# Free ISO 42001 Readiness Check: Score Your AI Management System

> A free ISO/IEC 42001 readiness assessment. Twenty questions mapped to the clauses and Annex A controls, a score out of 100, every gap named with the action that closes it. Five minutes, no sign-up.

- Canonical: https://sentrysolutions.ai/iso-42001/readiness-check

# The free ISO 42001 readiness check

Twenty questions an auditor will ask, each mapped to the ISO/IEC 42001 clause or Annex A control it comes from. A score out of 100, every gap named with the action that closes it, five minutes, no sign-up.

[Start the check](#readiness-checker) [How we run ours](https://sentrysolutions.ai/iso-42001/how-we-run-ours)

The short answer

The Sentry AI ISO 42001 readiness check is a free self-assessment of an AI management system against ISO/IEC 42001:2023. It asks twenty questions across scope, leadership, risk and impact assessment, support, operation, monitoring, internal audit and management review, scores the answers out of 100 into four bands from “Start with the inventory” to “Ready for Stage 1”, and names every gap with the action that closes it. It runs in the browser with no sign-up. The score is Sentry AI's weighting, not a certification body's.

ISO 42001 readiness check · free0/20

### Twenty questions an auditor will ask

Each one maps to the clause or Annex A control it comes from. Answer honestly rather than aspirationally: the gap between what leadership believes is running and what is actually running is the finding that usually starts the programme. The score is computed in your browser. Nothing is sent anywhere unless you ask for the report by email.

Clause 4, context and scope

1. Is the boundary of what your AI management system covers written down, including which parts of the business are out of scope?

Clause 5, leadership

2. Is there an AI policy that a named executive has approved, rather than a template nobody signed?

Clause 5, leadership

3. Is one person accountable for AI across the organisation, with the authority to stop a system?

Clause 6 and Annex A, AI inventory

4. Do you have a single register of every AI system in use, including tools bought on a credit card and agents a team stood up quietly?

Annex A, accountability

5. Does each entry in that register name an owner who knows they own it?

Clause 6.1, risk assessment

6. Has each significant AI system been risk assessed for bias, explainability, data exposure and inappropriate autonomy?

Clause 6.1.4, AI system impact assessment

7. Have you assessed the impact on the people subject to automated decisions, not just the risk to the organisation?

Clause 6.2, objectives

8. Are there measurable AI objectives, so someone can say at review whether the system is working?

Clause 7.2, competence

9. Are training records kept for the people who operate or oversee AI systems?

Clause 7.5, documented information

10. Is your documentation version controlled, with a clear current version of every policy and procedure?

Clause 8 and Annex A, lifecycle

11. Is there a defined path a new AI system follows from proposal through approval, deployment and eventual retirement?

Clause 8, operational control

12. Are approvals recorded at the time a decision is made, rather than reconstructed later?

Annex A, human oversight

13. Does anything consequential, spending money, sending externally or changing a customer record, pass a person before it happens?

Annex A, human oversight

14. Can every AI system be stopped, by someone who knows they hold that switch and has tested it?

Annex A, data for AI systems

15. Do you know what data each system may touch, where it is processed, and which actions it must never take?

Clause 8 and Annex A, third parties

16. Have you read what your AI suppliers commit to on training, retention and data residency?

Clause 9.1, monitoring

17. Is what your AI systems actually do monitored in production, rather than assumed from the specification?

Clause 9, evidence

18. Could you show an auditor months of operating evidence, not just the policies?

Clause 9.2, internal audit

19. Has an internal audit of the AI management system been run at least once?

Clause 9.3 and 10, review and improvement

20. Does leadership formally review the AI management system on a schedule, with corrective actions tracked to closure?

## How the score works

Each answer scores one for yes, a half for in part and nothing for no, and the total is scaled to 100. Every question carries the same weight, because an auditor does not grade on a curve: a missing inventory is a nonconformity whether or not the policy is beautifully written. The four bands are ours, set from what we have seen it take to reach a Stage 1 audit, and they are not a prediction of any audit outcome.

Score

Band

What it usually means

85 and above

Ready for Stage 1

On this evidence a Stage 1 audit would be a documentation review rather than a discovery exercise. The work left is usually depth of evidence, not missing structure.

60 to 84

Close, with gaps

The structure exists and the gaps are specific. Most organisations here are four to six months out, and the binding constraint is operating evidence rather than paperwork.

35 to 59

Foundations underway

Real pieces are in place and the management system is not yet one system. Fix the inventory and the accountability first: nearly everything else in the standard reads off those two.

0 to 34

Start with the inventory

Nothing here is unusual for an organisation that has been using AI faster than it has been governing it. You cannot scope, risk assess or certify what has not been listed, so the register is the first and only place to start.

