Home Solutions AI Readiness & Governance — ISO/IEC 42001 About Start the Quick Check
AIMS-42 · mapped to ISO/IEC 42001:2023

Could you stand up an ISO/IEC 42001 audit today?

ISO/IEC 42001 is the international standard for AI management systems — seven clauses of requirements and thirty-eight controls. This assessment is mapped directly to them, and tells you which of the eight things a certification body looks for at Stage 1 you could actually produce.

15 questions · about 8 minutes · your result on screen immediately, no waiting and no call required.

This is a self-assessment instrument. It records what you tell us about your own organisation. It does not verify, audit or certify anything, and it is not legal advice. Certification against ISO/IEC 42001 is issued only by an accredited certification body. VisionXY7 Ltd prepares organisations for certification audits; it does not perform them.

Two ways in. Both free to complete.

The Quick Check tests the fifteen points that best predict how the other one hundred and forty behave. The full assessment examines all of them.

Tier 0 · start here

Quick Check

Free
  • Six scope questions and fifteen sentinels
  • About eight minutes
  • Your result on screen immediately — maturity index, the eight domains, and the Stage 1 gate status
  • A copy by email, yours to forward
  • One recommended next step
Start the Quick Check
Tier 1 · the full instrument

Readiness Assessment

Free to complete
  • All seven clauses and all thirty-eight Annex A controls
  • Eight modules, saved and resumed in your own time
  • Length adapts to what your organisation actually does with AI — a user-only organisation is not asked development questions
  • A control-by-control gap register with remediation and effort against each finding
  • A phased roadmap, personally reviewed before it is issued
Start with the Quick Check first

The full assessment opens from your Quick Check result, so nothing you answer is asked twice.

Not sure ISO/IEC 42001 is your question yet? If AI is in use across your organisation but nobody has been made responsible for it, a management system standard is the wrong place to start. The free AI Readiness Assessment is the better first move — it asks whether anyone is governing AI at all, which is the question underneath this one.

What gets measured

Eight domains, each carrying a stated weight in the maturity index. The weights are published here rather than hidden, because a score whose derivation you cannot see is not a finding — it is a number.

DomainWhat it covers in the standardWeight
Planning & Risk ManagementClauses 6.1.1–6.1.3, 6.2, 6.3, 8.2, 8.3 — risk criteria, the AI risk assessment, the Statement of Applicability, objectives18%
Context & LeadershipClauses 4–5 and Annex A.2, A.3 — scope, the AI policy, accountability, roles, the route to raise a concern15%
AI Lifecycle ControlsClause 8.1 and Annex A.6, A.9 — approval before go-live, change control, monitoring in production, human oversight15%
AI Impact AssessmentClauses 6.1.4, 8.4 and Annex A.5 — the effect on the individuals and groups your AI touches12%
Data GovernanceAnnex A.4.3, A.7 — data inventory, provenance, quality requirements and how they are checked12%
Resources & CompetenceClause 7 and Annex A.4 — people, skills, awareness, documented information10%
Performance & ImprovementClauses 9–10 — internal audit, management review, nonconformity and corrective action10%
Transparency & Third PartiesAnnex A.8, A.10 — what affected people are told, supplier due diligence, contractual AI requirements8%

Why a self-assessment cannot award itself the top level

Every item is scored against the same five-level scale. Four of those levels are available to you here. The fifth is not, and the reason is the whole argument for taking this seriously.

0
Absent

The requirement is not addressed in any form.

1
Ad hoc

Happens informally, depends on individuals, not written down or owned.

2
Defined

Documented, but not yet approved, communicated, or consistently applied.

3
Operating

Documented, applied consistently, and evidenced by records. The highest level a self-assessment can award.

4
Audit-evidenced

Independently verified against retained evidence, with demonstrated improvement over time. Cannot be self-awarded.

This is not a sales device. Level 4 means somebody competent and independent examined your evidence and found it held. No questionnaire can produce that, including this one. If your result stops at Operating, that is the instrument being accurate about what it has and has not seen — and it is the same distinction a certification body will draw when it asks to see the records behind your answers.

The eight things a certification body asks for at Stage 1

A Stage 1 audit is largely a documentation review. These eight are what it reviews. The assessment reports each one as Met, Partial, Open or Unknown — on what you have told us — so you can see which of them you could put in front of an auditor today.

Clause 4.3
AIMS scope

A written statement of which parts of the organisation, which locations and which AI systems your management system covers.

Clause 5.2 / A.2.2
AI policy

Approved by top management, covering both the development and the use of AI, communicated and available.

Clause 6.1.2
AI risk assessment

A defined and repeatable method, applied across your AI systems, with records that show it was applied.

Clause 6.1.3
Statement of Applicability

Every Annex A control listed, with justification for what you include and what you exclude. Without it there is nothing to audit against.

Clause 6.1.4 / A.5.2
AI system impact assessment

The effect on individuals and groups your AI systems touch — not the effect on the business.

Clause 9.2
Internal audit

A programme, carried out, with findings recorded — your own check before somebody else’s.

