Assess implementation
Rate each management-system control from not in place to implemented and effective.
Evaluate how prepared your organisation is to establish, operate, review, and improve an AI management system aligned to ISO/IEC 42001. The assessment highlights clause-oriented gaps, weak evidence, and practical implementation priorities.
Complete the assessment using the current state of your organisation, not the intended future state.
Rate each management-system control from not in place to implemented and effective.
Indicate whether supporting evidence is absent, informal, documented, or verified.
Review readiness by topic, major gaps, evidence needs, and an implementation sequence.
Questions are grouped around management-system themes and related AI controls without reproducing the copyrighted wording of ISO/IEC 42001.
The assessment combines implementation maturity with evidence strength so that undocumented claims do not receive the same weight as verified controls.
Each applicable control is scored from 0 to 100 for implementation and multiplied by an evidence factor from 0.45 to 1.00. The overall result is the mean of adjusted scores.
The questionnaire is selective and does not reproduce or replace ISO/IEC 42001. It cannot determine legal compliance, certification eligibility, or control effectiveness without independent evidence review.
Use low-scoring items to build a corrective roadmap, identify evidence owners, prepare internal audit sampling, and sequence implementation around material AI risks and business priorities.
No. It is a readiness self-assessment and cannot issue, guarantee, or imply certification or conformity.
A licensed copy of the applicable standard is important for formal implementation and audit preparation. This tool does not reproduce the standard text.
Mark an item not applicable only when it is genuinely outside the defined AI management-system scope and the exclusion can be justified without undermining intended outcomes.
Management systems depend on demonstrable implementation. Weak or absent evidence reduces confidence that a stated control is repeatable and effective.
Examples include approved records, sampled logs, completed reviews, test results, audit trails, meeting decisions, corrective-action verification, and other evidence checked for accuracy and currency.
There is no universal threshold. Internal audit can begin earlier, but lower scores usually indicate that auditors will find more design and implementation gaps.
Yes, provided the scope, interfaces, dependencies, interested parties, risks, suppliers, and governance arrangements are clearly defined.
Repeat it after material AI changes, incidents, major supplier changes, significant corrective actions, management review, or at planned intervals.
No. Applicable legal, regulatory, contractual, privacy, employment, sector, and consumer obligations require separate competent review.
Planned evidence should not be rated as documented or verified. Score the current state and use the result to prioritise evidence creation.
Assign owners and due dates, assess risk and business impact, define acceptance criteria, implement controls, retain evidence, and verify effectiveness before closure.
The page does not use external APIs. Server submission is required for the non-JavaScript calculation, while CSV and JSON exports are generated locally in the browser.