ISO 42001 AI Governance Audit
This skill enables AI agents to perform a comprehensive AI governance readiness and gap assessment based on ISO/IEC 42001:2023 - the international standard for Artificial Intelligence Management Systems (AIMS).
ISO 42001 provides a framework for responsible development, deployment, and use of AI systems, addressing risks, ethics, security, transparency, and regulatory compliance.
Use this skill to evaluate whether AI projects follow international best practices, manage risks effectively, and maintain ethical standards throughout the AI lifecycle.
Certification boundary: This skill can prepare evidence and identify gaps, but it is not a certification audit. Do not claim ISO/IEC 42001 conformance unless a qualified auditor or certification process verifies it.
Combine with security audits, code reviews, or ethical AI assessments for comprehensive AI system evaluation.
When to Use This Skill
Invoke this skill when:
- Developing or integrating AI systems
- Ensuring AI governance and compliance
- Managing AI risks and ethical concerns
- Preparing for AI regulatory requirements (EU AI Act, etc.)
- Auditing existing AI implementations
- Establishing AI governance frameworks
- Responding to AI security or bias incidents
- Planning responsible AI deployment
- Documenting AI systems for stakeholders
Inputs Required
When executing this audit, gather:
- ai_system_description: Detailed description (purpose, capabilities, data used, users affected, deployment context) [REQUIRED]
- use_case: Specific application (e.g., hiring tool, medical diagnosis, content moderation) [REQUIRED]
- risk_category: High-risk, limited-risk, or minimal-risk per EU AI Act classification [OPTIONAL but recommended]
- existing_documentation: Technical docs, data sheets, model cards, risk assessments [OPTIONAL]
- stakeholders: Who develops, deploys, uses, and is affected by the AI [OPTIONAL]
- regulatory_context: Applicable laws (GDPR, EU AI Act, industry regulations) [OPTIONAL]
- impact_assessment_context: Existing or needed AI impact assessments, especially for systems affecting individuals, groups, or society [OPTIONAL]
ISO 42001 Framework Overview
ISO 42001 is structured around 10 key clauses plus supporting annexes:
Core Clauses
- Scope - Define AIMS boundaries
- Normative References - Related standards
- Terms and Definitions - AI terminology
- Context of Organization - Internal/external factors
- Leadership - Management commitment and roles
- Planning - Objectives and risk management
- Support - Resources, competence, communication
- Operation - AI system lifecycle management
- Performance Evaluation - Monitoring and measurement
- Improvement - Continual enhancement
Key ISO 42001 Principles
1. Risk-Based Approach
- Identify, assess, and mitigate AI-specific risks
- Consider technical, ethical, legal, and social risks
- Proportionate controls based on risk level
2. Ethical AI
- Fairness and non-discrimination
- Transparency and explainability
- Human oversight and control
- Privacy and data protection
- Accountability
3. Lifecycle Management
- Design → Development → Deployment → Monitoring → Decommissioning
- Continuous evaluation and improvement
- Documentation throughout
4. Stakeholder Engagement
- Involve affected parties
- Clear communication about AI use
- Mechanisms for feedback and redress
Related ISO AI Standards
Use ISO/IEC 42001 as the management-system anchor. When the request focuses on social, human, environmental, or lifecycle impact assessment, also reference ISO/IEC 42005:2025 as a companion standard for AI system impact assessments. When the request focuses on risk methodology, consider ISO/IEC 23894 as supporting guidance.
Audit Procedure
Work through seven steps, each mapped to ISO 42001 clauses. The full control-by-control
checklists — evaluation questions, scoring rubrics, example risks, and the seven AI
lifecycle stages — live in references/audit-procedure.md.
Read the section for the step you are on rather than loading the whole file at once.
| Step |
Focus |
ISO 42001 Clause |
Est. |
| 1. Context & Scope |
AIMS boundaries, stakeholders, EU AI Act risk classification |
4 |
15 min |
| 2. Leadership & Governance |
Management commitment, AI policy, roles & responsibilities |
5 |
20 min |
| 3. Planning & Risk Management |
Risk categories, assessment process, AI objectives |
6 |
30 min |
| 4. Support & Resources |
Resources, competence, awareness, communication, documentation |
7 |
20 min |
| 5. Operation (AI Lifecycle) |
Design → data → development → validation → deployment → monitoring → decommissioning |
8 |
40 min |
| 6. Performance Evaluation |
KPIs, internal audit, management review |
9 |
20 min |
| 7. Improvement |
Nonconformity, corrective action, continual improvement (PDCA) |
10 |
15 min |
For each step: evaluate the documented controls, record evidence vs. gaps, assign a
clause score (0–10), and carry the findings into the report.
