Using AI at work? Check you're managing it properly.
Staff are already using AI tools, often without anyone deciding the rules. ISO/IEC 42001 is the first international standard for managing AI responsibly, and it's what clients, investors and regulators are starting to ask about. This check shows how your business measures up.
36 questions · about 15 minutes · no card needed
This is for you if…
- Your team uses tools like ChatGPT or Copilot, or AI features in software you buy
- You build or resell anything with AI in it
- You use AI in decisions about people: credit scoring, fraud checks, screening applicants
- A client, investor or regulator has asked about your AI governance
What you get
- A score across the 9 areas of Annex A, plus the core management clauses
- Extra weight on data and lifecycle questions, where the real risk sits
- A prioritised action list, starting with an inventory of the AI you already use
What the questions cover
One area per screen, each with a handful of yes, no or partly questions.
Leadership, objectives and improvement
The core management basics (clauses 4 to 10): who's in charge of AI, what you're aiming for, and how you get better.
5 questions
AI policies
Annex A.2: the written rules for how your business uses AI.
3 questions
Internal organisation
Annex A.3: who does what, and how people raise concerns.
3 questions
Resources for AI systems
Annex A.4: knowing what each AI tool depends on.
4 questions
Impact assessment
Annex A.5: thinking through how AI could affect people and society.
4 questions
AI system lifecycle
Annex A.6: managing AI tools from planning to retirement.
5 questions
Data for AI systems
Annex A.7: the quality, source and handling of data used by AI.
5 questions
Information for interested parties
Annex A.8: being open with customers and others about your AI use.
4 questions
Third-party relationships
Annex A.10: managing AI suppliers and partners.
3 questions
Common questions
We only use ChatGPT now and then. Does this apply to us?
Yes, and that's often where the risk hides. Staff pasting customer or staff details into a public AI tool is a privacy problem too, under POPIA in South Africa, the NDPA in Nigeria or Kenya's Data Protection Act. The assessment starts with what you're actually using.
Do we need ISO 42001 by law?
No. It's a voluntary standard, not a law. But it's fast becoming what clients and investors ask for, and it lines up with privacy laws across Africa and with the EU AI Act. Some regulators are going further: Nigeria is moving towards licensing and yearly impact assessments for high-risk AI.
How does it relate to ISO 27001?
They fit together. ISO 27001 covers information security, ISO 42001 covers how AI is governed. If you've done the security work, a lot of it counts here too.
More answers in the help centre.
Ready to see where you stand?
Free 14-day Pro trial, no card needed. You'll have a score and an action list in about 15 minutes.
Start the free checkAlso available: ISO/IEC 27001 readiness