
      "commonGap": "Awareness activity targets the AI team, while the people most likely to put client data into an AI tool have received nothing.",
      "weight": 1
    },
    {
      "ref": "7.4",
      "slug": "communication",
      "title": "Communication",
      "section": "7. Support",
      "goodLooksLike": "Defined internal and external communication on AI matters: what is communicated, when, to whom, and by whom.",
      "whyItMatters": "External communication about AI is where organisations create obligations they later cannot meet, so an assessor looks at what you have already claimed publicly.",
      "commonGap": "Marketing claims about AI capability were never reviewed against what the governance evidence supports.",
      "weight": 1
    },
    {
      "ref": "7.5",
      "slug": "documented-information",
      "title": "Documented information",
      "section": "7. Support",
      "goodLooksLike": "Documents are controlled: versioned, approved, available where needed, and retired when superseded.",
      "whyItMatters": "Uncontrolled documentation undermines every other clause, because nobody can tell which version was in force when a decision was taken.",
      "commonGap": "Several versions of the same policy circulate and staff act on whichever they were sent.",
      "weight": 1
    },
    {
      "ref": "8.1",
      "slug": "operational-control",
      "title": "Operational planning and control",
      "section": "8. Operation",
      "goodLooksLike": "The processes the management system requires are actually running, with records showing they run rather than exist.",
      "whyItMatters": "This is where documented becomes operating, and it is the transition most organisations have not made when they book the audit.",
      "commonGap": "Processes are documented and were performed once at implementation, with no evidence of the second cycle.",
      "weight": 2
    },
    {
      "ref": "8.4",
      "slug": "operational-impact",
      "title": "Impact assessment in operation",
      "section": "8. Operation",
      "goodLooksLike": "Impact assessments are performed when new AI systems are introduced or materially changed, not only during implementation.",
      "whyItMatters": "An impact assessment process that only ever ran once is a project artefact rather than an operating control.",
      "commonGap": "Systems introduced since certification never went through the process, because nothing triggers it.",
      "weight": 2
    },
    {
      "ref": "9.1",
      "slug": "monitoring",
      "title": "Monitoring, measurement, analysis and evaluation",
      "section": "9. Performance",
      "goodLooksLike": "Defined measures for whether the AI management system is working, with results analysed and acted upon.",
      "whyItMatters": "Without measurement, improvement in clause 10 has no input and management review has nothing to review.",
      "commonGap": "Measures track activity, such as training completion, rather than effectiveness, such as whether AI risk decisions improved.",
      "weight": 1
    },
    {
      "ref": "9.2",
      "slug": "internal-audit",
      "title": "Internal audit",
      "section": "9. Performance",
      "goodLooksLike": "A planned audit programme covering the whole management system, performed by someone independent of the work audited, with findings raised and closed.",
      "whyItMatters": "An internal audit that finds nothing is the strongest signal available that the audit was not real, and assessors treat it that way.",
      "commonGap": "The internal audit is performed by the person who built the management system, which is not independence however competent they are.",
      "weight": 2
    },
    {
      "ref": "9.3",
      "slug": "management-review",
      "title": "Management review",
      "section": "9. Performance",
      "goodLooksLike": "Top management reviews the system at planned intervals, covering the required inputs, and the minutes record decisions rather than attendance.",
      "whyItMatters": "Management review is the clause where leadership commitment becomes evidence, and it is straightforward to fail because the inputs are prescribed.",
      "commonGap": "The review took place but the minutes record no decision, so there is nothing to demonstrate the system was actually directed.",
      "weight": 2
    },
    {
      "ref": "10.2",
      "slug": "nonconformity",
      "title": "Nonconformity and corrective action",
      "section": "10. Improvement",
      "goodLooksLike": "Nonconformities are recorded, their causes examined, corrective action taken, and effectiveness checked afterwards.",
      "whyItMatters": "An empty nonconformity log across a full cycle suggests either nothing is being examined or findings are not being recorded.",
      "commonGap": "Corrective actions fix the instance without examining the cause, so the same finding returns at the next audit.",
      "weight": 1
    },
    {
      "ref": "A.2",
      "slug": "policies-for-ai",
      "title": "Policies related to AI",
      "section": "Annex A",
