A Statement of Applicability template lands in your inbox: 38 blank rows, a column for "applicable," a column for "justification," and no idea where to start filling it in. Or a vendor security questionnaire cites a specific Annex A control number and expects a real answer, not a shrug.
An ISO 42001 checklist has two parts: the mandatory clauses (4 through 10) every certifying organization must meet, and the 38 Annex A controls across 9 objectives (A.2 through A.10) an organization selects from based on its own AI risk assessment. The controls aren't a wall-to-wall implementation list. They're a catalogue you draw from, documented in a Statement of Applicability that records which ones apply, which don't, and why.
This guide is written for readers past the "what is ISO 42001" question: compliance leads, security leads, and founders who've been handed "get us ISO 42001-ready" as a task, or who need to answer a questionnaire citing a specific control number today.
Here's what I'll cover:
- The two-part structure: mandatory clauses versus selectable Annex A controls
- What a Statement of Applicability actually is and why it matters more than the control count itself
- The full, control-by-control ISO 42001 checklist: all 38 controls, organized by objective
- The mandatory-document checklist you need before you apply
- How to actually use this checklist, step by step
- Common mistakes that turn this into a box-ticking exercise instead of a risk-based one
One scope note before the rest of this guide: this article assumes you already know roughly what ISO 42001 is. If you need the standard itself explained first, the AI Management System (AIMS), what certification involves, why it matters for a SaaS company, ComplyJet's ISO 42001 guide covers that ground. This piece is the reference list itself.
Who Actually Uses This ISO 42001 Checklist
Three situations bring people to this exact checklist, and they're worth naming before the tables start.
Teams actively pursuing certification use it as the iso 42001 implementation checklist they build the AIMS from: risk assessment first, then the Statement of Applicability, then the control build-out, then the mandatory documents. That's the main audience this article is written for.
Teams already deep into the process, with Stage 1 or Stage 2 booked, use it as the iso 42001 audit checklist they walk through right before an auditor shows up, confirming every applicable control has real evidence behind it and every mandatory document is current, not stale from six months earlier.
Teams that aren't certifying at all still land here from a vendor security questionnaire that cites a specific Annex A control number, or from a GRC program using the 38 controls as an internal reference taxonomy, the same pattern already seen with ISO 27002's controls catalog. For that group, the full table below is the answer on its own, no certification project required.
The ISO 42001 Checklist's Requirements: Mandatory Clauses vs. Annex A Controls
Every ISO 42001 checklist has two genuinely different parts, and conflating them is where most confusion starts. Clauses 4 through 10 are mandatory: every organization pursuing certification meets all seven, no exceptions, no selection involved. Annex A's 38 controls are different: an organization picks the ones relevant to its own AI systems and risk profile, and documents that selection formally.
Treat this iso 42001 requirements checklist as two layers stacked on top of each other. The bottom layer, clauses 4-10, is the non-negotiable management-system core: context, leadership, planning, support, operation, performance evaluation, improvement. The top layer, Annex A, is where the actual judgment calls live.
ISO 42001 Checklist Requirements: The 7 Mandatory Clauses at a Glance
This iso 42001 requirements checklist starts with what's actually mandatory before getting to the selectable controls layer above it. These seven clauses form the auditable management-system core, already verified in full in ComplyJet's ISO 42001 guide and reused here rather than re-derived.
| Clause | What It Requires |
|---|---|
| 4. Context of the organization | Understand the organization, its interested parties, and the AIMS scope |
| 5. Leadership | Top management commits to the AIMS, sets AI policy, assigns roles and responsibilities |
| 6. Planning | Assess AI-related risks and opportunities, set AIMS objectives to address them |
| 7. Support | Provide the resources, competence, awareness, and documented information the AIMS needs |
| 8. Operation | Run the operational core: AI risk assessment, AI system impact assessment, lifecycle controls |
| 9. Performance evaluation | Monitor, measure, internally audit, and formally review the AIMS |
| 10. Improvement | Correct nonconformities and drive continual improvement based on what evaluation finds |
For the full clause-by-clause explanation, including clauses 1-3's front matter, see ComplyJet's ISO 42001 guide. This checklist stays focused on what to actually check off, not on re-explaining each clause.