## Getting the most out of it

### Answer for today, not the plan

Score what is actually running. A policy written but not followed is an in part at best. The gap between what leadership believes and what is running is the finding that usually starts the programme.

### Have two people take it

Have the person accountable for AI and the person who runs the systems answer separately, then compare the share links. Where they disagree is where an auditor will look first.

### Work the gaps in order

Inventory and accountability first, because everything else reads off them. Then risk and impact assessment, then the operating controls, then the evidence, the internal audit and the management review.

### Take it again in a month

The score moves when records exist, not when documents are written. Retaking it monthly is a fair measure of whether the management system is running or only described.

## Built by a team doing it to itself

We run our own information security management system on agents, with every risk, control, decision and piece of evidence in a register, and our ISO 42001 work runs on the same control set. The twenty questions are the ones we had to answer ourselves. [Here is how we run ours, with the real numbers](https://sentrysolutions.ai/iso-42001/how-we-run-ours). For the process from here to a certificate, read [ISO 42001 certification in Australia and NZ](https://sentrysolutions.ai/iso-42001/certification).

Sentry AI is not a certification body and does not hold ISO 42001 yet. We prepare organisations for certification; an accredited body certifies them.

More on ISO 42001

-   [ISO/IEC 42001 explained, with the readiness checklist](https://sentrysolutions.ai/iso-42001)
-   [How we run our own management system, with agents](https://sentrysolutions.ai/iso-42001/how-we-run-ours)
-   [ISO 42001 certification in Australia and NZ](https://sentrysolutions.ai/iso-42001/certification)
-   [ISO 42001 for Claude and Copilot rollouts](https://sentrysolutions.ai/iso-42001/claude-and-copilot)
-   [ISO 42001 vs the NIST AI RMF](https://sentrysolutions.ai/iso-42001/vs-nist-ai-rmf)
-   [AI governance, the service](https://sentrysolutions.ai/ai-governance)

## Frequently asked questions

### Is the ISO 42001 readiness check free?

Yes. It is free, it needs no sign-up, and it shows your score and your gaps on screen. The questions are answered and scored in your browser. Nothing is sent to us unless you choose to have the full gap report emailed to you.

### How long does the readiness check take?

About five minutes. There are twenty questions, each answered yes, in part or no. Answer for what is actually running today, not for what is planned or written in a policy nobody follows.

### What does the readiness check cover?

The clauses of ISO/IEC 42001:2023 an auditor tests (scope, leadership, planning, risk and impact assessment, support, operation, monitoring, internal audit, management review) and the Annex A controls behind human oversight, the AI inventory, data for AI systems, the AI system lifecycle and third-party suppliers. Every question is labelled with the clause or control it comes from.

### Does a high score mean we will pass certification?

No. The score is our own weighting of how much of the management system you have in place. Only an accredited certification body can decide whether you pass, after a Stage 1 and a Stage 2 audit. A high score means a Stage 1 audit is likely to be a documentation review rather than a discovery exercise.

### What should we fix first?

The AI inventory and named accountability. You cannot scope, risk assess, impact assess or evidence a system nobody has listed or owns, so nearly every other clause reads off those two. The emailed report lists every gap in the order we would work through them.

### Can I share the result with my team or board?

Yes. The result has a share link that carries your answers and nothing else: no name, no company, no email. Whoever opens it sees the same score and the same gaps, and can change answers to see how the score moves.

### Who built the ISO 42001 readiness check?

Sentry AI, an AI company in Auckland. We are building our own AI management system on the same control set as our ISO 27001 programme, and the questions are the ones we had to answer ourselves. We prepare organisations for certification; an accredited body certifies them.

## Want to know how far you are from Stage 2?

Take the free readiness check first. If the gaps are real, a short call will show you what building the management system involves for a business your size.

[Take the readiness check](https://sentrysolutions.ai/iso-42001/readiness-check) [Book a call](https://calendly.com/james-sentry-ai)

Ask an AI about this page

[ChatGPT](https://chatgpt.com/?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Freadiness-check%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20ISO%2042001%20readiness%20check.%20Cite%20the%20page.)[Claude](https://claude.ai/new?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Freadiness-check%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20ISO%2042001%20readiness%20check.%20Cite%20the%20page.)[Perplexity](https://www.perplexity.ai/search/new?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Freadiness-check%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20ISO%2042001%20readiness%20check.%20Cite%20the%20page.)[Google AI Mode](https://www.google.com/search?udm=50&q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Freadiness-check%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20ISO%2042001%20readiness%20check.%20Cite%20the%20page.)

Opens the assistant with this page loaded: read it, summarise it, cite it.
