C L A R E N T   3 6 0

Loading

ISO/IEC 42001:2023 Self-Assessment

Evaluate your organization's AI governance maturity against international requirements, identify operational gaps, and establish a robust Artificial Intelligence Management System (AIMS).

Introducing ISO/IEC 42001:2023 – Artificial Intelligence Management System

Globally recognized best practice, ISO/IEC 42001:2023 provides organizations with a structured framework to establish, implement, maintain, and continually improve an Artificial Intelligence Management System (AIMS). The standard helps organizations govern AI responsibly, ensuring transparency, accountability, security, ethics, and compliance throughout the AI lifecycle. It supports organizations in managing AI-related risks while enabling innovation and operational efficiency.

The benefits of certification

Independent certification demonstrates your organization’s commitment to responsible and trustworthy AI practices.

By achieving third-party assurance that your Artificial Intelligence Management System meets the requirements of ISO/IEC 42001:2023, organizations can build confidence among customers, regulators, investors, and stakeholders while demonstrating strong governance over AI technologies and processes.

ISO 42001 Artificial Intelligence Management System GRC

Why organizations require ISO 42001?

Organizations adopt ISO/IEC 42001:2023 to establish a systematic and internationally recognized approach for governing artificial intelligence systems responsibly. As AI technologies become increasingly integrated into business operations, decision-making, automation, analytics, and customer engagement, organizations must ensure AI systems are secure, ethical, transparent, and aligned with legal and regulatory expectations.

Risk Management

A primary reason for implementing ISO 42001 is risk management. The standard enables organizations to identify, assess, and manage risks associated with AI systems, including bias, lack of transparency, privacy concerns, cybersecurity threats, inaccurate outputs, and unintended consequences. Rather than responding reactively to AI-related incidents, organizations establish proactive governance and control mechanisms to maintain trust and accountability.

Legal & Regulatory Compliance

ISO 42001 also supports legal, regulatory, and contractual compliance. Governments and regulators worldwide are introducing AI governance and privacy requirements to ensure responsible AI use. Certification provides evidence that organizations have implemented appropriate controls, monitoring mechanisms, human oversight, and governance structures to address compliance obligations and stakeholder expectations.

Trust & Competitive Advantage

Certification reassures customers, partners, and stakeholders that AI technologies are managed responsibly and ethically. Organizations can demonstrate transparency in AI decision-making, improve confidence in automated systems, and strengthen their reputation in the marketplace. Many industries and government sectors are increasingly requiring demonstrable AI governance capabilities as part of procurement and partnership requirements.

Strengthened Organizational Governance

The standard strengthens organizational governance by defining AI-related roles, responsibilities, policies, risk assessment processes, performance evaluation methods, and continual improvement practices. AI governance becomes an enterprise-wide responsibility rather than solely a technical or development function.

Ethical AI & Responsible Innovation

ISO 42001 further promotes transparency, fairness, accountability, human oversight, and ethical use of artificial intelligence technologies. It supports organizations in aligning innovation with responsible business practices while reducing operational, legal, reputational, and societal risks associated with AI adoption.

Where is your organization on the path to responsible AI maturity?

Increasing adoption of artificial intelligence technologies across industries is driving the need for stronger AI governance, accountability, and risk management practices. Organizations are now expected to ensure that AI systems operate safely, ethically, transparently, and in alignment with organizational objectives and societal expectations.

With a mature and certified Artificial Intelligence Management System (AIMS) in place, organizations can manage AI risks effectively while unlocking innovation, operational efficiency, and strategic growth opportunities. This includes building stakeholder trust, supporting compliance, improving decision-making, enabling responsible automation, and demonstrating leadership in trustworthy AI practices regardless of industry or region.

How the self-assessment work?

By filling in the checklist on the next few pages you can gauge what stage of maturity your AI Management System (AIMS) is currently at in relation to the main requirements of ISO/IEC 42001:2023, and what actions you can take next. No matter where you are in your AI governance journey, our range of solutions can help you move forward.

Please fill in the checklist below, each ‘YES’ counts as one point towards your final score and subsequent maturity range.

Clause 4 - Context of the Organization
0 / 4 Completed
1. Internal & External Factors (4.1)

Has the organization identified and evaluated the internal and external factors – including legal, regulatory, ethical, societal, and technological considerations – that are relevant to the development, provision, or use of AI systems and that may influence the AIMS?

2. Interested Parties' Needs (4.2)

Has the organization determined the needs and expectations of relevant interested parties (such as employees, customers, regulators, and affected communities) in relation to AI governance, and identified which of those requirements are applicable to the AIMS?

3. Scope of AIMS (4.3)

Has the organization clearly defined the scope of its AI Management System, specifying which AI systems, organizational units, locations, functions, and processes are included, and documented this scope in a formally maintained statement?

