Free tool · ISO/IEC 42001:2023
ISO/IEC 42001 pre-audit self-check
Questions drawn straight from the clauses and Annex A controls of the standard, and only the ones that apply to the role you hold. It shows you where an auditor is likely to raise a finding, before one does.
Step 1
What does your organisation actually do with AI?
Clause 4.1 requires you to determine your role, and your role decides which Annex A controls apply. Tick everything that is true. Most organisations tick more than one.
Not sure? The AI Role Selector walks through it properly.
Step 2
Where do you stand against the standard?
Answer honestly. A self-check that flatters you is worth nothing at a Stage 1 audit. “Partly” means it exists but is not documented, not approved, or not being followed.
What an auditor is likely to raise
How to read your level
This five level scale is Cianaa’s own, written in audit terms. ISO/IEC 42001 does not define maturity levels. It is a way of describing how far a control has travelled, from a practice that happens informally to one that is documented, operating and improving.
What this tool is, and what it is not
This is a self-assessment you complete yourself. It is not an audit, it is not a gap analysis we performed, and it does not commit us to any finding at a real audit. Cianaa is an independent certification body, so we will not write your policies, build your risk register or prepare your Statement of Applicability, and we will not certify a management system we helped create. What we can tell you is what the standard requires and what an auditor will ask to see. That is what this tool does.
Found gaps? That is what a pre-audit is for.
A pre-audit is an independent look at where you stand before the certification audit begins, carried out by the same lead auditors who conducted the audit behind New Zealand’s first ISO/IEC 42001 certification.