The ISO 42001 Checklist's Statement of Applicability (SoA), Explained
The Statement of Applicability (SoA) is the document that records which of the 38 Annex A controls apply to your organization, which don't, and why. It's built from your AI risk assessment and AI system impact assessment, and it's what turns a flat 38-control list into an actual, defensible checklist for your specific systems.
This is the iso 42001 statement of applicability every certification body asks for, and it's usually the first document an auditor reaches for when reviewing Annex A coverage. A thin or copy-pasted SoA is one of the fastest ways to turn a clean Stage 1 review into a list of "Areas of Concern" that delay Stage 2, so it's worth treating as a real working document rather than a formality filled in the week before the audit.
What actually goes in an SoA entry, per control: the control number and name, whether it's applicable, and if it is, a short note on how it's implemented; if it isn't, the specific reason why (a control about third-party AI model risk doesn't apply to an org that builds every model in-house, for instance). Auditors read the "why" column closely. A blank one, or a copy-pasted generic justification, is a common finding worth avoiding from the start.
This is the document that connects the risk assessment to the actual checklist below. Build the risk and impact assessment first, then use it to populate the iso 42001 statement of applicability, then use that SoA to decide which of the 38 controls in the next section actually apply to your organization.
The Full ISO 42001 Annex A Controls List: All 38 Controls by Objective
The Complete ISO 42001 Controls List, One Table Per Objective
This is the complete iso 42001 controls list, organized exactly the way Annex A organizes it: all 38 controls, one row each, grouped under the 9 objectives, with enough detail per row to actually work from rather than just a name repeated back.
Cross-referenced against Vanta's dedicated controls page and isms.online's Annex A breakdown, with mindsetcyber.com.au's per-objective count used as the source of truth for the full 38-control table below since it's the only source checked that lists every individual control name rather than just the 9 objective headings. Treat it as the iso 42001 controls spreadsheet you'd otherwise have to assemble yourself from a paid standard and a handful of partial blog posts, no download or gate required.
A.2 Policies Related to AI (3 Controls)
The governance layer for the AI policy itself, how it's maintained, and how it aligns with the organization's other policies.
| Control | Name | What It Covers |
|---|---|---|
| A.2.2 | AI policy | A documented, leadership-approved policy setting the organization's direction for responsible AI |
| A.2.3 | Alignment with other organizational policies | The AI policy checked against existing security, privacy, and data policies for consistency, not written in isolation |
| A.2.4 | Review of the AI policy | The AI policy reviewed on a defined schedule and updated as AI systems and risks change |
A.3 Internal Organization (2 Controls)
The smallest objective on the checklist: who owns AI governance internally, and how concerns actually get reported.
| Control | Name | What It Covers |
|---|---|---|
| A.3.2 | AI roles and responsibilities | Named owners for AI governance tasks and decisions, not an ambiguous shared responsibility |
| A.3.3 | Reporting of concerns | A clear, known channel for anyone to raise an AI-related concern internally |
A.4 Resources for AI Systems (5 Controls)
What the AIMS actually needs to run: documented resources across data, tooling, compute, and people.
| Control | Name | What It Covers |
|---|---|---|
| A.4.2 | Resource documentation | A maintained record of the resources each AI system depends on |
| A.4.3 | Data resources | The datasets an AI system uses, tracked and documented |
| A.4.4 | Tooling resources | The tools and platforms used to build, run, and monitor AI systems |
| A.4.5 | System and computing resources | The infrastructure and compute an AI system runs on |
| A.4.6 | Human resources | The people and skills assigned to AI development, deployment, and oversight |
A.5 Assessing Impacts of AI Systems (4 Controls)
The impact-assessment process itself, including effects on individuals, groups, and society more broadly.
| Control | Name | What It Covers |
|---|---|---|
| A.5.2 | AI system impact assessment process | A defined, repeatable process for assessing an AI system's potential impact before and during use |
| A.5.3 | Documentation of AI system impact assessments | Impact assessments recorded and kept as real evidence, not performed once and forgotten |
| A.5.4 | Assessing AI system impact on individuals or groups of individuals | Direct effects on people, including fairness and bias considerations, assessed explicitly |
| A.5.5 | Assessing societal impacts of AI systems | Broader effects beyond individual users, evaluated as part of the same process |
A.6 AI System Life Cycle (9 Controls)
The largest single objective on the checklist, covering an AI system from design through deployment, operation, and monitoring.
