Score your ISO 42001 readiness in one sitting, and know which gaps to close first.

26 questions across clauses 4 to 10 of ISO/IEC 42001:2023, each scored 2, 1 or 0. In about 45 minutes you will have a score out of 52, a readiness band, and the gaps in the order to close them. The PDF holds the same questions with tick boxes, for working through with your team.

Start on the page

Step 1 · Before you score

Put the evidence on the table first.

A yes needs four links in place: a document exists, a record shows it is used, someone owns it, and it has been reviewed. A stage 1 auditor reads in that order.

Pull the documents on the right into one folder before you start. Each answer then rests on something you can open. A yes means you could show the evidence to an auditor today, so a document nobody can find scores partial at best.

There is no submission and nothing to send anywhere.

The evidence folder

  • Scope statement for the AI management system
  • AI inventory, including AI inside SaaS tools
  • AI policy, with its approval record
  • AI risk method, risk register and treatment plan
  • Statement of Applicability
  • AI system impact assessments
  • AI objectives, with owners and dates
  • Competence and training records
  • Monitoring and measurement results
  • Internal audit programme and reports
  • Management review minutes
  • Nonconformity and corrective-action records

Take an AI policy that sits in the folder with no approval record and no review date. Question 5 scores 1.

Step 2 · Part 1 of 5 · Clauses 4 and 5 · 7 questions

Score the management system foundations.

Start with the inventory, because every other answer depends on knowing what you run. Few organisations can produce a complete AI inventory on request. The AI embedded in everyday SaaS tools is the part that gets missed.

If your register lists the platforms IT bought and nothing inside them, question 1 scores partial. APRA expects regulated entities to hold a complete AI inventory.

  1. 01

    Do you have a complete inventory of the AI systems you build, buy and use?

    Good looks like

    A register listing every AI system, including AI embedded inside SaaS tools, with an owner for each.

  2. 02

    Have you defined and written down the scope of your AI management system?

    Good looks like

    A scope statement covering which systems, teams and locations are in, and what is deliberately excluded and why.

  3. 03

    Have you identified your role for each AI system: developer, provider or user?

    Good looks like

    Each system tagged with your role, because the obligations differ when you build versus deploy a tool.

  4. 04

    Have you considered the interested parties affected by your AI, including customers and regulators?

    Good looks like

    A short analysis of who is affected by your AI and what they expect, feeding your objectives.

  5. 05

    Is there an approved AI policy that sets your principles for responsible AI?

    Good looks like

    A published policy signed off by leadership that aligns with your privacy, security and HR policies.

    A.2
  6. 06

    Has leadership taken visible ownership of AI governance?

    Good looks like

    Top management has set direction, allocated resources and reviews AI governance on a regular cadence.

  7. 07

    Are roles, responsibilities and authorities for AI assigned to named people?

    Good looks like

    A responsibility map naming who owns AI risk, who approves deployments and how concerns get raised.

    A.3

Step 3 · Part 2 of 5 · Clause 6 · 5 questions

Score planning and risk.

Clause 6 holds the risk assessment, the treatment plan, the Statement of Applicability and the impact assessment. A security review asks whether a system is protected. An impact assessment asks who could be harmed by its decisions.

If you only have the security review, question 11 scores partial at best. For question 10, the Annex A controls guide walks through all 38 decisions the Statement of Applicability records.

  1. 08

    Do you have a documented method for assessing AI risk?

    Good looks like

    A written methodology that scores likelihood and severity, covering technical risk and ethical or societal risk.

  2. 09

    Have you run that assessment and recorded the results in a risk register?

    Good looks like

    A populated AI risk register with owners, ratings and review dates.

  3. 10

    Do you have a risk treatment plan and a Statement of Applicability?

    Good looks like

    A Statement of Applicability that records which of the 38 Annex A controls you apply, and justifies any you exclude.

  4. 11

    Do you carry out an AI system impact assessment on people, groups and society?

    Good looks like

    A documented impact assessment process, completed for your higher-risk systems, covering bias, fairness and data protection.

    A.5
  5. 12

    Have you set measurable AI objectives with owners and timelines?

    Good looks like

    Objectives that flow from your policy, each with a metric, an owner and a target date.

Step 4 · Part 3 of 5 · Clauses 7 and 8 · 7 questions

Score support and operation.

Support is the resourcing and knowledge behind the system. Operation is the system running day to day across the AI lifecycle and the data that feeds it.

Score these questions even if you only use vendor AI. The standard's scope includes organisations that use or manage third-party AI.

  1. 13

    Have you allocated the resources your AI work needs: people, budget, data and compute?

    Good looks like

    A record of the resources committed to building and running AI responsibly.

    A.4
  2. 14

    Are the people working on AI competent, with training records to show it?

    Good looks like

    A competence framework and training logs covering AI risk, ethics and security for the relevant roles.

  3. 15

    Do staff understand the AI policy, and do you communicate AI matters internally and externally?

    Good looks like

    An awareness programme plus defined channels for communicating AI risks and decisions.

