ISO 42001:2023 Audit & Control Checklist
The organization shall define and put in place a process to report concerns about the organization's role with respect to an AI system throughout its life cycle.
The organization shall define and put in place a process to report concerns about the organization's role with respect to an AI system throughout its life cycle.
Building on CSET’s harmonized AI framework, this report collates actionable guidance from these resources into an easy-to-navigate format and connects the information back to core recommended practices, establishing a critical link between high-level principles and practical implementation details.
ISO 42001 establishes the formal policies and roles. NIST AI RMF provides the practical, risk-based steps to identify and measure harms in your specific operational context. Sequencing both creates a system that is certifiable and resilient.
We address this by creating the AI Risk Repository: a living database of 1,725 risks extracted from 74 existing taxonomies and frameworks. We organize these risks using two complementary classification systems.
Post-deployment measurement and monitoring is necessary (1) to validate that an AI system is operating reliably and as expected in real-world scenarios, (2) to track unforeseen outputs and drift, and (3) to identify unexpected consequences of integrating AI systems in new or changing contexts.
A practitioner's map of published international standards for AI systems, covering foundational concepts, governance, trustworthiness, data quality, lifecycle management, computational approaches, use cases, and conformity assessment.
No universally accepted definition of artificial intelligence exists — a gap that carries direct consequences for regulation, compliance obligations, and regulatory scope. This textbook proposes the AI Governance Stack as its central organizing framework: a five-layer operational model.
We may never fully understand how some AI systems arrive at their answers. Governance cannot wait for perfect explainability. The real test is whether organisations can define acceptable boundaries, detect when systems cross them, and respond when the machine surprises them.
AI risk management is the systematic and continuous application of management policies, processes and practices to the tasks of analysing, evaluating, controlling and monitoring risks throughout the entire lifecycle of an AI system.
Audit functions face a dual challenge: using AI to improve assurance while providing assurance over the AI systems themselves. The same technologies that improve analytical capability also introduce new risks relating to explainability, evidence integrity, data quality, privacy, and accountability.
AI tools now read and write code, search business data, run commands, change repositories, and call external systems. Across eight AI tooling sources, each chapter answers what the source records, what it misses, which fields matter, what the data can support, and where its limits begin.
An ML-BOM (Machine Learning Bill of Materials) is a CycloneDX BOM document designed to address the unique complexities and risks of AI/ML systems. It provides a detailed inventory of all components, configurations, and processes involved in the development, training, deployment, and hosting
The forecasts show a consistent pattern: participants assessed baseline risks of catastrophic cyber harms in 2026 as low but non-negligible, and they expected some AI capabilities to substantially increase those risks, especially when AI lowers barriers for moderate-sophistication actors.
Frontier models can now autonomously discover zero-day vulnerabilities, generate working exploits, and chain complex attack paths. The time between a vulnerability being disclosed and being weaponized has collapsed. And the threat has moved up the stack
Secure the Data. Protect the Model. Control Access. Monitor Every Decision.
Between December 2021 and June 2025, the share of large- and mid-cap developed-market companies with at least one AI expert director grew from 15% to 25%. Yet only 14% of boards had effectively integrated that expertise as of mid-2025, meaning they had recruited the credential without deploying it.
When you evaluate any control in this document, ask a single question: does this make the attack impossible, or just tedious? Mitigations whose value comes from friction rather than a hard barrier degrade significantly against an adversary that can grind through tedious steps at scale.
The assessment should be completed using a combination of management interviews, sample-based evidence review, control design assessment, control operating-effectiveness testing, system walk-throughs, and independent challenge. Scoring should be evidence-based and should not rely solely on managemen
Agentic skills are becoming first-class citizens of AI workflow: reusable bundles of progressive instructions, code, resources, and operational know-how that agents can discover, load, and execute. That makes them powerful, but it also moves risk into a new layer.
AI fundamentally changes an organisation's risk profile. It expands the attack surface, increases data movement across systems, and introduces behaviour that can change over time as models are updated and interact with new data.
AI is not a single decision; it is a stack of decisions: what data goes in, how the model learns, how it is wired into the business, how it is watched, and how it is proven. Governance must be a stack too. Every part of an AI system gets its own layer of controls, with its own owner and its own evid
AI security is rarely treated as a cultural problem. Most organizations manage AI risk with technical controls, and do very little about the risks that people introduce: shadow AI, blind trust in hallucinated output, unintentional IP leakage and more.
ISO 42001 does not make your AI trustworthy. It makes your AI governance auditable, and that is the point. One warning: an ISO 42001 certificate is not solely EU AI Act compliance. It is evidence of governance, not a legal safe harbour.
Mechanisms at the model level to ensure that AI Agents meet safety standards are insufficient. Implementing and maintaining those guardrails once models are deployed in the enterprise context are necessary.
Curated Library of AI Governance Resources