4. AIMS Processes & Ownership (4.4)

Has the organization defined and implemented the processes, roles, responsibilities, and continual improvement mechanisms necessary to establish, implement, maintain, and continually improve the AIMS in accordance with ISO/IEC 42001:2023?

Clause 5 - Leadership
0 / 4 Completed
5. Leadership & Commitment (5.1)

Has top management demonstrated active commitment to the AI Management System by integrating AI governance into the organization’s strategic direction, ensuring adequate resources, and championing a responsible AI culture across all relevant functions?

6. AI Policy (5.2)

Has the organization established a documented AI policy that states its objectives and commitment to responsible AI, aligns with the organization’s purpose and strategic context, and has been communicated to all personnel and relevant stakeholders?

7. Roles, Responsibilities & Authorities (5.3)

Have roles, responsibilities, and authorities for AI governance been clearly defined, assigned, and communicated, including accountability for ensuring the AIMS conforms to ISO/IEC 42001:2023 requirements and for reporting AIMS performance to top management?

8. Operational Awareness & Leadership (5.3)

Has leadership ensured that AI objectives and responsible AI principles are understood and applied at the operational level, and that personnel are aware of how their roles contribute to the effectiveness of the AIMS and to ethical AI outcomes?

Clause 6 - Planning
0 / 5 Completed
9. Risks and Opportunities (6.1)

Has the organization identified the risks and opportunities associated with its AI systems – including risks to fairness, transparency, safety, privacy, and security – and determined actions to address them in a manner proportionate to their potential impact?

10. AI Risk Assessment Methodology (6.1.2)

Has the organization established and implemented a defined methodology for AI risk assessment that includes criteria for evaluating the likelihood and severity of harm, covers the full AI system lifecycle, and produces consistent and reproducible results?

11. AI Impact Assessments (6.1.3)

Has the organization conducted AI impact assessments for its AI systems, and are the outcomes of these assessments used to inform risk treatment decisions, design choices, and operational controls?

12. Risk Treatment & Controls (6.1.4)

Have risk treatment options been selected and applied for AI-related risks, including the identification and implementation of appropriate controls from ISO/IEC 42001 Annex A, and has a Statement of Applicability been documented to justify the inclusion or exclusion of applicable controls?

13. AI Management Objectives (6.2)

Have measurable AI management objectives been established, documented, and communicated across the organization, with defined plans specifying what will be done, who is responsible, the resources required, timelines, and how results will be evaluated?

Clause 7 - Support
0 / 4 Completed
14. Resources Allocation (7.1)

Has the organization determined and provided the resources – including personnel, infrastructure, technology, data, and financial resources – needed to establish, implement, maintain, and continually improve the AIMS, including resources specific to responsible AI development and governance?

15. Competency & Development (7.2)

Are individuals performing AI-related roles – including AI development, deployment, procurement, and oversight functions – competent on the basis of appropriate education, training, or experience, and are competency gaps identified and addressed through targeted development actions?

16. Awareness of AI Policy & Principles (7.3)

Are personnel and relevant stakeholders made aware of the AI policy, AI objectives, the ethical principles underpinning the organization’s AI approach, their individual responsibilities in supporting the AIMS, and the potential consequences of non-conformance?

17. Communication & Documented Information (7.4 & 7.5)

Is documented information required by ISO/IEC 42001:2023 properly created, maintained, protected, distributed, and controlled, and are internal and external communication requirements for AI governance clearly defined, including the audience, content, timing, and channels?

Clause 8 - Operation
0 / 5 Completed
18. Operational Planning & Controls (8.1)

Has the organization planned, implemented, and controlled the processes needed to meet AI management requirements and deliver on its AI objectives, ensuring that these processes are executed as planned and that documented evidence of operational activities is maintained?

19. AI System Lifecycle Management (8.2)

Does the organization manage the full AI system lifecycle – from requirements definition and data acquisition through to development, testing, deployment, monitoring, and decommissioning – with defined controls applied at each stage to ensure responsible and ethical outcomes?

20. Control of AI Changes (8.2)

When changes to AI systems, their operational context, or the data they rely upon are planned, are these changes assessed, reviewed, and controlled to identify and mitigate any new or changed risks prior to implementation?

21. Third-Party AI Suppliers & Partners (8.3)

Are third-party AI suppliers, partners, and providers of AI-related products or services subject to defined governance requirements, including contractual obligations relating to responsible AI, transparency, data handling, and conformance with the organization’s AI policy and applicable controls?

22. Risk Treatment Plan Implementation (8.4)

Are AI risk treatment plans actively implemented and monitored, are residual risks formally accepted by authorized personnel, and are periodic AI risk assessments conducted with documented records maintained to demonstrate accountability and enable management review?

