Evidence-aware readiness assessment

ISO/IEC 42001 readiness checker

Evaluate how prepared your organisation is to establish, operate, review, and improve an AI management system aligned to ISO/IEC 42001. The assessment highlights clause-oriented gaps, weak evidence, and practical implementation priorities.

This tool does not certify conformity.
It provides a structured readiness view based solely on the information you enter and does not replace the standard, legal advice, accredited certification, or an independent audit.

How it works

Complete the assessment using the current state of your organisation, not the intended future state.

1

Assess implementation

Rate each management-system control from not in place to implemented and effective.

2

Rate evidence strength

Indicate whether supporting evidence is absent, informal, documented, or verified.

3

Prioritise action

Review readiness by topic, major gaps, evidence needs, and an implementation sequence.

AI management-system readiness assessment

Questions are grouped around management-system themes and related AI controls without reproducing the copyrighted wording of ISO/IEC 42001.

Assessment progress0% complete
0%
Context of the AI management system
The intended scope, boundaries, AI systems, business units, and interfaces are defined.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Relevant interested parties, obligations, and expectations are identified and reviewed.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Leadership and governance
Executive accountability, decision rights, and oversight responsibilities are assigned.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

An approved AI policy sets commitments, principles, and governance expectations.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Planning and risk treatment
AI-related risks and opportunities are identified, assessed, treated, and tracked.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Measurable AI management objectives have owners, targets, and review dates.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Support, competence, and documentation
Required competence is defined and supported by training, experience, or specialist input.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Controlled documentation and records are current, approved, retrievable, and protected.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Operational controls and lifecycle
AI lifecycle controls cover design, data, testing, deployment, change, use, and retirement.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Human oversight, escalation, fallback, and intervention arrangements are defined and tested.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Impact assessment and responsible use
Impact assessments consider people, groups, customers, society, and foreseeable misuse.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Transparency, communication, explainability, and user information are proportionate to risk.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Supplier and third-party controls
AI suppliers and dependencies undergo risk-based due diligence before approval.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Contracts address responsibilities, changes, monitoring, incidents, data, and exit arrangements.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Monitoring and performance evaluation
Performance, risk, incidents, drift, controls, and objective progress are monitored.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Internal audit and management review are planned, independent, evidence-based, and acted upon.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Incident management and improvement
AI incidents and nonconformities are reported, contained, investigated, and corrected.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Corrective actions address root causes and feed continual improvement and governance updates.

Use “Not applicable” only with a defensible scope rationale.

Rate the current, repeatable state.

Evidence adjusts the implementation score.

Privacy: No assessment data is transmitted to external services. Basic submission and result generation occur on this server. Browser-based export files are generated locally. Any persistent storage would require a separate, deliberate secure implementation by the site owner.

Methodology, limitations, and practical use

The assessment combines implementation maturity with evidence strength so that undocumented claims do not receive the same weight as verified controls.

Methodology

Each applicable control is scored from 0 to 100 for implementation and multiplied by an evidence factor from 0.45 to 1.00. The overall result is the mean of adjusted scores.

Limitations

The questionnaire is selective and does not reproduce or replace ISO/IEC 42001. It cannot determine legal compliance, certification eligibility, or control effectiveness without independent evidence review.

Using the result

Use low-scoring items to build a corrective roadmap, identify evidence owners, prepare internal audit sampling, and sequence implementation around material AI risks and business priorities.

Frequently asked questions

Does this tool certify ISO/IEC 42001 conformity?

No. It is a readiness self-assessment and cannot issue, guarantee, or imply certification or conformity.

Do I need a copy of ISO/IEC 42001?

A licensed copy of the applicable standard is important for formal implementation and audit preparation. This tool does not reproduce the standard text.

How should I choose applicability?

Mark an item not applicable only when it is genuinely outside the defined AI management-system scope and the exclusion can be justified without undermining intended outcomes.

Why does evidence strength change the score?

Management systems depend on demonstrable implementation. Weak or absent evidence reduces confidence that a stated control is repeatable and effective.

What counts as verified evidence?

Examples include approved records, sampled logs, completed reviews, test results, audit trails, meeting decisions, corrective-action verification, and other evidence checked for accuracy and currency.

What score is needed before internal audit?

There is no universal threshold. Internal audit can begin earlier, but lower scores usually indicate that auditors will find more design and implementation gaps.

Can this assessment cover one AI system?

Yes, provided the scope, interfaces, dependencies, interested parties, risks, suppliers, and governance arrangements are clearly defined.

How often should the assessment be repeated?

Repeat it after material AI changes, incidents, major supplier changes, significant corrective actions, management review, or at planned intervals.

Does the tool assess legal compliance?

No. Applicable legal, regulatory, contractual, privacy, employment, sector, and consumer obligations require separate competent review.

Can evidence be planned rather than available?

Planned evidence should not be rated as documented or verified. Score the current state and use the result to prioritise evidence creation.

What should we do with major gaps?

Assign owners and due dates, assess risk and business impact, define acceptance criteria, implement controls, retain evidence, and verify effectiveness before closure.

Is the result stored or sent externally?

The page does not use external APIs. Server submission is required for the non-JavaScript calculation, while CSV and JSON exports are generated locally in the browser.