

Free tool
ISO 42001 readiness assessment
Score your AI management system clause by clause, get an instant readiness percentage and a gap list ordered by what to fix first. No email gate.
Every free ISO 42001 gap assessment turns out to be a PDF behind a form, which is an odd way to help someone work out where they stand. This is the assessment itself: every clause and control objective, what an assessor actually expects to see, and where organisations usually fall short. Score yourself and the gap list orders itself by what matters rather than by clause number.
Nothing leaves your browser: A readiness assessment is a candid record of where you are weakest, which is exactly the sort of thing that should not be posted to someone else's server in exchange for a report. Your scores are saved in this browser's local storage so you can close the tab and come back, which also means they stay on this device until you clear them and anyone using this browser profile can read them. Nothing is sent anywhere, the page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon, and you export the file yourself. A policy inside the page cannot stop you copying the result somewhere else, so what you do with it afterwards is yours to protect.
Readiness
—
Not yet assessed
Score each item below. Nothing is submitted, and your scores stay in this browser.
0 of 31 items assessed. Items that most often decide a certification outcome are weighted double.
- 4.1
A documented understanding of the internal and external issues that affect your use of AI: your sector, the regulation reaching you, your risk appetite, and the role you play as a developer, provider or deployer.
- 4.2
An identified set of interested parties and what each requires: customers, regulators, employees, and the people affected by decisions your AI systems influence.
- 4.3High weight
A written scope stating which AI systems, functions, locations and roles are covered, with justification for anything excluded.
- 4.4
The processes making up the management system are established and their interactions understood, rather than existing as a folder of documents.
- 5.1High weight
Evidence that top management is accountable: resources allocated, objectives set, decisions taken about AI use, and attention given when something went wrong.
- 5.2High weight
An approved policy stating your principles for developing and using AI, appropriate to the organisation, communicated, and specific enough to rule something out.
- 5.3
Named accountability for AI governance, with the authority attached to it, and the people named able to describe what they own.
- 6.1.2High weight
A repeatable method for assessing AI risk, applied to your actual systems, producing rated risks with owners rather than a generic register.
- 6.1.3High weight
A treatment plan tracing each assessed risk to the controls addressing it, with residual risk accepted at the right level.
- 6.1.4High weight
A process for assessing the impact of AI systems on individuals and society, applied and documented for the systems in scope.
- 6.2
Measurable objectives for AI governance, with the plan to reach them: who, by when, with what resource, and how success is measured.
- 6.3
Changes to the management system are planned rather than made ad hoc, with consideration of consequences and resource.
- 7.2
The competence needed for AI governance is defined, the gap against it assessed, and training or recruitment evidenced.
- 7.3
People know the AI policy, what it requires of them, and the consequences of not following it, including staff using AI tools rather than building them.
- 7.4
Defined internal and external communication on AI matters: what is communicated, when, to whom, and by whom.
- 7.5
Documents are controlled: versioned, approved, available where needed, and retired when superseded.
- 8.1High weight
The processes the management system requires are actually running, with records showing they run rather than exist.
- 8.4High weight
Impact assessments are performed when new AI systems are introduced or materially changed, not only during implementation.
- 9.1
Defined measures for whether the AI management system is working, with results analysed and acted upon.
- 9.2High weight
A planned audit programme covering the whole management system, performed by someone independent of the work audited, with findings raised and closed.
- 9.3High weight
Top management reviews the system at planned intervals, covering the required inputs, and the minutes record decisions rather than attendance.
- 10.2
Nonconformities are recorded, their causes examined, corrective action taken, and effectiveness checked afterwards.
- A.2
A policy set covering AI specifically, reviewed on a schedule, and supported by the topic-level policies your use of AI requires.
- A.3
Clear allocation of AI responsibilities across the organisation, including a route for reporting concerns about an AI system.
- A.4High weight
The resources your AI systems depend on are documented: data, tooling, compute, human oversight and the systems themselves.
- A.5High weight
A documented approach to assessing impact on individuals and society, applied consistently, with the results feeding risk treatment.
- A.6
Defined requirements across the life cycle: objectives, design, verification, deployment, operation and retirement, with records at each stage.
- A.7High weight
Documented provenance, quality and preparation of data used in AI systems, with the basis for using it recorded.
- A.8
Documented information provided to users and affected parties about the AI system: what it does, its limitations, and how to contest an outcome.
- A.9
Defined intended use, documented limits, and controls preventing use outside them, including human oversight where it matters.
- A.10High weight
Responsibilities allocated across the AI supply chain, with supplier assessment covering AI-specific matters and contracts reflecting them.
What the assessment covers
Clauses 4 to 10 follow the harmonised structure shared by every ISO management system standard, so if you hold ISO 27001 much of this will be familiar. Annex A is where the AI-specific expectations sit, and it is assessed here at control-objective level.
