ISO 42001 SoA Builder
Build your ISO/IEC 42001 Statement of Applicability: work through all 38 Annex A controls across the 9 objectives, mark each applicable or excluded with an implementation status, and export a scored SoA to Markdown or CSV.
Comparing AI governance platforms? See the best EU AI Act compliance software guide.
Implementation maturity: 0%
Assessed 0/38 · 0 gaps
A.2 Policies related to AI
Set, align, and review the policies that govern how your organisation develops and uses AI.
A.3 Internal organization
Assign accountability and channels for raising concerns about AI.
A.4 Resources for AI systems
Document the data, tools, infrastructure, and people needed to operate AI systems responsibly.
A.5 Assessing impacts of AI systems
Assess and document how AI systems may affect people, groups, and society.
A.6 AI system life cycle
Control responsible design, development, deployment, operation, monitoring, and records across the AI system life cycle.
A.7 Data for AI systems
Manage how data is acquired, prepared, governed, and traced for AI systems.
A.8 Information for interested parties of AI systems
Provide users and other interested parties with clear information and report incidents.
A.9 Use of AI systems
Define responsible-use processes, objectives, and intended use.
A.10 Third-party and customer relationships
Set responsibilities and expectations with suppliers and customers.
- AI policy , Not assessed
- Alignment with other organizational policies , Not assessed
- Review of the AI policy , Not assessed
- AI roles and responsibilities , Not assessed
- Reporting of concerns , Not assessed
- Resource documentation , Not assessed
- Data resources , Not assessed
- Tooling resources , Not assessed
- System and computing resources , Not assessed
- Human resources , Not assessed
- AI system impact assessment process , Not assessed
- Documentation of AI system impact assessments , Not assessed
- + 26 more in the export.
Export your scored assessment and prioritised gap list. Everything stays in your browser: nothing is uploaded.
All 38 Annex A Controls
Every ISO/IEC 42001 Annex A control (A.2 to A.10) pre-loaded, grouped by the nine control objectives an auditor works through.
The First Artifact an Auditor Opens
Mark each control applicable or excluded with its status and justification, and export the Statement of Applicability your Stage 1 audit asks for.
Maps to Runtime Controls
Controls like impact assessment, logging and human oversight map onto policy gates and sealed evidence: the SoA doubles as your runtime control plan.
Disclaimer: This tool helps you draft an ISO/IEC 42001 Statement of Applicability. It does not make your organisation certified and is not legal or certification advice. Confirm control applicability and implementation with your auditor.