  4. 16

    Is your documented information controlled, with versioning, retention and access rules?

    Good looks like

    Documents under version control with clear ownership.

  5. 17

    Do you manage AI across its full lifecycle, from design through to retirement?

    Good looks like

    Lifecycle controls for requirements, design, testing, deployment, operation and decommissioning.

    A.6
  6. 18

    Do you govern the data used to train and test your AI: provenance, quality and preparation?

    Good looks like

    Documented data sources, quality checks and bias handling for training and test data.

    A.7
  7. 19

    Are there operating procedures that keep AI use to its intended purpose?

    Good looks like

    Responsible-use procedures and change management for models, datasets and prompts.

    A.9

Step 5 · Part 4 of 5 · Annex A · 9 groups, cross-check only

Cross-check the 38 controls by group.

Annex A holds 38 controls in nine groups, numbered A.2 to A.10. Mark each group yes, partial or no at a glance. These rows do not add to the score. They show which groups to drill into when you write the Statement of Applicability, which must account for every group.

A low score on question 1 pulls A.4 down here too, because A.4 is where the inventory lives. Drill into low groups with the full control-by-control guide.

A.2
Policies for AI
An AI policy exists, aligns with your other policies, and is reviewed.
A.3
Internal organisation
Roles, responsibilities, and a route for reporting AI concerns.
A.4
Resources for AI systems
Data, tooling, compute and human resources are documented.
A.5
Assessing impacts
A process to assess AI impact on individuals, groups and society.
A.6
AI system life cycle
Responsible design and development across the whole lifecycle.
A.7
Data for AI systems
Acquisition, quality, provenance and preparation of data.
A.8
Information for interested parties
Transparency and documentation for users and affected people.
A.9
Use of AI systems
Responsible, intended use with operating procedures.
A.10
Third-party relationships
Responsibilities split clearly with suppliers and customers.

Annex A starts at A.2 because A.1 is the general clause that introduces the controls. The standard also ships Annex B, with implementation guidance for each control, and Annex C, a starting list of AI objectives and risk sources you can borrow when you plan.

Step 6 · Part 5 of 5 · Clauses 9 and 10 · 7 questions

Score monitoring and improvement.

These questions show whether the management system runs or only exists on paper. Most first attempts have the policy and the risk register but cannot show monitoring, internal audit and management review happening.

Score each one on records with dates. An internal audit programme with no completed report scores 1 on question 24.

  1. 20

    Do you tell users and affected people when AI is involved, and what it can and cannot do?

    Good looks like

    Clear information on intended use, limitations and AI-generated content for the people affected.

    A.8
  2. 21

    Do you manage AI risk across your suppliers and the parties you supply?

    Good looks like

    Responsibilities split clearly in contracts, with controls on third-party and customer-facing AI.

    A.10
  3. 22

    Do you monitor, measure and log how your AI is performing and behaving?

    Good looks like

    Defined metrics and logging for AI performance and governance, reviewed on a schedule.

  4. 23

    Is there a way to handle AI incidents when something goes wrong?

    Good looks like

    An incident and escalation procedure that covers AI failures as well as IT outages.

  5. 24

    Do you run internal audits of your AI management system?

    Good looks like

    A planned internal audit programme with reports that someone acts on.

  6. 25

    Does leadership formally review the AI management system on a regular basis?

    Good looks like

    Management review meetings with minutes, decisions and follow-up actions.

  7. 26

    When you find a problem, do you record it and fix the root cause?

    Good looks like

    Nonconformity and corrective-action records showing the issue, the cause and the fix.

Step 7

Add up your score and read your band.

26 questions, 2 for yes, 1 for partial, 0 for no. Maximum 52. The Annex A groups in Part 4 do not count.

Only an accredited certification body can certify you, whatever your score. The band tells you whether calling one is worth your time yet.

0 to 17

Early

AI is in use but largely ungoverned. The priority is the basics: a complete AI inventory, an approved policy and named owners. Start with Part 1, and plan on 9 to 12 months to reach stage 2.

18 to 35

Developing

The pieces exist but are uneven and lightly documented. You have a policy and some risk work, but impact assessments, monitoring and internal audit are thin. A focused gap-closure programme of 4 to 6 months is the next step.

36 to 52

Audit-ready

A real management system is running. The remaining work is evidence: making sure monitoring, internal audit and management review are documented and repeatable. A stage 1 readiness audit is a sensible next step. Once the remaining gaps are closed, plan on stage 1 within 1 to 2 months.

Step 8 · Regulator pre-check · yes or no

Run the regulator pre-check.

No law in Australia or New Zealand requires ISO 42001. Regulators and buyers already expect parts of it.

Answer yes or no for the column that applies to you. These rows are not scored.

Australia · APRA letter, Voluntary AI Safety Standard

  • An AI inventory exists and includes AI features inside SaaS products.
  • The AI supply chain is mapped to fourth parties, including the foundation-model provider behind each vendor.
  • Model drift is monitored against thresholds with a named owner.
  • Exit options for material AI suppliers have been written and tested.
  • Staff who use enterprise AI tools have been trained on use, misuse and limitations.
  • Each of the ten Voluntary AI Safety Standard guardrails has a named control or a written reason it does not apply.