4. Context 4 items
- 4.1Context of the organisation
A documented understanding of the internal and external issues that affect your use of AI: your sector, the regulation reaching you, your risk appetite, and the role you play as a developer, provider or deployer.
Common gap: The context is written generically and could describe any organisation, which tells an assessor it was produced for the file rather than from analysis.
- 4.2Needs and expectations of interested parties
An identified set of interested parties and what each requires: customers, regulators, employees, and the people affected by decisions your AI systems influence.
Common gap: The list covers customers and regulators and omits the people the AI system acts upon, which is the group the standard most cares about.
- 4.3Scope of the AI management system
A written scope stating which AI systems, functions, locations and roles are covered, with justification for anything excluded.
Common gap: Scope is defined by legal entity rather than by AI system, so it is impossible to tell whether a given system is inside it.
- 4.4The AI management system itself
The processes making up the management system are established and their interactions understood, rather than existing as a folder of documents.
Common gap: Documents exist for each requirement with nothing connecting them, so the system cannot be traced from context through to improvement.
5. Leadership 3 items
- 5.1Leadership and commitment
Evidence that top management is accountable: resources allocated, objectives set, decisions taken about AI use, and attention given when something went wrong.
Common gap: A signed policy is offered as the whole evidence, with no record of management deciding anything about AI.
- 5.2AI policy
An approved policy stating your principles for developing and using AI, appropriate to the organisation, communicated, and specific enough to rule something out.
Common gap: The policy is a statement of values with no prohibitions, thresholds or escalation points, so no decision can be tested against it.
- 5.3Roles, responsibilities and authorities
Named accountability for AI governance, with the authority attached to it, and the people named able to describe what they own.
Common gap: Responsibility sits with a committee rather than a person, so no individual can be asked what they decided.
6. Planning 5 items
- 6.1.2AI risk assessment
A repeatable method for assessing AI risk, applied to your actual systems, producing rated risks with owners rather than a generic register.
Common gap: The risk assessment lists risks common to all AI rather than risks arising from the systems this organisation actually runs.
- 6.1.3AI risk treatment
A treatment plan tracing each assessed risk to the controls addressing it, with residual risk accepted at the right level.
Common gap: Controls were selected first and the risk assessment written afterwards to justify them, which is visible immediately in the numbering.
- 6.1.4AI system impact assessment
A process for assessing the impact of AI systems on individuals and society, applied and documented for the systems in scope.
Common gap: The impact assessment is a data protection impact assessment relabelled, so it examines privacy and not fairness, contestability or the consequences of being wrong.
- 6.2AI objectives and planning
Measurable objectives for AI governance, with the plan to reach them: who, by when, with what resource, and how success is measured.
Common gap: Objectives are aspirational statements with no measure attached, so no monitoring can determine whether they were met.
- 6.3Planning of changes
Changes to the management system are planned rather than made ad hoc, with consideration of consequences and resource.
Common gap: The system was designed once at implementation and no process exists for changing it deliberately.
7. Support 4 items
- 7.2Competence
The competence needed for AI governance is defined, the gap against it assessed, and training or recruitment evidenced.
Common gap: Competence is assumed because the team is technical, with no assessment of whether anyone understands AI-specific risk.
- 7.3Awareness
People know the AI policy, what it requires of them, and the consequences of not following it, including staff using AI tools rather than building them.
Common gap: Awareness activity targets the AI team, while the people most likely to put client data into an AI tool have received nothing.
- 7.4Communication
Defined internal and external communication on AI matters: what is communicated, when, to whom, and by whom.
Common gap: Marketing claims about AI capability were never reviewed against what the governance evidence supports.
- 7.5Documented information
Documents are controlled: versioned, approved, available where needed, and retired when superseded.
Common gap: Several versions of the same policy circulate and staff act on whichever they were sent.
8. Operation 2 items
- 8.1Operational planning and control
The processes the management system requires are actually running, with records showing they run rather than exist.
Common gap: Processes are documented and were performed once at implementation, with no evidence of the second cycle.
- 8.4Impact assessment in operation
Impact assessments are performed when new AI systems are introduced or materially changed, not only during implementation.
Common gap: Systems introduced since certification never went through the process, because nothing triggers it.
9. Performance 3 items
- 9.1Monitoring, measurement, analysis and evaluation
Defined measures for whether the AI management system is working, with results analysed and acted upon.
Common gap: Measures track activity, such as training completion, rather than effectiveness, such as whether AI risk decisions improved.
- 9.2Internal audit
A planned audit programme covering the whole management system, performed by someone independent of the work audited, with findings raised and closed.
Common gap: The internal audit is performed by the person who built the management system, which is not independence however competent they are.
- 9.3Management review
Top management reviews the system at planned intervals, covering the required inputs, and the minutes record decisions rather than attendance.
Common gap: The review took place but the minutes record no decision, so there is nothing to demonstrate the system was actually directed.
