ISO/IEC 42001:2023 Readiness

Be ISO 42001 audit ready, control by control.

A guided path through every Annex A control, scoped to the AI systems you actually develop, provide or use. Your business liaison answers, your GRC Liaison reviews, and each stage ends in a document your auditor asks for.

At a glance

Standard
ISO/IEC 42001:2023
Clauses covered
4 to 10
Annex A controls mapped
38
Document templates
34
AI risk scenarios in the library
40
Seats included
1 GRC Liaison + 2 business

How it works

Six stages, each one ends in a document.

Stages unlock in order. Implementation and management review run in parallel once your Statement of Applicability is complete.

  1. Context

    Clause 4

    Guided questions about your organisation, its role(s) with respect to AI, your interested parties and your AI obligations — and an inventory of every AI system you develop, provide or use. A formal AIMS scope statement drafted from your answers, which you approve.

    You produce

    A documented context, an AI system inventory and an agreed AIMS scope statement

  2. Statement of Applicability

    Annex A

    Decide which of the 38 Annex A controls apply, and justify each one. Baseline controls every AIMS needs arrive pre-justified; role hints tell you which controls typically apply to AI providers versus AI users.

    You produce

    A complete, justified Statement of Applicability in Word and Excel

  3. Risk & impact

    Clauses 6.1.2–6.1.4

    Assess the impact of each in-scope AI system on individuals, groups and society, structured on ISO/IEC 42005. Then assess from a library of 40 AI risk scenarios — prompt injection, bias, drift, shadow AI, vendor model changes — seeded by what your inventory contains. Score on a 5×5 grid. Treat each risk down and record management approval of the residual.

    You produce

    Impact assessments per AI system and a scored, approved risk register

  4. Documents

    Clause 7.5

    A 38-item worklist assembled from 34 templates — the AI policy, governance charter, lifecycle, data and oversight procedures — plus documents generated straight from your earlier stages: scope, inventory, SoA, impact assessments, treatment plan. Edit offline and re-upload your own.

    You produce

    A complete, audit-ready set of AIMS documents and records

  5. Control implementation

    Annex A

    Capture evidence per control, assign owners, and take each one through your internal audit with findings, corrective actions and target dates. Suggested evidence is listed for every control.

    You produce

    Every applicable control audited, with evidence and findings on record

  6. Management review

    Clause 9.3

    Author the minutes. Nine of twelve agenda items pre-fill from your live assessment, including the state of your impact assessments and inventory.

    You produce

    A dated, immutable management-review record, exported to Word

Then the auditor

Hand your certification body the internal audit record: every applicable control with its evidence, findings and corrective actions, alongside the AI inventory, impact assessments, Statement of Applicability, risk register, procedures and minutes. Export the pack, or open two read-only seats once the assessment is in maintenance.

Always oriented

Know you are ready before your auditor does.

Every assessment opens on one dashboard. Six honest numbers, and no invented score. When all six read complete, you are ready.

AI systems in scope

6 / 7

inventoried, one excluded with reason

Controls applicable

34 / 38

justified in the SoA

Impact assessments complete

6 / 6

one per in-scope system

Residual within threshold

26 / 29

3 accepted with approval

Documents ready

28 / 34

mandatory items generated

Controls audited

28 / 34

evidence and findings on record

Illustrative figures. Real dashboard.

The output

Everything your certification body will ask for.

Statement of Applicability

Cover page and control-by-control justification across the nine Annex A objectives. Exported to Word and Excel.

Impact assessments & risk register

One impact assessment per AI system across the Annex C objectives; a risk register with inherent and residual scores, control mapping and an approved treatment plan.

AIMS document set

AI policy, procedures and registers generated from your answers. Every version stored, yours to edit and replace.

Management-review minutes

Immutable per cycle, with the agenda rolled up from the assessment itself.

AI, with a leash

Compliance lives in the nuance. Your team decides what is true for your organisation. Your GRC Liaison signs off. The scope drafter, the impact-assessment refiner and the minutes refiner use only the facts in your answers, and are forbidden from inventing systems, numbers, findings, documents or decisions.

The library

Everything is already drafted.

34 templates — the AI policy, governance, lifecycle, data, oversight and supplier documents — so you write none from scratch.

34

document templates

38

worklist items, 34 mandatory

40

AI risk scenarios, inventory-aware

38

Annex A controls

Template · Clause 5.2

Mandatory

AI Policy

The top-level policy your certification body reads first: responsible-AI commitments, alignment with your other policies, review cycle.

Template · A.5

Mandatory

AI System Impact Assessment Procedure

When and how you assess consequences for individuals and society, aligned to ISO/IEC 42005 — the record auditors ask for first.

Template · A.9

Mandatory

Responsible Use of AI Policy & Human Oversight

Rules for staff use of AI tools, intended-use adherence, and how a competent person can intervene.

Who does what

Two roles. One assessment.

Business side

Creator and business liaison

Answer the context questions. Build the AI inventory. Decide applicability. Run the impact assessments and risk register. Upload evidence and own controls.

Governance side

GRC Liaison

Owns the audit panel: findings, notes and required actions on every control. Reviews what the business asserts.

Optional

RegXpert partner

No AI governance function in-house? Invite a RegXpert into the GRC seat. They review your answers and guide your team.

Each assessment carries one GRC Liaison seat and two business seats. Seats are counted live from who actually holds a role. Clear an owner and the seat frees immediately.

Free resources

Useful before you subscribe.

Working documents, not marketing PDFs. Three download instantly; two ask you to sign in first.

Excel

Mandatory documents & records checklist

Every document and record ISO/IEC 42001:2023 expects, with clause and Annex A references and priority.

Word

Management-review agenda

The Clause 9.3 agenda — all twelve inputs and outputs — ready to chair your first review.

Word

Questions for your certification body

Fifteen questions to ask before you engage an auditor, from ISO/IEC 42006 accreditation to audit days.

Excel · sign-in

Sign-in

Statement of Applicability worksheet

All 38 Annex A controls as a worksheet: applicable, justification, baseline pre-marked.

Excel · sign-in

Sign-in

AI risk register starter

Ten authored AI risks in the register format the app uses, with scoring bands.

Pricing

One flat rate per assessment.

Your first assessment is free for its first month, with no card. After that, every assessment carries one flat USD rate, monthly or annual. Cancel any time, effective at the end of the period. Your records remain yours to export.

Per assessment

US$249

per month per assessment

  • 1 GRC Liaison seat and 2 business seats

  • All six stages and every export

  • AI drafting, evidence storage and the full template library

Annual

US$2,490

per year per assessment

  • Pay for 10 months, receive 12

  • Charged up front, no refund of the unused term

  • Same seats, stages and exports

Maintenance

US$75

per month, once complete

  • Roughly 30% of the active rate

  • 2 read-only seats for auditors and reviewers

  • Reopen any time, and the full rate resumes next period

Bringing in an external AI governance consultant? That is charged on top of the platform fee: US$1,500 a month during implementation, and on request for ongoing maintenance and surveillance. The rate covers up to 20 hours a month of review and feedback, and depends on the nature of the work.

Book a demo

Want to see it on your own scope?

We will walk through the six stages and the documents they produce for an organisation like yours.

Book a demo
ISO 42001 Readiness — RegXperience