ISO 42001 Checklist: 45 checks for AI governance, data, AI security and autonomous agents
45 checks to ISO/IEC 42001:2023 — provenance on every item: clause, Annex A, separate law or recognised practice. Free PDF, no sign-up, English and German.
Published on September 20, 2026
ISO 42001 Checklist: 45 checks for AI governance, data, AI security and autonomous agents
ISO/IEC 42001 is voluntary — no deadline, no authority, no sanction — and still the only standard that describes an AI management system as a whole.
This checklist takes 45 items from our working catalogue and says, on each one, what it rests on: the standard, Annex A, separate law, or recognised practice. PDF, English and German, no sign-up and no e-mail address.
”We have an AI policy”
The sentence comes early in almost every conversation, and it is usually true. Two pages, on the intranet, signed by the board. The next question is the uncomfortable one: how many AI systems do you run?
The answer is rarely a number. It is a list that grows while you are still in the room: the assistant that came bundled with the office licences. The chatbot in support. A scoring model a department bought two years ago. And the three agents somebody wired together over a weekend because it helped — those appear on no list, because they never went through procurement.
A policy that does not say which systems it covers is not governance. It is a statement of intent. That gap is exactly where ISO/IEC 42001 begins — and exactly where it stops again.
What ISO/IEC 42001 is — and what it is not
ISO/IEC 42001:2023 is the first management-system standard for artificial intelligence. It is built like ISO/IEC 27001 or ISO 9001: clauses 4 to 10 describe the management system — context, leadership, planning, support, operation, evaluation, improvement — and an Annex A carries the controls, 38 of them, grouped into nine objectives from A.2 to A.10.
ISO/IEC 42001 is voluntary. It sets no deadline, it names no supervisory authority, it carries no sanction. The clauses become binding only at the moment an organisation decides to be certified. Any sentence of the form “ISO 42001 requires this by date X” is wrong — the thing with deadlines is the AI Act, not this standard.
That is not a defect but the purpose of a management-system standard: it describes the structure, not the state of the art. Which is why what is missing afterwards is precisely what turns structure into a working system — the concrete assessment question, and an honest account of where it actually comes from.
Four layers, visible on every item
Most AI checklists in circulation mix four entirely different things: what the standard says, what is an Annex A control, what applies regardless of any standard, and what somebody considers a good idea. Mix those, and you can no longer explain to a board what happens if you delete an item.
So in this list every item carries its provenance on the item itself — not in a footnote:
| Layer | Meaning | Items |
|---|---|---|
| N — clause | Sits in clauses 4–10. Binding only for those seeking certification. | 10 |
| A — Annex A | An Annex A control. Whether it applies is decided and justified by the organisation in the Statement of Applicability. | 16 |
| R — separate law | GDPR or the AI Act. Applies regardless of ISO 42001; the standard neither creates these duties nor removes them. | 2 |
| H — recognised practice | State of the art, not in the standard. Delete these and you breach nothing. | 17 |
That 17 of 45 items carry layer H is not a weakness of the list — it is its actual content. A checklist that only transcribes the standard has nothing to say about AI security or autonomous agents. One that passes practice off as a requirement loses its credibility in the first audit. The only usable answer is to show both, and to write down which is which.
What is in the checklist
Seven sections, in the order you actually work through them on a project — frame first, then risk, then data, then the technology, then the chain, then the people.
| Section | Content | Items |
|---|---|---|
| A — The AI management system | Scope, policy, roles, inventory, shadow AI, internal audit | 7 |
| B — Risk and impact assessment | Risk criteria, assessment method, Annex A reconciliation, Statement of Applicability, impact on those affected, re-assessment triggers | 6 |
| C — Data and data provenance | Data quality, collection and rights, provenance, preparation, labelling pipelines, memorisation, data-subject rights, retention | 8 |
| D — AI security: model, chain, guardrails | Purpose definition, change approval, model registry, ML-BOM, signed weights, prompt injection, untrusted content, guardrail layer | 8 |
| E — Autonomous agents | Least privilege, human approval for irreversible actions, quotas and circuit breakers, sandboxing, output handling, human oversight | 6 |
| F — Supply chain and third parties | Procurement process, foundation models, subprocessors, terms of use, allocation of responsibility | 5 |
| G — Transparency, people and operation | Disclosure to users, external communication, complaints route, reporting channel, ongoing monitoring | 5 |
The part management-system checklists skip
Fourteen of the 45 items — sections D and E — appear in no standard in this form. They appear in incident reports.
Annex A of ISO/IEC 42001 has controls for the life cycle, for data, for information to interested parties and for third parties. It has no control headed “prompt injection”, none for model provenance, and none for the question of what an agent may do without asking first. That is no criticism of the standard — it is from 2023 and describes a management system, not a threat model. For an organisation putting agents into production today, the gap is real nonetheless.