10. Improvement 1 item
- 10.2Nonconformity and corrective action
Nonconformities are recorded, their causes examined, corrective action taken, and effectiveness checked afterwards.
Common gap: Corrective actions fix the instance without examining the cause, so the same finding returns at the next audit.
Annex A 9 items
- A.2Policies related to AI
A policy set covering AI specifically, reviewed on a schedule, and supported by the topic-level policies your use of AI requires.
Common gap: AI is addressed by a paragraph inserted into an existing IT policy rather than by anything written for the purpose.
- A.3Internal organisation
Clear allocation of AI responsibilities across the organisation, including a route for reporting concerns about an AI system.
Common gap: There is no mechanism for an employee to raise a concern about an AI system's behaviour.
- A.4Resources for AI systems
The resources your AI systems depend on are documented: data, tooling, compute, human oversight and the systems themselves.
Common gap: No AI system inventory exists, so the organisation cannot state how many AI systems it operates.
- A.5Assessing impacts of AI systems
A documented approach to assessing impact on individuals and society, applied consistently, with the results feeding risk treatment.
Common gap: Impact is considered informally in design discussions but never recorded, so nothing can be produced when asked.
- A.6AI system life cycle
Defined requirements across the life cycle: objectives, design, verification, deployment, operation and retirement, with records at each stage.
Common gap: The life cycle covers development and deployment and stops, with no process for decommissioning a model.
- A.7Data for AI systems
Documented provenance, quality and preparation of data used in AI systems, with the basis for using it recorded.
Common gap: Training and fine-tuning data provenance was never documented, so the organisation cannot demonstrate it had the right to use it.
- A.8Information for interested parties
Documented information provided to users and affected parties about the AI system: what it does, its limitations, and how to contest an outcome.
Common gap: Users are not told they are interacting with an AI system, or told with no route to challenge what it produced.
- A.9Responsible use of AI systems
Defined intended use, documented limits, and controls preventing use outside them, including human oversight where it matters.
Common gap: Intended use is documented and nothing detects or prevents use beyond it.
- A.10Third-party and customer relationships
Responsibilities allocated across the AI supply chain, with supplier assessment covering AI-specific matters and contracts reflecting them.
Common gap: AI suppliers are assessed with a generic IT security questionnaire that asks nothing about models, training data or output liability.
Use the data
The full assessment set is published as JSON under CC BY 4.0, currently version 1.0.0. Build it into your own tooling or adapt it for your organisation.
What a score here does not tell you
This measures whether the right things are in place. It cannot measure how deep your evidence is, and depth is what a stage 2 audit examines. A management system scoring well with three weeks of operating history will not certify, because certification bodies want to see processes that have run through a full cycle: an internal audit that found something, a management review that decided something, a nonconformity that was closed and checked.
Treat a high score as permission to plan the audit, not to book it.
Common questions
›What is ISO 42001?
The international standard for an AI management system, published in December 2023. It is the AI equivalent of what ISO 27001 does for information security: a governance framework covering how an organisation develops, provides or uses AI systems, and it is certifiable by an accredited body.
›How long does ISO 42001 certification take?
For an organisation starting from nothing, realistically nine to fifteen months. The binding constraint is rarely writing the documentation; it is that the management system has to operate long enough to produce evidence an auditor can sample. An internal audit and a management review both need to have genuinely happened before a stage 2 audit is worth booking.
›We already have ISO 27001. Does that help?
Considerably. ISO 42001 uses the same harmonised structure, so your clause 4 to 10 processes, internal audit programme, management review and document control largely transfer. What does not transfer is the AI-specific work: the AI system inventory, impact assessment on individuals and society, and data provenance. Expect the reused portion to save months rather than to be most of the job.
›What is an AI system impact assessment?
An assessment of how an AI system affects individuals and society, as distinct from how it affects your organisation. It is the clearest difference between ISO 42001 and an information security management system, and it is the requirement most often satisfied incorrectly by relabelling a data protection impact assessment, which examines privacy rather than fairness, contestability or the consequences of being wrong.
›Does this reproduce the text of ISO 42001?
No. ISO holds copyright in the standard. Clause and control-objective numbers and short titles are identifiers used here as references, and every explanatory note is original writing about what assessors look for in practice. You still need to buy the standard, and Annex A is assessed here at control-objective level rather than individual control level.
›Is a good score enough to book the audit?
No, and it is worth being blunt about that. This measures whether you have the right things in place, not how deep the evidence is. Certification bodies want to see processes that have run through a full cycle. A high score with three weeks of operating history will not pass a stage 2 audit.
When you need more than a tool
ISO/IEC 42001 Implementation and Remediation
Full-cycle AI management system consultancy: gap analysis, AIMS implementation, remediation, and pre-audit review from first inventory to certification, led by an ISO/IEC 42001 Lead Auditor.
Start a readiness review