      "goodLooksLike": "A policy set covering AI specifically, reviewed on a schedule, and supported by the topic-level policies your use of AI requires.",
      "whyItMatters": "The control objectives in Annex A are where the AI-specific expectations sit, and policy is the foundation the rest reference.",
      "commonGap": "AI is addressed by a paragraph inserted into an existing IT policy rather than by anything written for the purpose.",
      "weight": 1
    },
    {
      "ref": "A.3",
      "slug": "internal-organization",
      "title": "Internal organisation",
      "section": "Annex A",
      "goodLooksLike": "Clear allocation of AI responsibilities across the organisation, including a route for reporting concerns about an AI system.",
      "whyItMatters": "AI concerns are frequently raised by people with no obvious route to raise them, and that route is what this objective is testing for.",
      "commonGap": "There is no mechanism for an employee to raise a concern about an AI system's behaviour.",
      "weight": 1
    },
    {
      "ref": "A.4",
      "slug": "resources",
      "title": "Resources for AI systems",
      "section": "Annex A",
      "goodLooksLike": "The resources your AI systems depend on are documented: data, tooling, compute, human oversight and the systems themselves.",
      "whyItMatters": "You cannot govern what you have not enumerated, and this is the objective that forces the inventory to exist.",
      "commonGap": "No AI system inventory exists, so the organisation cannot state how many AI systems it operates.",
      "weight": 2
    },
    {
      "ref": "A.5",
      "slug": "impacts",
      "title": "Assessing impacts of AI systems",
      "section": "Annex A",
      "goodLooksLike": "A documented approach to assessing impact on individuals and society, applied consistently, with the results feeding risk treatment.",
      "whyItMatters": "This is the heart of what makes ISO 42001 different, and it is the objective that maps most directly onto emerging regulation.",
      "commonGap": "Impact is considered informally in design discussions but never recorded, so nothing can be produced when asked.",
      "weight": 2
    },
    {
      "ref": "A.6",
      "slug": "life-cycle",
      "title": "AI system life cycle",
      "section": "Annex A",
      "goodLooksLike": "Defined requirements across the life cycle: objectives, design, verification, deployment, operation and retirement, with records at each stage.",
      "whyItMatters": "Retirement is the stage nobody plans, and models left running after their owner leaves are a common and awkward finding.",
      "commonGap": "The life cycle covers development and deployment and stops, with no process for decommissioning a model.",
      "weight": 1
    },
    {
      "ref": "A.7",
      "slug": "data",
      "title": "Data for AI systems",
      "section": "Annex A",
      "goodLooksLike": "Documented provenance, quality and preparation of data used in AI systems, with the basis for using it recorded.",
      "whyItMatters": "Data provenance is where AI governance meets both data protection and intellectual property, and it is increasingly what customers ask about first.",
      "commonGap": "Training and fine-tuning data provenance was never documented, so the organisation cannot demonstrate it had the right to use it.",
      "weight": 2
    },
    {
      "ref": "A.8",
      "slug": "information-for-parties",
      "title": "Information for interested parties",
      "section": "Annex A",
      "goodLooksLike": "Documented information provided to users and affected parties about the AI system: what it does, its limitations, and how to contest an outcome.",
      "whyItMatters": "Transparency obligations are converging across regulation, and this objective is where you demonstrate you already meet them.",
      "commonGap": "Users are not told they are interacting with an AI system, or told with no route to challenge what it produced.",
      "weight": 1
    },
    {
      "ref": "A.9",
      "slug": "responsible-use",
      "title": "Responsible use of AI systems",
      "section": "Annex A",
      "goodLooksLike": "Defined intended use, documented limits, and controls preventing use outside them, including human oversight where it matters.",
      "whyItMatters": "Most AI harm arises from a system used outside its intended purpose, which is a governance failure rather than a technical one.",
      "commonGap": "Intended use is documented and nothing detects or prevents use beyond it.",
      "weight": 1
    },
    {
      "ref": "A.10",
      "slug": "third-party",
      "title": "Third-party and customer relationships",
      "section": "Annex A",
      "goodLooksLike": "Responsibilities allocated across the AI supply chain, with supplier assessment covering AI-specific matters and contracts reflecting them.",
      "whyItMatters": "Most organisations consume AI rather than build it, which makes this the objective doing the most work in practice.",
      "commonGap": "AI suppliers are assessed with a generic IT security questionnaire that asks nothing about models, training data or output liability.",
      "weight": 2
    }
  ]
}