Output Format
Assemble findings into the standard ISO 42001 audit report. The copy-ready template
and a clause-by-clause self-assessment checklist are in
references/report-template.md.
The report covers, in order:
- Executive Summary — overall conformance, per-clause status table, risk classification, top 5 critical findings, positive highlights
- Detailed Findings — clause-by-clause analysis with evidence, gaps, and recommendations
- Risk Assessment Summary — critical/high risks with controls, owners, and deadlines
- Compliance Roadmap — phased actions (0–3 / 3–6 / 6–12 months)
- Documentation Requirements — missing artifacts to create
- Recommendations by Stakeholder — leadership, AI teams, legal/compliance, operations
- Next Steps — immediate through long-term
- Appendices — checklist, risk register, glossary, references
Best Practices
- Start with Risk Assessment: Prioritize based on AI risk level
- Document Everything: ISO 42001 requires extensive documentation
- Engage Stakeholders Early: Include affected parties in governance
- Use Existing Frameworks: Leverage NIST AI RMF, EU AI Act requirements
- Automate Monitoring: Build MLOps with governance built-in
- Train Your Team: ISO 42001 requires competent personnel
- Regular Audits: Don't wait for problems—proactive reviews
- Learn from Incidents: Every issue is improvement opportunity
- Balance Innovation and Safety: Responsible AI doesn't mean no AI
- Seek Independent Review When Needed: Third-party ISO 42001 certification can add credibility, but this skill only supports readiness and evidence preparation
Regulatory Alignment
ISO 42001 aligns with major AI regulations:
EU AI Act:
- Risk classification framework
- High-risk AI obligations
- Transparency requirements
- Conformity assessment
GDPR:
- Data protection by design
- Privacy impact assessments
- Data subject rights
- Lawful processing
NIST AI RMF:
- Govern, Map, Measure, Manage functions
- Risk-based approach
- Trustworthy AI characteristics
ISO/IEC 42005:2025:
- AI system impact assessment
- Human, social, and environmental impacts across the lifecycle
- Transparent documentation of foreseeable impacts
Sector-Specific:
- Healthcare: FDA AI/ML guidance, MDR
- Finance: Model Risk Management (SR 11-7)
- Employment: EEOC AI guidance
Common Pitfalls
- "We'll add governance later" - Build it in from the start
- Treating ISO 42001 as one-time exercise - It's continual
- Documentation without implementation - Must be operational
- Ignoring low-risk AI - Even minimal-risk needs baseline governance
- No stakeholder engagement - Affected parties must be involved
- Insufficient resources - Responsible AI requires investment
- Lack of monitoring - Deploy-and-forget is non-compliant
- No incident response plan - When AI fails, you need a plan
- Training as checkbox - Teams must truly understand responsible AI
- Copying templates without customization - Tailor to your context
Version
1.0 - Initial release based on ISO/IEC 42001:2023
Remember: ISO 42001 is about building trustworthy AI systems through systematic risk management and governance. It's not a barrier to innovation—it's a framework for responsible innovation that protects both organizations and the people affected by AI.
1---2name: iso-42001-ai-governance3description: AI governance readiness and gap assessment using ISO/IEC 42001:2023. Evaluate AI management-system practices for risk management, accountability, transparency, security, and continuous improvement.4---5
6# ISO 42001 AI Governance Audit
7
8This skill enables AI agents to perform a comprehensive **AI governance readiness and gap assessment** based on **ISO/IEC 42001:2023** - the international standard for Artificial Intelligence Management Systems (AIMS).
9
10ISO 42001 provides a framework for responsible development, deployment, and use of AI systems, addressing risks, ethics, security, transparency, and regulatory compliance.
11
12Use this skill to evaluate whether AI projects follow international best practices, manage risks effectively, and maintain ethical standards throughout the AI lifecycle.