| Control | Name | What It Covers |
|---|---|---|
| A.6.1.2 | Objectives for responsible development of AI systems | Clear, documented goals for how AI systems should be developed responsibly |
| A.6.1.3 | Processes for responsible design and development of AI systems | The actual process controls that put those objectives into practice |
| A.6.2.2 | AI system requirements and specification | Requirements defined and documented before development starts, not retrofitted after |
| A.6.2.3 | Documentation of AI system design and development | Design and development decisions recorded as they happen |
| A.6.2.4 | AI system verification and validation | Testing that confirms the system does what it's specified to do |
| A.6.2.5 | AI system deployment | A controlled, documented process for moving an AI system into production |
| A.6.2.6 | AI system operation and monitoring | Ongoing monitoring of a deployed system's real-world behavior |
| A.6.2.7 | AI system technical documentation | Technical documentation maintained and kept current across the system's life |
| A.6.2.8 | AI system recording of event logs | Event logs captured consistently enough to support monitoring and investigation |
A.7 Data for AI Systems (5 Controls)
Data quality, provenance, and preparation for both training and ongoing operation.
| Control | Name | What It Covers |
|---|---|---|
| A.7.2 | Data for development and enhancement of AI systems | Data used to build and improve AI systems, managed and documented |
| A.7.3 | Acquisition of data | How data is sourced, with appropriate checks before it enters the pipeline |
| A.7.4 | Quality of data for AI systems | Data quality actively managed, not assumed |
| A.7.5 | Data provenance | Where data actually came from, tracked and documented |
| A.7.6 | Data preparation | Data cleaning and preparation steps documented and consistent |
A.8 Information for Interested Parties (4 Controls)
Transparency toward users, customers, regulators, and anyone else affected by the AI system.
| Control | Name | What It Covers |
|---|---|---|
| A.8.2 | System documentation and information for users | Users given clear, accurate information about what the AI system does |
| A.8.3 | External reporting | A defined process for reporting AI-related information externally when required |
| A.8.4 | Communication of incidents | A clear process for communicating AI-related incidents to affected parties |
| A.8.5 | Information for interested parties | Broader stakeholder communication beyond direct users, handled consistently |
A.9 Use of AI Systems (3 Controls)
How a deployed AI system is actually meant to be used, and how that's enforced.
| Control | Name | What It Covers |
|---|---|---|
| A.9.2 | Processes for responsible use of AI systems | Defined processes governing how staff and systems actually use AI responsibly |
| A.9.3 | Objectives for responsible use of AI systems | Clear goals for what responsible use looks like in practice |
| A.9.4 | Intended use of the AI system | The system's intended use documented explicitly, so misuse is easier to identify |
A.10 Third-Party and Customer Relationships (3 Controls)
Vendor and supply-chain AI risk, plus how responsibilities are actually divided with suppliers and customers.
| Control | Name | What It Covers |
|---|---|---|
| A.10.2 | Allocating responsibilities | Clear division of AI-related responsibilities between the organization and its suppliers or customers |
| A.10.3 | Suppliers | AI-related risk from third-party suppliers actively managed, not assumed away |
| A.10.4 | Customers | Customer-facing responsibilities and expectations around AI use clearly set |
That's the full 38: 3 plus 2 plus 5 plus 4 plus 9 plus 5 plus 4 plus 3 plus 3. Every control sits in exactly one objective, and the Statement of Applicability section above is what decides which of these 38 actually apply to your organization's own AI systems.