New Zealand · Privacy Commissioner, MBIE guidance

  • A privacy impact assessment has been completed before any AI tool that uses personal information went live.
  • Māori data and te ao Māori considerations are documented in the impact assessment for systems that touch Māori data.
  • AI procurement includes an AI risk assessment, in line with the MBIE Responsible AI Guidance procurement checklist.
  • Hosting location and data residency are recorded for each system, for public-sector tenders.

Step 9

Put the gaps in order.

List every question that scored 0 or 1, then sort the list using the order on the right. Give each line an owner and a target date. That list is your gap-closure plan.

A Developing score of 24 with a partial on question 1 and zeros on questions 24 and 25 puts the inventory first and the internal audit programme second.

  1. 01

    Question 1, the AI inventory.

    Every other answer depends on knowing what you run, and the scope statement in question 2 is drawn from it.

  2. 02

    Any no on the regulator pre-check that applies to you.

    A supervisor or tender panel finds these before an auditor does, whether or not you ever certify.

  3. 03

    Low scores in Part 5, questions 20 to 26.

    Monitoring, internal audit and management review are the records surveillance audits sample in years one and two after certification.

  4. 04

    Question 11, the impact assessment.

    The impact assessment is what separates ISO 42001 from an information security standard, so a security review alone leaves this question open. ISO/IEC 42005:2025 describes the method.

  5. 05

    Every remaining zero, then every remaining partial.

    Work through them in part order, starting with Part 1.

Step 10 · If you scored 36 or more

Choose the certification body and book stage 1.

ISO does not certify anyone. Accredited certification bodies do. Choose a body that is JAS-ANZ accredited for ISO/IEC 42001 and check it on the JAS-ANZ register before you sign.

Before you choose a certification body

  • The body is accredited for ISO/IEC 42001 specifically, in addition to any ISO 27001 or ISO 9001 accreditation.
  • The body did not design or implement your management system. Accredited bodies keep consulting and certification separate.
  • If you already hold ISO 27001, the body can audit both standards together on the shared Annex SL clauses.
  • The sample certificate they show carries an accreditation mark and number that match the register entry.

Gap analysis. You are here.

Compare your current state against the standard, using a checklist like this one, and build a plan to close what is missing. Allow 2 to 4 weeks for it. No clause requires a gap analysis. It is how clause 6.1.3 and the Statement of Applicability get produced in practice.

Stage 1 audit

The certification body spends 1 to 2 days, on site or remote, reviewing your documented information: scope, policy, risk and impact assessment methods, Statement of Applicability, and evidence that internal audit and management review have run. It reports areas of concern, and stage 2 follows 4 to 8 weeks later so you can resolve them.

Stage 2 audit

The auditor checks that the controls are implemented and working, through interviews, observation and sampling of records. Plan on 2 to 5 days, depending on scope. Nonconformities are raised and closed. The certificate is issued on the certification decision.

Surveillance, years one and two

Lighter audits of 1 to 2 days each year confirm the system keeps running and improving. Monitoring, internal audit and management review records are what they sample.

Recertification, end of year three

A full re-audit renews the certificate for a new three-year cycle.

Questions about readiness and the audit.

Is a gap analysis mandatory under ISO 42001?

No clause requires one. In practice it is how clause 6.1.3 and the Statement of Applicability get produced, so every certification programme runs one first.

What happens at a stage 1 audit?

The certification body reviews your documented information: scope, AI policy, risk and impact assessment methods, Statement of Applicability, and evidence of internal audit and management review. It reports areas of concern, which must be resolved before stage 2.

How long is an ISO 42001 certificate valid?

Three years, with surveillance audits at least annually in years one and two, then a full recertification audit at the end of year three.

Are all 38 Annex A controls mandatory?

No. Each control is considered under clause 6.1.3 and included or excluded with a written justification in the Statement of Applicability.

Can we reuse our ISO 27001 documents?

Partly. ISO 42001 shares the Annex SL structure, so clauses 4, 5, 7, 9 and 10 overlap with ISO 27001. The AI risk assessment, AI system impact assessment and lifecycle controls are new and need their own documents.

Stuck on the gaps you just found?

PolyGovern runs a structured ISO 42001 gap assessment for Australian and New Zealand organisations: a clear read of where you stand against every clause and control, and a prioritised plan to reach stage 1.

Download · PDF · 9 pages

The checklist as a scorable PDF.

All 26 questions with tick boxes, the Annex A cross-check, the score sheet and the certification path, for working through with your team.

Thirty-minute call

ISO 42001 gap assessment.

A senior consultant walks through your score live against what a stage 1 auditor will ask for.

Download the checklist

Tell us who you are and the PDF will download straight away.

By submitting you consent to PolyGovern contacting you about the checklist. No spam; unsubscribe any time.

Get in Touch