13
14**Certification boundary**: This skill can prepare evidence and identify gaps, but it is not a certification audit. Do not claim ISO/IEC 42001 conformance unless a qualified auditor or certification process verifies it.
15
16Combine with security audits, code reviews, or ethical AI assessments for comprehensive AI system evaluation.
17
18## When to Use This Skill
19
20Invoke this skill when:
21- Developing or integrating AI systems
22- Ensuring AI governance and compliance
23- Managing AI risks and ethical concerns
24- Preparing for AI regulatory requirements (EU AI Act, etc.)
25- Auditing existing AI implementations
26- Establishing AI governance frameworks
27- Responding to AI security or bias incidents
28- Planning responsible AI deployment
29- Documenting AI systems for stakeholders
30
31## Inputs Required
32
33When executing this audit, gather:
34
35- **ai_system_description**: Detailed description (purpose, capabilities, data used, users affected, deployment context) [REQUIRED]
36- **use_case**: Specific application (e.g., hiring tool, medical diagnosis, content moderation) [REQUIRED]
37- **risk_category**: High-risk, limited-risk, or minimal-risk per EU AI Act classification [OPTIONAL but recommended]
38- **existing_documentation**: Technical docs, data sheets, model cards, risk assessments [OPTIONAL]
39- **stakeholders**: Who develops, deploys, uses, and is affected by the AI [OPTIONAL]
40- **regulatory_context**: Applicable laws (GDPR, EU AI Act, industry regulations) [OPTIONAL]
41- **impact_assessment_context**: Existing or needed AI impact assessments, especially for systems affecting individuals, groups, or society [OPTIONAL]
42
43## ISO 42001 Framework Overview
44
45ISO 42001 is structured around **10 key clauses** plus supporting annexes:
46
47### Core Clauses
48
491. **Scope** - Define AIMS boundaries
502. **Normative References** - Related standards
513. **Terms and Definitions** - AI terminology
524. **Context of Organization** - Internal/external factors
535. **Leadership** - Management commitment and roles
546. **Planning** - Objectives and risk management
557. **Support** - Resources, competence, communication
568. **Operation** - AI system lifecycle management
579. **Performance Evaluation** - Monitoring and measurement
5810. **Improvement** - Continual enhancement
59
60### Key ISO 42001 Principles
61
62#### 1. Risk-Based Approach
63- Identify, assess, and mitigate AI-specific risks
64- Consider technical, ethical, legal, and social risks
65- Proportionate controls based on risk level
66
67#### 2. Ethical AI
68- Fairness and non-discrimination
69- Transparency and explainability
70- Human oversight and control
71- Privacy and data protection
72- Accountability
73
74#### 3. Lifecycle Management
75- Design → Development → Deployment → Monitoring → Decommissioning
76- Continuous evaluation and improvement
77- Documentation throughout
78
79#### 4. Stakeholder Engagement
80- Involve affected parties
81- Clear communication about AI use
82- Mechanisms for feedback and redress
83
84### Related ISO AI Standards
85
86Use ISO/IEC 42001 as the management-system anchor. When the request focuses on social, human, environmental, or lifecycle impact assessment, also reference **ISO/IEC 42005:2025** as a companion standard for AI system impact assessments. When the request focuses on risk methodology, consider ISO/IEC 23894 as supporting guidance.
87
88---
89
90## Audit Procedure
91
92Work through seven steps, each mapped to ISO 42001 clauses. The full control-by-control
93checklists — evaluation questions, scoring rubrics, example risks, and the seven AI
94lifecycle stages — live in **[`references/audit-procedure.md`](references/audit-procedure.md)**.
95Read the section for the step you are on rather than loading the whole file at once.