ISO 42001 Mandatory Documents Checklist: What You Need Before You Apply
Beyond the 38-control table, an ISO 42001 checklist isn't complete without the paperwork that proves the AIMS is actually operating. Sourced across the same converging references used for the mandatory-clause table above: ISO 42001 has 20+ required documents and records, spanning four categories, and the exact count scales with organization size and AI-system scope rather than being a fixed list every certified company produces identically.
| Category | What It Includes |
|---|---|
| Required documents | AIMS Scope Statement, AI Policy, AI Objectives, Statement of Applicability |
| Required records | AI risk assessment, AI impact assessment, internal audit records, management review minutes, corrective action records |
| Policies and procedures | Roles and responsibilities, competence and training procedures, incident-handling procedures for AI systems |
| AI system-level documentation | AI system inventory, data governance records for each system in scope, monitoring and performance records |
Treat this iso 42001 mandatory documents table as a working checklist in its own right, separate from the 38-control table above. It's common for teams to spend most of their planning time on Annex A control selection and leave the documentation checklist for later, only to find it's the part an auditor asks for first, since documents and records are what actually prove the AIMS is running day to day.
How to Use This ISO 42001 Implementation Checklist (Practical Steps)
This is the order the checklist above actually gets used in, not a list to work through top to bottom at random:
- Run the AI risk assessment and AI system impact assessment. Everything downstream, the SoA, the control selection, the mandatory documents, depends on this being done first and done for real, not as a formality. A risk assessment written to satisfy an auditor's checkbox, rather than to actually surface risk, produces a weak SoA no matter how polished it looks.
- Build the Statement of Applicability from the 38-control table above. Go control by control, mark each one applicable or not, and write the actual reason, not a placeholder. This step alone is usually where the iso 42001 implementation checklist takes the most real time, since it forces a genuine decision on every one of the 38 controls rather than a blanket yes.
- Implement only the controls the SoA marks applicable. Resist the urge to implement all 38 "to be safe." It adds cost and complexity without adding real risk coverage, and it dilutes attention away from the controls that actually matter for your specific AI systems.
- Assemble the mandatory-documents checklist. Use the four-category table above as the working list, and track what's built versus outstanding. Treat missing documents as gaps to close now, not something to backfill the week before Stage 1.
- Run an internal audit before the external one. This confirms the AIMS is actually operating as designed, and it's the practical iso 42001 audit checklist teams work from once the internal audit gets scheduled, catching gaps before an outside auditor does. An internal audit that finds nothing wrong on the first pass is itself worth a second look; it usually means the audit wasn't thorough enough, not that the AIMS is flawless.
For the fuller certification process this section deliberately doesn't re-explain, readiness assessment through Stage 1 and Stage 2 audits, timeline, and cost, see ComplyJet's ISO 42001 certification cost guide.
Common ISO 42001 Compliance Checklist Mistakes to Avoid
- Treating all 38 Annex A controls as mandatory. Covered above, and worth repeating because it's the single most common misreading of this checklist: select based on risk, not by default.
- Scoping the checklist across the entire company instead of the actual AI systems in play. A five-person company with one AI feature doesn't need every team and process in scope, just the systems that actually use or produce AI.
- Leaving the SoA's "why" column blank or generic. "Not applicable" with no real justification is exactly the finding an auditor flags first.
- Skipping the mandatory-document checklist because Annex A got all the attention. The 20+ documents and records matter just as much as the control selection, and they're easy to under-scope once the 38-control table has taken up most of the planning time.
- Confusing this checklist with a generic AI governance policy. A written policy is one document inside a much larger system. It isn't a substitute for the risk assessment, the SoA, or the mandatory-document checklist.
- Treating the checklist as a one-time exercise. AI systems change, new ones get added, and the SoA and control selection need periodic review, not a single pass at the start.
- Assuming ISO 27001's Annex A checklist substitutes for this one. The two standards share a management-system skeleton, which helps, but ISO 27001's Annex A doesn't cover AI-specific requirements like impact assessment for bias and fairness or AI system lifecycle controls.
- Building the checklist once and never assigning an owner to keep it current. A Statement of Applicability with no named owner tends to drift out of date the first time an AI system changes, which is exactly the moment a surveillance audit is most likely to catch it.
Most of these mistakes share a root cause: treating this as a static, one-time compliance checklist rather than a living document that gets revisited as the organization's AI footprint actually grows. A genuinely useful iso 42001 compliance checklist gets a named owner and a real review cadence, the same discipline clause 9's management review already requires of the AIMS itself.