What those fourteen items say comes down to one sentence: treat every model output and every retrieved piece of content as untrusted, and let no consequential action run without a human in between. Concretely: input from RAG, tools, the web, files and e-mail is isolated and labelled so that it cannot be read as an instruction. Model weights are signed, and unsigned artefacts fail at the deployment gate. Agents work from allow-lists, not from a general mandate. Payments, deletions, external communication and deployments need a human release. And each of these items carries an H in the list — because that is honest, and because it lets you decide for yourself which of them you need.
ISO 42001 and the AI Act: two rulebooks, one operation
The two get conflated constantly, and it backfires in both directions: organisations treat the standard as a legal duty, or they treat a certificate as evidence of conformity under the AI Act. Neither is true.
Regulation (EU) 2024/1689 applies whether or not you run a management system. An ISO 42001 certificate replaces neither the classification of your systems, nor the conformity assessment, nor any of the obligations under the regulation. Conversely, the regulation takes nothing away from the standard. In this checklist the AI Act therefore appears at only two points where it genuinely applies — human oversight (Art. 14) and disclosure to users (Art. 50) — and always as a separate anchor beside the standard reference, never merged into it.
In practice: do the classification under the regulation first, because it tells you what applies. Build the management system afterwards, because it tells you how to keep it running. Do it the other way round and you build a structure around obligations you have not yet identified.
Three rules we hold ourselves to
- Provenance sits on every item. Standard, Annex A, separate law or practice — on the item, not in a footnote. Delete an H item and you breach nothing. You should be able to see that without having to ask.
- The standard’s text is not reprinted. No wording of ISO/IEC 42001 is reproduced verbatim. Control numbers and clause references are citations; every assessment question is our own formulation. The standard itself you buy from ISO or your national standards body.
- The status is dated. Edition ISO/IEC 42001:2023. AI Act references are as at 20 September 2026 — and appear only where they actually apply.
The two editions
| Edition | Size | File |
|---|---|---|
| English | 15 pages · 170 KB | cws-iso-42001-checklist-45-en-v1.0.pdf |
| Deutsch | 15 pages · 184 KB | cws-iso-42001-checkliste-45-de-v1.0.pdf |
Download the ISO 42001 Checklist as PDF
Free, no registration, no e-mail address · PDF, 15 pages · Version 1.0 of 20 September 2026
Both editions carry the same content, the same numbering and the same layer marks. Item 12 is item 12 in either language.
What next?
AIGovernance_Suite_ — These 45 items are the public cut of the working catalogue. The tool holds the full catalogue: every control with its assessment question, applicability decision, justification, implementation status and owner, across several AI systems at once. What comes out at the end is not a table but a Statement of Applicability you can hand over. Go to CyberWerkSuite →
CWS Consultancy · AI Governance — Where you stand, measured against your real AI systems, then the order of work: what comes first, what can wait, what is legal duty anyway. Then the building — policy, roles, inventory, impact assessment, Annex A reconciliation, guardrails and agent rules — and at the end the evidence: Statement of Applicability, internal audit, management review. With or without an intention to certify. Book an intro call →
Frequently asked questions
Is ISO/IEC 42001 mandatory?
No. The standard is voluntary: no deadline, no supervisory authority, no sanction. Clauses 4–10 become binding only when an organisation seeks certification. Deadlines and sanctions belong to Regulation (EU) 2024/1689, not to this standard.
Does an ISO 42001 certificate satisfy the AI Act?
No. The regulation applies whether or not you run a management system. A certificate replaces neither the classification of your systems, nor the conformity assessment, nor any obligation under the regulation. A well-built management system does make the evidence considerably cheaper to produce.
Does the PDF contain text from the standard?
No. Control numbers, clause numbers and clause references are cited as locations; every assessment question is a CyberWerkSuite formulation. For the text of the standard you need your own copy of ISO/IEC 42001:2023.
Why are 17 of the 45 items not requirements?
Because that is what they are. Annex A of ISO/IEC 42001 has no control for prompt injection, none for model provenance and none for the authority of autonomous agents. Those items therefore carry layer H — recognised practice. Delete them and you breach nothing; ignore them and you read about them in an incident report.
Who is the list for?
For organisations already using AI — not only for those pursuing certification. Sections A to C are for the management system, D and E for operations, F and G for external relationships. You can start at any section.
May I share the PDF?
Yes, unchanged and with attribution. For extracts, rewordings or inclusion in your own material, please ask first.
© 2026 CyberWerkSuite · Dr. Sait Yalazay. Redistribution permitted unchanged and with attribution.