AIMS Checklist
AIMS Checklist
Checklist
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the world’s first international standard for
establishing, implementing, maintaining, and continually improving an
Artificial Intelligence Management System (AIMS). It provides a structured
governance framework that enables organizations to responsibly design,
develop, deploy, operate, monitor, and decommission AI systems across
their lifecycle. An AIMS integrates people, processes, and technology to
ensure AI systems remain:
- Trustworthy
- Transparent
- Fair
- Secure
- Compliant with legal, regulatory, and ethical obligations
>EU AI Act
>Data Protection and Privacy Laws (GDPR, DPDP Act)
>Industry AI governance requirements
>Builds stakeholder trust and enhances brand credibility
[Link] | 01
Format / Process for Achieving ISO/IEC 42001
Certification
1. Planning and Scope Definition
2. AIMS Implementation
3. Internal Audit
4. Management Review
6. Continual Improvement
[Link] | 02
Clause-Wise Checklist for AI Management System
(AIMS) Implementation
Clause 1: Scope
[Link] | 03
Clause 2: Normative References
[Link] | 04
Clause 4: Context of the Organization
[Link] | 05
4.2: Understanding the Needs and Expectations of Interested Parties
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
[Link] | 06
4.3: Determining the Scope of the AI Management System
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Has the organization formally Low /
Defined /
Establish AIMS framework established an AI Management Yes/No Medium /
Managed /
System aligned to ISO/IEC 42001? High
Optimized
[Link] | 07
Clause 5: Leadership
[Link] | 08
5.2: AI Policy
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Is a formally documented, Low /
Defined /
Establish AI policy approved, and version-controlled Yes/No Medium /
Managed /
AI Policy in place? High
Optimized
[Link] | 09
5.3: Roles, Responsibilities, and Authorities
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
[Link] | 10
Clause 6: Planning
6.1.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
[Link] | 11
6.1.2: AI Risk Assessment
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
[Link] | 12
6.1.3: AI Risk Treatment
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Are AI risk treatment options Low /
Defined /
Treatment strategy defined (mitigate, avoid, transfer, Yes/No Medium /
Managed /
accept)? High
Optimized
Is a Statement of Applicability
Statement of Applicability (SoA) developed and maintained
for AI controls?
Initial /
Is a formal AI System Impact Low /
Impact assessment Defined /
Assessment (AIIA/AI-IA) Yes/No Medium /
framework Managed /
framework established? High
Optimized
[Link] | 13
6.2: AI Objectives and Planning to Achieve Them
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Are measurable AI governance Low /
Defined /
Objective definition objectives established at relevant Yes/No Medium /
Managed /
levels? High
Optimized
Initial /
Are changes to AIMS and AI systems Low /
Defined /
Change governance planned, risk-assessed, approved, Yes/No Medium /
Managed /
and documented? High
Optimized
[Link] | 14
Clause 7: Support
7.1: Resources
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
7.2: Competence
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Is documented evidence of
Competence evidence competence maintained and
controlled?
[Link] | 15
7.3: Awareness
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Low /
Are personnel aware of the AI Defined /
Policy awareness Yes/No Medium /
Policy and AIMS objectives? Managed /
High
Optimized
7.4: Communication
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
[Link] | 16
7.5: Documented Information
7.5.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Are documents properly Low /
Defined /
Document control identified, versioned, reviewed, Yes/No Medium /
Managed /
and approved? High
Optimized
Initial /
Are documents protected from Low /
Defined /
Access control unauthorized access, alteration, Yes/No Medium /
Managed /
or loss? High
Optimized
[Link] | 17
Clause 8: Operation
Is documented information
available to demonstrate
Documentation availability
processes are carried out as
planned?
[Link] | 18
8.2: AI Risk Assessment (Operational Execution)
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Low /
Are AI risk assessments Defined /
Periodic risk reviews Yes/No Medium /
conducted at planned intervals? Managed /
High
Optimized
Initial /
Low /
Are risk treatment plans Defined /
Treatment execution Yes/No Medium /
implemented as approved? Managed /
High
Optimized
[Link] | 19
8.4: AI System Impact Assessment (Operational Execution)
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Low /
Are AI system impact assessments Defined /
Scheduled assessments Yes/No Medium /
conducted at planned intervals? Managed /
High
Optimized
[Link] | 20
Clause 9: Performance Evaluation
[Link] | 21
9.2: Internal Audit
9.2.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Has the organization established a Low /
Defined /
Audit framework formal AIMS internal audit Yes/No Medium /
Managed /
framework? High
Optimized
[Link] | 22
9.3: Management Review
9.3.1: General
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Does top management conduct Low /
Defined /
Review governance formal AIMS management reviews Yes/No Medium /
Managed /
at planned intervals? High
Optimized
Initial /
Low /
Are previous review actions Defined /
Action status Yes/No Medium /
tracked and reported for closure? Managed /
High
Optimized
Initial /
Low /
Are management decisions and Defined /
Decision recording Yes/No Medium /
action items documented? Managed /
High
Optimized
[Link] | 23
Clause 10: Improvement
Initial /
Has the organization established a Low /
Defined /
Improvement framework formal continual improvement Yes/No Medium /
Managed /
framework for the AIMS? High
Optimized
[Link] | 24
10.2: Nonconformity and Corrective Action
Control Audit Question / Implementation Maturity Risk Evidence Responsible Findings Corrective
Objective Verification Point Status Level Rating Required Owner Action
Initial /
Does the organization identify and Low /
Defined /
Nonconformity identification record AI governance or AIMS Yes/No Medium /
Managed /
nonconformities? High
Optimized
Is the effectiveness of
Corrective action effectiveness corrective actions verified after
implementation?
[Link] | 25