Clause 9.3
Management review

Top management formally reviewing the management system, with a recorded decision trail.

Clause 10.2
Nonconformity & corrective action

When something goes wrong, a defined process that treats it as an incident and fixes the cause.

Where this can lead, if you want it to

Information, not a pitch. Both assessments are free to complete and you are under no obligation to do anything with either.

StepWhat it isPrice
You are here — ISO/IEC 42001 Quick Check Live scored result, eight-gate status, one recommended next step. Free
Readiness Assessment All seven clauses, all thirty-eight controls, full gap register, phased roadmap, personally reviewed. Free to complete
Gap Review Your assessment worked through with Dr. Seify, remotely, and the register turned into a sequenced plan with owners and dates. Scoped per engagement
ISMS-to-AIMS Extension For organisations already certified to ISO/IEC 27001 or ISO 9001 — mapping what you already hold onto what ISO/IEC 42001 adds. Scoped per engagement
Governance Build AI policy, risk criteria, risk assessment, Statement of Applicability, impact assessment process, internal audit programme — the Stage 1 document set, built with you. Scoped per engagement
Certification Readiness Pre-audit review against evidence, internal audit cycle, management review, and support through Stage 1 and Stage 2 with your chosen certification body. VisionXY7 does not certify. Scoped per engagement
Fractional Chief AI Officer Ongoing ownership of AI governance where the organisation has no natural home for it. See mahdiseify.com →
We will recommend one of these — the one your results point to. If that is “nothing yet, revisit in six months”, we will say so, and we have said so before.

Assessments are reviewed by Dr. Mahdi Seify — PhD in AI-driven business analytics (University of Liverpool), MBA, ISO/IEC 27001 Lead Auditor and Lead Implementer, MIT Sloan AI Strategy, 100+ cross-sector projects.

The AIMS-42 methodology applies his ISO/IEC 27001 audit practice to the structure of ISO/IEC 42001. His certified credential is in ISO/IEC 27001; for ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005 and the EU AI Act the position is working knowledge, applied through that audit methodology. We state that precisely because a product that assesses conformity cannot be imprecise about its own author’s credentials.

Questions people actually ask

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the international management system standard for artificial intelligence. It sets out what an organisation must put in place to govern AI on an ongoing basis — across seven clauses of requirements and thirty-eight Annex A controls — in the same way ISO/IEC 27001 does for information security. It is certifiable, which means an accredited certification body can audit you against it and issue a certificate.

Can VisionXY7 certify us against ISO/IEC 42001?

No, and no consultancy can. Certification against ISO/IEC 42001 is issued only by an accredited certification body. VisionXY7 Ltd prepares organisations for certification audits; it does not perform them. What this assessment gives you is a maturity index, the status of the eight documents and processes a certification body looks for at Stage 1, and a control-by-control gap register. If a consultancy offers to certify you, they are describing something they are not able to do.

We are already certified to ISO/IEC 27001. Does that count for anything?

Substantially, yes. The management system machinery in Clauses 4 to 10 — context, leadership, planning, competence, internal audit, management review, corrective action — is shared across ISO management system standards. An organisation already certified to ISO/IEC 27001 or ISO 9001 typically already holds forty to sixty per cent of what ISO/IEC 42001 asks for, and the work becomes extension rather than construction. The assessment asks which certificates you hold and reflects that in the result.

How long does it take?

The Quick Check is fifteen questions and takes about eight minutes, with your result shown on screen immediately. The full Readiness Assessment covers every clause and every Annex A control across eight modules; its length adapts to your organisation’s role in the AI ecosystem — typically between 87 and 156 items — and it can be saved and resumed, so most people do it across two or three sittings.

Why can’t a self-assessment award the top maturity level?

The scale runs 0 to 4. Level 3, Operating, means documented, applied consistently and evidenced by records — the highest level anything self-reported can honestly reach. Level 4, Audit-evidenced, means independently verified against retained evidence with demonstrated improvement over time, and by definition that requires examination by a competent independent reviewer. A self-assessment awarding itself the top level would be describing something it has not done.

Who sees our answers?

Submissions go to VisionXY7 and are reviewed by Dr. Mahdi Seify. Consent for the report and consent for marketing are asked separately and either can be withdrawn. Answer data is stored separately from contact data. Records are kept for 24 months and then deleted. There is no third-party analytics, no pixel, no session recording and no chat widget on any questionnaire screen — this instrument asks you to disclose your own governance weaknesses, and you are entitled to check that nobody else is watching you do it.

What does the assessment never ask for?

Named individuals other than you, system names, vendor names, client names, or the details of any incident. The instrument asks whether a process exists — never what it found. That is a data protection decision and it is also the reason people answer honestly.

Find out in eight minutes.

Fifteen questions, your result on screen immediately, and the eight Stage 1 gates marked against what you have told us. No account, no card, no call.

Start the Quick Check
This is a self-assessment instrument. It records what you tell us about your own organisation. It does not verify, audit or certify anything, and it is not legal advice. Certification against ISO/IEC 42001 is issued only by an accredited certification body. VisionXY7 Ltd prepares organisations for certification audits; it does not perform them.