Free tool · ISO/IEC 42001:2023

ISO/IEC 42001 pre-audit self-check

Questions drawn straight from the clauses and Annex A controls of the standard, and only the ones that apply to the role you hold. It shows you where an auditor is likely to raise a finding, before one does.

23 to 34 questions About 10 minutes Nothing is submitted anywhere Runs entirely in your browser Tailored to the role you hold

Step 1

What does your organisation actually do with AI?

Clause 4.1 requires you to determine your role, and your role decides which Annex A controls apply. Tick everything that is true. Most organisations tick more than one.

Not sure? The AI Role Selector walks through it properly.

Step 2

Where do you stand against the standard?

Answer honestly. A self-check that flatters you is worth nothing at a Stage 1 audit. “Partly” means it exists but is not documented, not approved, or not being followed.

Optional. Used only to title your printed report. Nothing is sent anywhere.

What an auditor is likely to raise

Your likely findings will appear here as you answer.

How to read your level

This five level scale is Cianaa’s own, written in audit terms. ISO/IEC 42001 does not define maturity levels. It is a way of describing how far a control has travelled, from a practice that happens informally to one that is documented, operating and improving.

1AbsentNot in place. An auditor would raise a nonconformity.
2InformalIt happens in practice, but nothing is written down or approved.
3DocumentedWritten and approved. Stage 1 looks for exactly this.
4OperatingBeing followed, with records an auditor can sample. Stage 2 tests this.
5EmbeddedMonitored, reviewed and improved. Surveillance audits stay comfortable.

What this tool is, and what it is not

This is a self-assessment you complete yourself. It is not an audit, it is not a gap analysis we performed, and it does not commit us to any finding at a real audit. Cianaa is an independent certification body, so we will not write your policies, build your risk register or prepare your Statement of Applicability, and we will not certify a management system we helped create. What we can tell you is what the standard requires and what an auditor will ask to see. That is what this tool does.

Found gaps? That is what a pre-audit is for.

A pre-audit is an independent look at where you stand before the certification audit begins, carried out by the same lead auditors who conducted the audit behind New Zealand’s first ISO/IEC 42001 certification.