Guide

ISO 42001 readiness

An explainer on ISO/IEC 42001 readiness, what the standard asks for, how to judge how ready you are and where organisations most often fall short.

What is ISO 42001 readiness?

ISO/IEC 42001 readiness is how prepared your organisation is to be certified against the international standard for an AI management system. You judge it by working through what the standard asks for, the context and scope of your AI, the leadership and policy behind it, the risk and impact work, the controls, the documented information and the internal audit and management review, and finding where your practice already meets the standard and where it does not yet. Readiness is the distance between your current management system and the standard's requirements, and closing that distance is the work before certification. This explainer sets out what the standard asks and where organisations most often fall short, anchored to ISO/IEC 42001. It is written for the owner steering toward certification, the CRO, the chief audit executive or the governance lead.

What ISO/IEC 42001 asks for

ISO/IEC 42001 is a management-system standard, so it is less about any single AI system and more about the system of governance around all of them. It follows the same structure as other management-system standards, which means requirements for understanding your context, leadership commitment and policy, planning that addresses risks, support and documented information, operation, performance evaluation through internal audit and management review and, finally, improvement. Alongside these it carries a set of Annex A controls specific to AI, covering matters such as the AI policy, roles and responsibilities, impact assessment and the management of AI systems across their lifecycle. Readiness means having both the management-system elements and the AI-specific controls in place and evidenced.

How to judge your readiness

Readiness is a comparison, so run it as one. Take each requirement of the standard and ask two questions, whether you do the thing it asks and whether you can evidence that you do. A requirement you meet in practice but cannot evidence is not yet ready, because a certification audit tests both. Work through the management-system requirements and the Annex A controls in turn, and mark each as met and evidenced, done but not evidenced or not yet done. The picture that emerges is your readiness, and the second category, done but not evidenced, is usually the largest and the most surprising.

Where organisations most often fall short

Certain findings recur. The first is scope, an incomplete picture of the AI systems in use, because the standard cannot be met over systems you have not identified. The second is evidence, governance that happens but leaves records an auditor cannot rely on, held in shared drives where their integrity cannot be shown. The third is the management-system machinery that a younger program has not built yet, a defined internal audit of the AI management system and a documented management review, which the standard requires and which do not exist until someone sets them up. The fourth is lifecycle, assessments and controls done once and not maintained as systems change. Readiness work concentrates on these.

Readiness is not certification

It is worth being precise about what readiness gets you. A readiness assessment, whether you run it yourself or engage an adviser, tells you how close you are and what to close. It does not certify you. Certification against ISO/IEC 42001 is performed by an accredited certification body through a formal audit, and no software and no self-assessment can stand in for that. The value of readiness work is that it makes the certification audit shorter and its result more predictable, because the findings have been made and closed before the auditor arrives rather than during the audit.

A readiness checklist

  • The AI systems in scope are fully identified, including embedded and informally adopted ones.
  • An AI policy and defined roles and responsibilities are in place and current.
  • Risk and impact assessment runs across the AI lifecycle, with owners and decisions on the record.
  • The Annex A controls relevant to your context are implemented and evidenced.
  • Documented information exists and its integrity can be shown, not just its contents.
  • Internal audit of the AI management system and management review are defined and have run.

Frequently asked questions

Is ISO/IEC 42001 certification mandatory in Australia? No. ISO/IEC 42001 is a voluntary standard. Organisations pursue certification because boards, regulators and enterprise customers increasingly ask to see governance measured against a recognised reference, not because the law requires the certificate.

How long does it take to get ready? It depends on where the program starts. A function with a current register, assessments on the record and reliable evidence is closer than one that governs well but cannot evidence it. The management-system machinery, internal audit and management review, often takes the longest because it has to be built and then run at least once to produce evidence.

Can we self-assess our readiness? Yes. A self-assessment against the standard’s requirements is a legitimate first step and often the whole of the readiness work. Some organisations also engage an adviser for an independent readiness review before committing to a certification audit.

Does Aicura certify us against ISO/IEC 42001? No. Aicura holds much of the evidence a readiness assessment and a certification audit draw on, and surfaces the AI footprint the standard applies to. It does not audit you, assess your readiness or certify you against the standard. A readiness assessment is your judgment or your adviser’s, and certification is the accredited body’s.

Where Aicura fits

Aicura is your AI Register, which addresses the first and most common readiness finding, an incomplete picture of the AI in scope. It holds the systems in use as the record and versions each as it changes, so the scope the standard applies to is current. Impact Assessments carry the risk and impact work the standard asks for across the lifecycle, and Incidents and the agent records in the AI Register hold the operational records that show the management system running.

The Evidence Vault addresses the evidence finding. It seals each record so its integrity can be shown, not just its contents, evidence you don’t have to trust us for, cryptographically anchored and verifiable without Aicura in the loop, which is what turns governance that happens into governance an auditor can rely on. Attestation lets accountable owners sign against the record, and the Trust Centre lets you share the evidence with an adviser or an auditor. Aicura holds the evidence and surfaces the footprint. It does not audit you, assess your readiness or certify you. You and your certification body do that.

For the related work, read how to measure AI governance against a framework and what counts as AI audit evidence. When the audit is booked, how to prepare for an AI governance audit sets out the preparation. The AI governance software overview sets out what Aicura supports.

Sources

  • ISO/IEC 42001:2023, AI management system, International Organization for Standardization, iso.org
  • ISO 19011:2018, Guidelines for auditing management systems, International Organization for Standardization, iso.org

A note on this page

This explainer is general information on ISO/IEC 42001 readiness. It is not legal advice, it is not a certification and it does not tell you whether your organisation meets the standard. For a determination against the standard you need an accredited certification body. For how the standard applies to your organisation, read the primary source above and take your own professional advice.

When you need to show your work

Aicura is your AI Register, and Pro adds the assurance layer, meaning impact assessments, incident records, attestation and the Evidence Vault, which seals each record so it can be verified without taking anyone's word for it, ours included. Pro is sales-led, so the best next step is a conversation and a walkthrough.