ISO/IEC 42001 is the international standard for AI management systems — seven clauses of requirements and thirty-eight controls. This assessment is mapped directly to them, and tells you which of the eight things a certification body looks for at Stage 1 you could actually produce.
15 questions · about 8 minutes · your result on screen immediately, no waiting and no call required.
The Quick Check tests the fifteen points that best predict how the other one hundred and forty behave. The full assessment examines all of them.
The full assessment opens from your Quick Check result, so nothing you answer is asked twice.
Not sure ISO/IEC 42001 is your question yet? If AI is in use across your organisation but nobody has been made responsible for it, a management system standard is the wrong place to start. The free AI Readiness Assessment is the better first move — it asks whether anyone is governing AI at all, which is the question underneath this one.
Eight domains, each carrying a stated weight in the maturity index. The weights are published here rather than hidden, because a score whose derivation you cannot see is not a finding — it is a number.
| Domain | What it covers in the standard | Weight |
|---|---|---|
| Planning & Risk Management | Clauses 6.1.1–6.1.3, 6.2, 6.3, 8.2, 8.3 — risk criteria, the AI risk assessment, the Statement of Applicability, objectives | 18% |
| Context & Leadership | Clauses 4–5 and Annex A.2, A.3 — scope, the AI policy, accountability, roles, the route to raise a concern | 15% |
| AI Lifecycle Controls | Clause 8.1 and Annex A.6, A.9 — approval before go-live, change control, monitoring in production, human oversight | 15% |
| AI Impact Assessment | Clauses 6.1.4, 8.4 and Annex A.5 — the effect on the individuals and groups your AI touches | 12% |
| Data Governance | Annex A.4.3, A.7 — data inventory, provenance, quality requirements and how they are checked | 12% |
| Resources & Competence | Clause 7 and Annex A.4 — people, skills, awareness, documented information | 10% |
| Performance & Improvement | Clauses 9–10 — internal audit, management review, nonconformity and corrective action | 10% |
| Transparency & Third Parties | Annex A.8, A.10 — what affected people are told, supplier due diligence, contractual AI requirements | 8% |
Every item is scored against the same five-level scale. Four of those levels are available to you here. The fifth is not, and the reason is the whole argument for taking this seriously.
The requirement is not addressed in any form.
Happens informally, depends on individuals, not written down or owned.
Documented, but not yet approved, communicated, or consistently applied.
Documented, applied consistently, and evidenced by records. The highest level a self-assessment can award.
Independently verified against retained evidence, with demonstrated improvement over time. Cannot be self-awarded.
A Stage 1 audit is largely a documentation review. These eight are what it reviews. The assessment reports each one as Met, Partial, Open or Unknown — on what you have told us — so you can see which of them you could put in front of an auditor today.
A written statement of which parts of the organisation, which locations and which AI systems your management system covers.
Approved by top management, covering both the development and the use of AI, communicated and available.
A defined and repeatable method, applied across your AI systems, with records that show it was applied.
Every Annex A control listed, with justification for what you include and what you exclude. Without it there is nothing to audit against.
The effect on individuals and groups your AI systems touch — not the effect on the business.
A programme, carried out, with findings recorded — your own check before somebody else’s.
Top management formally reviewing the management system, with a recorded decision trail.
When something goes wrong, a defined process that treats it as an incident and fixes the cause.
Information, not a pitch. Both assessments are free to complete and you are under no obligation to do anything with either.
| Step | What it is | Price |
|---|---|---|
| You are here — ISO/IEC 42001 Quick Check | Live scored result, eight-gate status, one recommended next step. | Free |
| Readiness Assessment | All seven clauses, all thirty-eight controls, full gap register, phased roadmap, personally reviewed. | Free to complete |
| Gap Review | Your assessment worked through with Dr. Seify, remotely, and the register turned into a sequenced plan with owners and dates. | Scoped per engagement |
| ISMS-to-AIMS Extension | For organisations already certified to ISO/IEC 27001 or ISO 9001 — mapping what you already hold onto what ISO/IEC 42001 adds. | Scoped per engagement |
| Governance Build | AI policy, risk criteria, risk assessment, Statement of Applicability, impact assessment process, internal audit programme — the Stage 1 document set, built with you. | Scoped per engagement |
| Certification Readiness | Pre-audit review against evidence, internal audit cycle, management review, and support through Stage 1 and Stage 2 with your chosen certification body. VisionXY7 does not certify. | Scoped per engagement |
| Fractional Chief AI Officer | Ongoing ownership of AI governance where the organisation has no natural home for it. | See mahdiseify.com → |
Assessments are reviewed by Dr. Mahdi Seify — PhD in AI-driven business analytics (University of Liverpool), MBA, ISO/IEC 27001 Lead Auditor and Lead Implementer, MIT Sloan AI Strategy, 100+ cross-sector projects.
The AIMS-42 methodology applies his ISO/IEC 27001 audit practice to the structure of ISO/IEC 42001. His certified credential is in ISO/IEC 27001; for ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005 and the EU AI Act the position is working knowledge, applied through that audit methodology. We state that precisely because a product that assesses conformity cannot be imprecise about its own author’s credentials.
ISO/IEC 42001:2023 is the international management system standard for artificial intelligence. It sets out what an organisation must put in place to govern AI on an ongoing basis — across seven clauses of requirements and thirty-eight Annex A controls — in the same way ISO/IEC 27001 does for information security. It is certifiable, which means an accredited certification body can audit you against it and issue a certificate.
No, and no consultancy can. Certification against ISO/IEC 42001 is issued only by an accredited certification body. VisionXY7 Ltd prepares organisations for certification audits; it does not perform them. What this assessment gives you is a maturity index, the status of the eight documents and processes a certification body looks for at Stage 1, and a control-by-control gap register. If a consultancy offers to certify you, they are describing something they are not able to do.
Substantially, yes. The management system machinery in Clauses 4 to 10 — context, leadership, planning, competence, internal audit, management review, corrective action — is shared across ISO management system standards. An organisation already certified to ISO/IEC 27001 or ISO 9001 typically already holds forty to sixty per cent of what ISO/IEC 42001 asks for, and the work becomes extension rather than construction. The assessment asks which certificates you hold and reflects that in the result.
The Quick Check is fifteen questions and takes about eight minutes, with your result shown on screen immediately. The full Readiness Assessment covers every clause and every Annex A control across eight modules; its length adapts to your organisation’s role in the AI ecosystem — typically between 87 and 156 items — and it can be saved and resumed, so most people do it across two or three sittings.
The scale runs 0 to 4. Level 3, Operating, means documented, applied consistently and evidenced by records — the highest level anything self-reported can honestly reach. Level 4, Audit-evidenced, means independently verified against retained evidence with demonstrated improvement over time, and by definition that requires examination by a competent independent reviewer. A self-assessment awarding itself the top level would be describing something it has not done.
Submissions go to VisionXY7 and are reviewed by Dr. Mahdi Seify. Consent for the report and consent for marketing are asked separately and either can be withdrawn. Answer data is stored separately from contact data. Records are kept for 24 months and then deleted. There is no third-party analytics, no pixel, no session recording and no chat widget on any questionnaire screen — this instrument asks you to disclose your own governance weaknesses, and you are entitled to check that nobody else is watching you do it.
Named individuals other than you, system names, vendor names, client names, or the details of any incident. The instrument asks whether a process exists — never what it found. That is a data protection decision and it is also the reason people answer honestly.
Fifteen questions, your result on screen immediately, and the eight Stage 1 gates marked against what you have told us. No account, no card, no call.
Start the Quick Check