ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. It describes how an organisation should govern the AI it builds, buys and uses. This guide turns the standard into ten practical steps, shows what evidence each part of Annex A typically needs, and gives you a 90-day plan to get started.
This guide is general information. It is not legal advice, and following it does not by itself make an organisation certified. Certification against ISO/IEC 42001 is carried out by an accredited certification body.
Who this guide is for
Risk, compliance and governance leads, and the AI and product teams who work with them, in organisations that are starting to implement ISO 42001 or that have been asked to show alignment with it by a board, a customer or a regulator.
What ISO 42001 requires
ISO 42001 asks you to establish an AI management system (AIMS): the policies, roles, processes and records that show your AI is governed. It has two parts.
- Clauses 4 to 10 describe the management system itself: context, leadership, planning, support, operation, performance evaluation and improvement. These follow the same structure as other ISO management system standards.
- Annex A lists 38 controls in nine groups that you consider and, where relevant, apply to your AI systems. Annex A is where most of the day-to-day evidence comes from.
You decide which Annex A controls apply, and you record that decision, with reasons, in a document called the Statement of Applicability.
The ten steps
Step 1. Define your scope and context (clause 4). Decide which AI systems, teams and locations are inside your AIMS. List the internal and external issues that affect your AI, and the interested parties who care about it, such as customers, regulators and staff. Evidence: a scope statement and a register of interested parties and their requirements.
Step 2. Set leadership and accountability (clause 5). Name an executive sponsor, and assign clear roles for who owns each AI system, who assesses its risk, and who approves it. Evidence: a roles and responsibilities document and a record of leadership approval.
Step 3. Build an AI inventory. You cannot govern what you cannot see. List every AI system, model and agent, including those bought from vendors and those embedded in other software. For each, record its purpose, owner, users, data and lifecycle status. Evidence: the inventory, with a review date.
Step 4. Assess risk and impact (clauses 6.1.2 and 6.1.4, 8.2 and 8.4). Define how you assess AI risk and how you assess an AI system's impact on people and society. Then do it for each system in your inventory. Evidence: a documented risk method, completed risk assessments and completed impact assessments.
Step 5. Treat risk and write your Statement of Applicability (clause 6.1.3). Decide how you will treat each risk, compare your chosen controls against Annex A, and record which controls apply and why, and which do not and why. Evidence: a risk treatment plan and a Statement of Applicability.

AI Governance Checklist
50 checkpoints for responsible AI deployment: governance documentation, evidence requirements, control mapping and regulator-ready reporting. Built for Australian compliance contexts (ISO 42001, APRA CPS 230, TEQSA).
Step 6. Set your AI policy and objectives (clauses 5.2 and 6.2). Publish an AI policy that leadership has approved, and set measurable objectives, such as the percentage of AI systems with a completed impact assessment. Evidence: the approved policy, the objectives, and a plan for how each will be measured.
Step 7. Provide resources, competence and awareness (clause 7). Make sure the people running the AIMS have the skills, budget and tools they need, and that everyone who works with AI understands the policy. Evidence: training records, competence records and communication records.
Step 8. Operate your controls across the AI lifecycle (clause 8 and Annex A). Put the controls you selected into practice, from design and testing through deployment, monitoring and retirement. Manage changes deliberately, and control any AI you buy from third parties. Evidence: design records, test results, change logs, monitoring reports and supplier records.
Step 9. Monitor, audit and review (clause 9). Measure how the AIMS is performing, run an internal audit, and hold a management review where leadership looks at the results. Evidence: monitoring data, internal audit reports and management review minutes.
Step 10. Improve (clause 10). When something fails or a finding is raised, record it, fix the cause and check that the fix worked. Evidence: a log of nonconformities and corrective actions.
What evidence each Annex A group typically needs
| Annex A group | What it covers | Typical evidence |
|---|---|---|
| A.2 Policies related to AI | Your AI policy and how it fits with other policies | Approved AI policy, review records, a mapping to related policies |
| A.3 Internal organisation | Roles, responsibilities and reporting of concerns | Role descriptions, an escalation and concern-reporting procedure |
| A.4 Resources for AI systems | The data, tools, computing and people an AI system needs | Resource documentation for each system |
| A.5 Assessing impacts of AI systems | How you assess effects on people and society | Impact assessment process and completed assessments |
| A.6 AI system life cycle | Design, testing, deployment, operation and monitoring | Design objectives, verification and validation results, deployment plans, monitoring records, event logs, technical documentation |
| A.7 Data for AI systems | Data quality, provenance and preparation | Data management procedures, provenance records, data quality checks |
| A.8 Information for interested parties | What you tell users and others about your AI | User documentation, disclosure notices, incident communication procedure |
| A.9 Use of AI systems | How AI is used responsibly inside your organisation | Responsible use procedures, defined intended uses |
| A.10 Third-party and customer relationships | Responsibilities shared with suppliers and customers | Supplier assessments, contract terms, customer information |
Common pitfalls
- Treating it as a document exercise. A policy on a shared drive is not a management system. Auditors look for evidence that the policy is followed.
- An incomplete inventory. Shadow AI and AI embedded in vendor software are the systems most often missed.
- A Statement of Applicability with no reasons. Every excluded control needs a documented justification.
- Point-in-time evidence. A risk assessment done once and never revisited goes stale as models, data and regulations change.
- No proof that evidence is unaltered. If a document can be edited after the fact, its value as evidence drops. Keep versions and record when each item was added.
A 90-day plan
Days 1 to 30: foundation. Confirm the executive sponsor and name the AIMS lead. Set the scope. Build the first version of the AI inventory. Agree the risk and impact assessment method.
Days 31 to 60: assessment and treatment. Assess the highest-risk systems first. Draft the risk treatment plan and the Statement of Applicability. Approve the AI policy and set the first objectives.
Days 61 to 90: operate and evidence. Put the selected controls into practice for your first systems. Collect evidence against each control. Run a small internal review to find gaps before anyone external does.
How Sentrify helps
Sentrify's 94 governance controls map to the 38 requirements of Annex A, and to the other frameworks in its crosswalk. You register your AI systems, upload evidence that is versioned and integrity-hashed, run an automated evaluation, and receive a TrustScore™ and an assurance report with the full evidence chain. Approvals stay with your people: Sentrify routes the review and records the decision. All data stays in AWS Sydney.
Sentrify's controls are aligned to ISO 42001. Alignment does not constitute certification.
Next steps
- Download the AI Governance Checklist for 50 practical checkpoints.
- See what the output looks like in the sample assurance report.
- Book a demo, or apply for the 8-week pilot.

AI Governance Checklist
50 checkpoints for responsible AI deployment: governance documentation, evidence requirements, control mapping and regulator-ready reporting. Built for Australian compliance contexts (ISO 42001, APRA CPS 230, TEQSA).
Turn this guide into evidence.
Related reading: ISO 42001 Explained: What Your AI Team Actually Needs to Do