Before you can prove your AI is governed, you need to know what "governed" actually requires.
Two laws now sit behind AI governance: ISO/IEC 42001 certifies your organisation's AI management system, and the EU AI Act regulates each AI system individually. This checklist covers what both actually require, so a readiness gap is something you find on your own terms, not an auditor's.
Most organisations can describe their AI use. Few can prove it is governed.
Being able to name the AI systems you run is not the same as being able to show which legal category each one falls into, what you have done to control it, and that a person genuinely oversees it — which is exactly what an auditor or regulator asks for.
No classification of which AI Act category each AI system actually falls into
AI policy exists on paper but no named accountable owner, objectives or internal audit programme behind it
AI risk tracked nowhere, or in a separate spreadsheet disconnected from every other business risk
No evidence that human oversight of high-risk AI is real rather than a policy statement
What AI governance readiness actually requires.
Classify every AI system against the EU AI Act — banned, high-risk, transparency-only, or out of scope — and record the legal reasoning.
Establish the organisation-level AI management system ISO/IEC 42001 certifies: policy, named owners, objectives, competence, internal audit.
Run a compliance and applicability assessment per system, and produce the Statement of Applicability an ISO 42001 audit starts with.
Assess impact — who could be harmed, how badly, and whether safeguards actually reduce that.
Map controls to every requirement they satisfy, with evidence attached and its validity tracked.
Record human oversight as real events, not a policy claim.
Run AI risk through the same risk discipline as every other business risk.
Catch changes to a system before they quietly turn a low-concern system into a regulated one.
Built for compliance and risk owners, not just AI engineers.
- A guided classification workflow that stops at banned uses and records the reasoning behind every category decision
- One requirement library per framework, with your position, evidence and gaps tracked item by item
- Before/after safeguard scoring on impact assessments, so a control's real effect is visible, not assumed
- A single control library mapped to every framework it satisfies, so one piece of evidence answers to all of them
- Oversight, risk, incidents and change all connected to the same AI system record
Governance that attaches to your AI register, not a second inventory
XGRC's AI Governance solution never duplicates the technical facts your AI register already holds. It attaches classification, compliance, impact, risk, controls, oversight, incident and change governance to the systems your register already tracks.
The same obligations. Actually provable.
AI Governance Readiness Checklist (ISO/IEC 42001 & EU AI Act)
- EU AI Act classification and role (provider vs deployer)
- ISO/IEC 42001 management system essentials
- Compliance, applicability and Statement of Applicability
- Impact assessment before and after safeguards
- Controls, evidence, oversight and AI-specific risk
- Incident and change governance
Aligned to the frameworks that actually govern AI.
- ISO/IEC 42001
- EU AI Act
- AI Governance
- AI Risk Management
One checklist across classification, compliance, impact, risk, controls and oversight.
- EU AI Act classification
- ISO/IEC 42001 management system
- Impact assessment
- AI-specific risk, controls and oversight
Explore the connected platform.
MAIA®
Governed AI for GRC
Explore MAIA® → Use CaseAI Change Management
Introducing an AI feature, chatbot, or automated decision tool carries risks a standard IT change request does not capture — data exposure, unreliable output, and unclear accountability. XGRC® gives organisations a structured way to assess, approve, and monitor AI-related change.
View use case → Use CaseEnterprise Risk Management
XGRC® provides a central ERM platform aligned to ISO 31000, COSO, and King V. Define your risk framework, identify and assess risks across all categories, link every risk to controls and audit findings, and report to the board with real-time visibility.
View use case → Use CaseInternal Controls
XGRC® is internal controls software that lets organisations design, implement, test, and assure controls in a structured way. Every control is linked to the risk it mitigates and the assurance provider testing it, so control effectiveness is demonstrable at any time.
View use case →Common questions.
Is this checklist about the EU AI Act, or ISO/IEC 42001?
Both, deliberately. ISO/IEC 42001 certifies your organisation's AI management system as a whole — policy, accountable owners, objectives, internal audit. The EU AI Act regulates individual AI systems — which category each one falls into and what that requires. Real AI governance readiness has to answer both.
Do we need to classify AI systems we didn't build ourselves?
Yes. Your role changes what you owe, not whether the law applies. If you deploy someone else's AI, you have deployer obligations. If you substantially modify it, rebrand it, or change what it's used for, the law can treat you as the manufacturer and you inherit the full provider obligation set.
What is a Statement of Applicability, and why does it matter for ISO 42001?
It lists every control in the ISO/IEC 42001 standard and states whether you apply or exclude it, with a reason for each. It is typically the first document an ISO 42001 auditor asks for — without it, a certification audit does not meaningfully begin.
Can AI risk sit in our existing risk register instead of a separate AI tool?
Yes, and it should. AI-specific failure modes (biased output, data leakage, model drift) are scored with the same framework and appetite thresholds as every other business risk, visible in the same board report rather than hidden in a separate system.
See AI governance as one connected system, not eleven separate spreadsheets.
Book a demo to see EU AI Act classification, ISO/IEC 42001 compliance, impact assessment, risk, controls and oversight running as one connected system, attached to your AI register.
Book a demoWhere should we send your download link?
Enter your details and we will email you the link to the checklist.
Your checklist is ready.
Click the button below to download the PDF. We have also sent this link to your email.
Download the checklist (PDF)