Framework

ISO/IEC 42001 readiness, assessed.

Two hundred and seventy-five questions across ISO/IEC 42001, 23894 and 38507, scored by the severity of each control — the depth engagement for firms heading towards accredited certification. Here is what it covers, how it weights, and the language it is careful about.

Questions
275
Standards
42001 · 23894 · 38507
Scoring
Severity-weighted
Outcome
Certification-ready

ISO/IEC 42001 readiness, assessed

Once a firm commits to accreditation, a maturity baseline stops being enough. The ISO Standards Deep Dive is the depth engagement: 275 questions assessing readiness against the three standards that together define how an AI management system is expected to look.

  • ISO/IEC 42001 — the AI management system standard, and the one certification is issued against.
  • ISO/IEC 23894 — AI risk management: how AI-specific risk is identified, treated and monitored.
  • ISO/IEC 38507 — the governance implications of AI for the governing body itself.

As with every AIssure assessment, each question is tested against the primary regulatory and standards text behind it, drawn from the regulatory knowledge graph, so the evidence base you hand a certification body is cited rather than asserted.

Certification-ready, not certified

This is the distinction that matters most on this page. An assessment prepares you for certification; it does not grant it. Accredited ISO/IEC 42001 certification is issued by accredited certification bodies — such as BSI, Schellman or A-LIGN — after their own audit. What AIssure produces is the evidence base and gap remediation that audit expects to find. That is why we say certification-ready, and never "certified" — the word is a claim we are not entitled to make on a certification body's behalf, and one a supervisor would be right to challenge.

How critical controls are weighted

Readiness is not a flat pass rate, because not every control carries the same consequence. The deep dive is scored as a severity-weighted compliance percentage: each control is weighted by how load-bearing it is — critical highest, then high, medium and low — so a gap against a critical requirement moves the score far more than a gap against a peripheral one.

The output is a compliance figure per standard plus an overall, rather than a single undifferentiated number. That tells a governing body something a pass rate cannot: not just how much is done, but whether what remains is the easy tail or the part the standard cares most about. It is also what makes the remediation plan honest — the work is ranked by the weight of the control behind it, so the sequence a certification body would expect is the sequence you are handed.

When to choose it

Choose the deep dive when you are heading towards accreditation — when the question has moved from how mature are we? to can we evidence a management system a certification body will accredit? It is the framework for firms that have decided ISO/IEC 42001 certification is a commitment rather than an aspiration.

If that decision is not yet made, the 96-question Maturity Assessment is the better first move: it sets a defensible baseline and ranks the gaps, which is what tells you where the deep dive will concentrate its effort. Many firms run the baseline, then commission the deep dive against the domains it flagged. Either way the outcome is certification-ready evidence — see both frameworks compared for how they fit together.

FAQ

ISO 42001 readiness — the questions we get.

What firms heading towards accreditation ask about the 275-question deep dive.

What does the ISO Standards Deep Dive assess?

It assesses readiness against three ISO standards — ISO/IEC 42001 (the AI management system), ISO/IEC 23894 (AI risk management) and ISO/IEC 38507 (the governance implications of AI) — across 275 questions. It is the depth engagement for firms heading towards accredited certification, where a maturity baseline is no longer enough.

Does the ISO deep dive make us ISO 42001 certified?

No. It makes you certification-ready. Accredited ISO/IEC 42001 certification is issued by accredited certification bodies — such as BSI, Schellman or A-LIGN — not by AIssure. What the deep dive produces is the evidence base and gap remediation a certification audit expects, so the language is deliberately 'certification-ready', never 'certified'.

How are critical controls weighted in the scoring?

The deep dive is scored as a severity-weighted compliance percentage rather than a flat pass rate. Critical controls carry the most weight, then high, medium and low — so a gap against a load-bearing requirement moves the score more than a gap against a peripheral one. You get a compliance figure per standard plus an overall, which reflects where the standard actually concentrates its expectations.

When should we choose the ISO deep dive over the maturity baseline?

Choose the deep dive when you are committed to accredited ISO/IEC 42001 certification and need depth against the standard, not a whole-estate baseline. Many firms run the 96-question Maturity Assessment first to rank their gaps, then move to the 275-question deep dive once the baseline has shown where accreditation work will concentrate.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.