Most of the ISO 42001 checklist questions we see aren't about what the controls mean. They're about the Statement of Applicability: how to justify marking something not applicable without it reading as a shortcut to an auditor. — Upendra Varma, CTO at ComplyJet
Where ComplyJet Fits Into Your ISO 42001 Checklist
ComplyJet directly supports and certifies ISO 42001, and the checklist above maps directly onto real product capability, not an adjacent mention. That includes Statement of Applicability support and control-evidence tracking across all 38 Annex A controls, automated evidence collection across 350+ integrations, and mandatory-document templates covering the four categories in the checklist above.
Pricing is flat and per-company, not per-seat, so the cost of working through this checklist stays predictable as your team grows during the certification process rather than scaling with headcount.
If you're earlier in the decision, still working out whether ISO 42001 applies to you at all, ComplyJet's ISO 42001 guide is the right starting point instead of this one.
FAQs
What Is on the ISO 42001 Checklist?
Two parts: the mandatory clauses (4-10) every certifying organization meets, and the 38 Annex A controls across 9 objectives an organization selects from based on its own AI risk assessment. Add the mandatory-document checklist (20+ documents and records) and that's the complete picture. See the sections above for the full breakdown of each.
How Many Controls Does ISO 42001 Have?
38 Annex A controls across 9 objectives, numbered A.2 through A.10. One source (OneTrust) states 39; the majority of independently checked sources, and ComplyJet's own verification, converge on 38. See the full control-by-control table above.
What Are the ISO 42001 Annex A Controls?
They're the 38 selectable controls covering AI policies, internal organization, resources, impact assessment, the AI system life cycle, data, transparency, use, and third-party relationships. See the objective-by-objective tables above for every control name and what it covers.
Is ISO 42001 Annex A Mandatory?
Not wall to wall. The 7 clauses (4-10) are mandatory for every certifying organization. Annex A's 38 controls are selected based on a risk-based Statement of Applicability, not implemented in full by default. See the requirements section above for the full mandatory-versus-selectable breakdown.
What Documents Do You Need for ISO 42001?
Roughly 20+ required documents and records across four categories: required documents (AIMS Scope Statement, AI Policy, Statement of Applicability), required records (risk and impact assessments, audit and review records), policies and procedures, and AI system-level documentation. See the mandatory-documents table above for the full list.
What Is a Statement of Applicability in ISO 42001?
The document that records which of the 38 Annex A controls apply to your organization, which don't, and why, built from your AI risk and impact assessment. It's usually the first document an auditor reviews for Annex A coverage. See the dedicated SoA section above for the full explanation.
How Do You Use an ISO 42001 Checklist?
Run the risk and impact assessment first, build the SoA from the 38-control table, implement only the controls the SoA marks applicable, assemble the mandatory-document checklist, then run an internal audit before the external one. See the practical steps section above for the full sequence.
Is There a Free ISO 42001 Checklist PDF?
ISO doesn't publish the standard itself as a free PDF; it's a paid publication. This article's full 38-control table and mandatory-document checklist above are built to serve the same practical need in one place, without a download or a gate, and kept current as the standard's guidance evolves.
Related Reading
- What Is ISO 42001? The Complete AI Management System Guide, for the standard itself explained, if you need that ground covered first
- ISO 42001 Certification: Requirements, Process, and Cost, for the fuller Stage 1/Stage 2 process, timeline, and cost breakdown this article deliberately doesn't re-explain
- ISO 27002 Checklist: All 93 Controls by Theme, Explained, the same control-by-control table structure applied to ISO 27001's sibling standard
- ISO 27001 and AI Compliance: The Complete Comparison, for how ISO 27001's own Annex A relates to this one
- ComplyJet's ISO 42001 Framework Page, for readers ready to evaluate certification support directly
Sources: Annex A control count and full per-objective list (38 controls, 9 objectives) verified against Vanta's ISO 42001 controls guide, ISMS.online's Annex A controls guide, and Mindsetcyber's Annex A controls list, the same source set independently verified in ComplyJet's ISO 42001 guide. Mandatory-clause structure and the 20+ mandatory-document figure carried forward from ComplyJet's own already-verified ISO 42001 guide and certification cost guide, sourced there to Hicomply, Advisera, and ISMS.online's documentation breakdowns.





