An ISO 42001 readiness checklist
By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · ISO 42001
ISO 42001 looks large until you list it out. For most organisations it is an AI inventory, a risk and impact assessment, the AI-specific controls, and the management machinery.
Foundation: inventory and risk
Begin by listing the AI systems you build and use, then assess their risk and their impact on individuals and society. This inventory-and-assessment groundwork is the foundation everything else references — the controls you select and the oversight you apply all follow from it.
Scope, policy, controls
Define the AIMS scope around the AI that matters, write the AI policy (leadership's responsible-AI commitments), select the Annex A controls your risk warrants, and document them in the statement of applicability. This is the design of the management system.
The AI-specific processes
- Lifecycle governance: responsible development, validation, monitoring, and decommissioning.
- Data governance, transparency, and human oversight for the systems that need them.
- Impact assessments for higher-risk systems, kept current.
Management machinery and evidence
Stand up the management-system mechanics — internal audit, management review, corrective action — and keep evidence the controls run. Reuse an ISO 27001 ISMS if you have one. SentinelPanda runs the AIMS controls, evidence, and audit cadence; an accredited body certifies.