Clause 9 - Performance Evaluation
0 / 5 Completed
23. Monitoring, Measurement & Analysis (9.1)

Has the organization determined what needs to be monitored and measured in relation to the AIMS and its AI systems, including the methods to be used, the frequency of monitoring, who is responsible, and how results are documented, analyzed, and acted upon?

24. Operational Behavior & Incident Monitoring (9.1)

Are AI system performance and behavior monitored in operation to detect unintended outputs, model drift, fairness degradation, or safety incidents, and are monitoring results used to trigger corrective actions and feed into AIMS improvement activities?

25. AIMS Internal Audits (9.2)

Are internal audits of the AIMS conducted at planned intervals by competent and impartial auditors, with audit scope, criteria, findings, and corrective actions properly documented and reported to top management?

26. Management Reviews (9.3)

Does top management conduct periodic management reviews of the AIMS, taking into account audit results, performance data, changes in context, stakeholder feedback, and progress against AI objectives, and are review outcomes documented with decisions and actions clearly recorded?

27. Nonconformities & Remediation (9.4)

Is a formal process in place to identify, record, and manage nonconformities and issues detected through monitoring or audit activities, and are corrective actions taken, root causes investigated, and effectiveness of remediation verified and documented?

Clause 10 - Improvement
0 / 3 Completed
28. Incident Investigation & Root Cause (10.1)

When a nonconformity or AI-related incident occurs, does the organization take prompt corrective action, investigate and address the root cause to prevent recurrence, verify the effectiveness of the corrective action taken, and retain documented evidence of the investigation and outcome?

29. Improvement Actions Tracking (10.2)

Does the organization identify opportunities to improve the suitability, adequacy, and effectiveness of the AIMS on an ongoing basis, and are improvement actions prioritized, planned, and tracked through to completion?

30. AIMS Continual Improvement (10.3)

Is the AIMS subject to continual improvement informed by performance evaluation outcomes, lessons learned from AI incidents, changes in the external AI regulatory and ethical landscape, and evolving stakeholder expectations, so that the organization’s AI governance practices advance over time?

0 / 30 Points Foundational
Foundational
0 - 10 Points

Initial Stage

Developing
11 - 20 Points

Defined Program

Optimized
21 - 30 Points

Audit Ready

Action Recommended: Explore AI Governance & Responsible AI Training

Your organization is at an early stage of AI management maturity. AI governance practices may be informal, undocumented, or inconsistently applied.

We recommend exploring AI management and responsible AI courses and qualifications for key personnel to build internal capability. Establishing a formal AI policy, assigning AI governance ownership, and conducting an initial AI risk assessment would be valuable first steps on your ISO/IEC 42001:2023 journey.

Action Recommended: Schedule Structured AIMS Gap Assessment

Your organization has established some AI governance practices but notable gaps remain.

A structured Gap Assessment from our specialists would help identify where your AIMS falls short of ISO/IEC 42001:2023 requirements. Our experts can benchmark your current practices against the standard, assess your AI impact assessment processes, and provide a prioritized roadmap to strengthen your AI governance framework and progress toward full conformance.

Congratulations: Ready for ISO/IEC 42001:2023 Certification!

Your organization demonstrates strong AI management maturity and is well aligned with the requirements of ISO/IEC 42001:2023.

At this level, the focus should shift to continual improvement, advancing responsible AI culture, and leveraging AIMS performance data to drive ethical AI outcomes. Our team can support you with advanced AI governance optimization, independent conformance assessments, and preparation for ISO/IEC 42001:2023 certification.

Next Steps

Regardless of your current maturity level, ISO/IEC 42001:2023 is a journey of continual improvement. The following actions are recommended based on your assessment outcomes:

  • Establish or formalize an AI policy that articulates your organization’s commitment to responsible, transparent, and ethical AI.

  • Define and document the scope of your AIMS, including which AI systems, functions, and processes are in scope.

  • Conduct an AI impact assessment for each material AI system to understand potential harms to individuals and society.

  • Assign clear AI governance ownership at both the executive and operational levels, with defined reporting lines.

  • Review your existing AI system documentation and controls against ISO/IEC 42001 Annex A and prepare a Statement of Applicability.

  • Schedule periodic AIMS management reviews aligned with your strategic planning and AI portfolio review cycles.

  • Consider engaging an independent expert to conduct a formal ISO/IEC 42001:2023 Gap Assessment or readiness review.

Ready to take the next step in your AI Governance journey?

For further information on how to strengthen your AI Management System, or to explore assessment, training, and advisory services aligned to ISO/IEC 42001:2023, please contact our team.

ISO/IEC 42001:2023 Official Standard

Access the official ISO publication directory to review standard requirements, AI governance guidelines, and AIMS implementation specifications.

Visit ISO Directory

Reset Assessment?

This will clear all 30 self-assessment checklist selections and reset your AIMS maturity score. This action cannot be undone.