Free resource
Structured to ISO 42001's Annex A (38 controls, 9 groups). Covers the AI impact assessment (clauses 6.1.4 / 8.4) that sets 42001 apart from ISO 27001 - impact on third parties and society, not just risk to you.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A readiness check structured to ISO/IEC 42001's Annex A - 38 controls across 9 groups. It covers the control that sets 42001 apart from ISO 27001: the AI system impact assessment, which weighs impact on people and society, not just risk to you. |
| How to score | Yes = in place and you can show the evidence today. Partly = it exists but is incomplete, informal or unevidenced. No = not in place. Only a clear Yes counts when it is audited. |
| What carries over from an ISMS | If you already run ISO 27001, a lot of the organisational and data controls carry over. The genuinely new work is AI-specific: impact assessment, life-cycle governance, transparency and human oversight. |
| The #1 mistake | Reusing an infosec risk assessment as the AI impact assessment. They answer different questions - one protects the organisation, the other weighs harm to third parties and society. |
Sheet: AI Governance
Structured to ISO/IEC 42001's Annex A (38 controls across 9 groups). Score each item. The control that distinguishes 42001 from ISO 27001 is the AI system impact assessment (clauses 6.1.4 / 8.4): impact on third parties and society, not just risk to the organisation.
| Annex A group | Control area | What good looks like | Most common failure (the red flag) | Status (Yes / Partly / No) | Owner | Evidence / gap |
|---|---|---|---|---|---|---|
| Policies for AI | An AI policy setting the organisation's position and principles | A board-approved AI policy stating principles, scope and risk appetite | A policy copied from a vendor with no organisation-specific position | - | - | - |
| Internal organisation | Accountability for AI is assigned - each system has a named owner | Each AI system has a named owner and an accountable role | 'AI is everyone's job', so no one is accountable when it goes wrong | - | - | - |
| Internal organisation | A route to raise concerns about an AI system | A channel to flag an AI system behaving badly, used and recorded | No way for staff to raise that a model is producing harmful output | - | - | - |
| Resources for AI | Data, tooling, compute and competent people are accounted for | A documented inventory of the data, tools, compute and skills each system relies on | Nobody can say what data or model a given feature actually uses | - | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources