How ready is your organisation to build an AIMS? | Free Download

September 2, 2026

ISO/IEC 42001 implementation is easier when the basic governance foundations are already in place. 


This short downloadable checklist gives you an initial sense of what your organisation has, before moving into a more detailed assessment. 


This checklist is an early planning tool. A high score does not confirm conformity with ISO/IEC 42001

Download the ISO/IEC 42001 Readiness Checklist

Visibility and scope

Do you know where AI is currently being developed, provided or used, including AI features built into third-party software? 

Leadership and responsibility

Is somebody clearly responsible for AI governance and for coordinating the development of the Artificial Intelligence Management System? 

Risk and impact

Does your organisation have a consistent way to examine the risks created by its AI systems and how those systems could affect people?

Lifecycle controls

Are AI systems reviewed before they’re introduced, and does appropriate oversight continue once they’re in use? 

Skills and evidence

Do the people involved understand their responsibilities? Can the organisation also explain important decisions through reliable records? 

Monitoring and improvement

Would your organisation know if an AI system began behaving unexpectedly? 

If several of these questions are difficult to answer, some of the foundations needed for ISO/IEC 42001 implementation may still need attention. 


The full ISO/IEC 42001 Readiness Checklist includes 24 questions, with a scoring guide to help you identify areas that need attention. 

Download the ISO/IEC 42001 Readiness Checklist

Share this article

alt=
September 1, 2026
If your organisation only uses third-party AI models, are you still responsible for the governance and oversight of that tool? Safeshield breaks down the answer.
September 1, 2026
A large part of AI governance involves systems the organisation didn’t build. Businesses increasingly rely on AI provided through external software, which creates a different governance challenge from working with technology developed entirely in-house. The organisation may have limited visibility into the underlying model, and some information may simply be unavailable. That doesn’t make effective governance impossible. It changes what the organisation can control and, as a result, the questions an AI GRC professional needs to ask. Understanding that distinction is useful for anyone learning how AI governance works in practice.
alt=
August 17, 2026
What is an impact assessment, what does it cover, and how does it help with ISO/IEC 42001? The Safeshield team answers all these questions. Includes downloadable checklist
More Posts