96
97| Step | Focus | ISO 42001 Clause | Est. |
98|------|-------|------------------|------|
99| 1. Context & Scope | AIMS boundaries, stakeholders, EU AI Act risk classification | 4 | 15 min |
100| 2. Leadership & Governance | Management commitment, AI policy, roles & responsibilities | 5 | 20 min |
101| 3. Planning & Risk Management | Risk categories, assessment process, AI objectives | 6 | 30 min |
102| 4. Support & Resources | Resources, competence, awareness, communication, documentation | 7 | 20 min |
103| 5. Operation (AI Lifecycle) | Design → data → development → validation → deployment → monitoring → decommissioning | 8 | 40 min |
104| 6. Performance Evaluation | KPIs, internal audit, management review | 9 | 20 min |
105| 7. Improvement | Nonconformity, corrective action, continual improvement (PDCA) | 10 | 15 min |
106
107For each step: evaluate the documented controls, record evidence vs. gaps, assign a
108clause score (0–10), and carry the findings into the report.
109
110---
111
112## Output Format
113
114Assemble findings into the standard ISO 42001 audit report. The copy-ready template
115and a clause-by-clause self-assessment checklist are in
116**[`references/report-template.md`](references/report-template.md)**.
117
118The report covers, in order:
119
1201. **Executive Summary** — overall conformance, per-clause status table, risk classification, top 5 critical findings, positive highlights
1212. **Detailed Findings** — clause-by-clause analysis with evidence, gaps, and recommendations
1223. **Risk Assessment Summary** — critical/high risks with controls, owners, and deadlines
1234. **Compliance Roadmap** — phased actions (0–3 / 3–6 / 6–12 months)
1245. **Documentation Requirements** — missing artifacts to create
1256. **Recommendations by Stakeholder** — leadership, AI teams, legal/compliance, operations
1267. **Next Steps** — immediate through long-term
1278. **Appendices** — checklist, risk register, glossary, references
128
129---
130
131## Best Practices
132
1331. **Start with Risk Assessment**: Prioritize based on AI risk level
1342. **Document Everything**: ISO 42001 requires extensive documentation
1353. **Engage Stakeholders Early**: Include affected parties in governance
1364. **Use Existing Frameworks**: Leverage NIST AI RMF, EU AI Act requirements
1375. **Automate Monitoring**: Build MLOps with governance built-in
1386. **Train Your Team**: ISO 42001 requires competent personnel
1397. **Regular Audits**: Don't wait for problems—proactive reviews
1408. **Learn from Incidents**: Every issue is improvement opportunity
1419. **Balance Innovation and Safety**: Responsible AI doesn't mean no AI
14210. **Seek Independent Review When Needed**: Third-party ISO 42001 certification can add credibility, but this skill only supports readiness and evidence preparation
143
144---
145
146## Regulatory Alignment
147
148ISO 42001 aligns with major AI regulations:
149
150**EU AI Act:**
151- Risk classification framework
152- High-risk AI obligations
153- Transparency requirements
154- Conformity assessment
155
156**GDPR:**
157- Data protection by design
158- Privacy impact assessments
159- Data subject rights
160- Lawful processing
161
162**NIST AI RMF:**
163- Govern, Map, Measure, Manage functions
164- Risk-based approach
165- Trustworthy AI characteristics
166
167**ISO/IEC 42005:2025:**
168- AI system impact assessment
169- Human, social, and environmental impacts across the lifecycle
170- Transparent documentation of foreseeable impacts
171
172**Sector-Specific:**
173- Healthcare: FDA AI/ML guidance, MDR
174- Finance: Model Risk Management (SR 11-7)
175- Employment: EEOC AI guidance
176
177---
178
179## Common Pitfalls
180
1811. **"We'll add governance later"** - Build it in from the start
1822. **Treating ISO 42001 as one-time exercise** - It's continual
1833. **Documentation without implementation** - Must be operational
1844. **Ignoring low-risk AI** - Even minimal-risk needs baseline governance
1855. **No stakeholder engagement** - Affected parties must be involved
1866. **Insufficient resources** - Responsible AI requires investment
1877. **Lack of monitoring** - Deploy-and-forget is non-compliant
1888. **No incident response plan** - When AI fails, you need a plan
1899. **Training as checkbox** - Teams must truly understand responsible AI
19010. **Copying templates without customization** - Tailor to your context
191
192---
193
194## Version
195
1961.0 - Initial release based on ISO/IEC 42001:2023
197
198---
199
200**Remember**: ISO 42001 is about building trustworthy AI systems through systematic risk management and governance. It's not a barrier to innovation—it's a framework for responsible innovation that protects both organizations and the people affected by AI.
201