Free · no signup · your answers stay in this browser
ISO/IEC 42001 is the certifiable management system standard for AI, and the work of getting ready is a document set: the twelve artifacts a certification body reviews at Stage 1. This tool builds them with you, in your browser: add a few inputs (your organisation, your AI systems, the people in the roles) and the pack arrives populated: scope statement, AI policy, roles matrix, AI inventory, risk register, the 38-control Statement of Applicability, impact assessments, audit checklists. Or assess your current state first: 24 questions, a 0 to 100 readiness score, your gaps ranked by audit impact, and the sequenced path to 100.
ISO/IEC 42001:2023 is the first certifiable management system standard for AI. Clauses 4 to 10 set the management requirements (scope, policy, roles, risk assessment, impact assessments, competence, monitoring, internal audit, management review) and Annex A lists 38 controls, selected through risk treatment and justified in a Statement of Applicability. Organisations certify the way they do for ISO 27001: an accredited certification body audits in two stages, then runs annual surveillance.
No, and no software can be. Certification only comes from an accredited certification body, which must stay independent: it audits, it never consults. This is a readiness check. It shows where you stand against what those bodies review at Stage 1 and Stage 2, so you engage one when you are ready to pass.
No. ISO 42001 certification gives no presumption of conformity with the EU AI Act; the Act's harmonised standards are being drafted separately. It does build most of the management muscle the Act relies on (risk management, documentation, logging, human oversight), and Annex III high-risk obligations now apply from 2 December 2027, which is exactly the window in which to build an AI management system.
A lot. The two standards share the same management-system skeleton, and an operating ISMS typically covers around half of the required machinery: document control, competence, internal audit, management review, corrective action. The new work is the AI delta: the AI system inventory, per-system impact assessments, AI-specific risk criteria and data controls. Your results show that split for your answers.
The assessment runs entirely in your browser and the full results are shown on-page, free, with no login or email required. Your answers are stored only in this browser. A free account adds saving, sharing and clean exports; free exports carry a small "Prepared with Raksa" mark.
Nothing leaves your browser unless you choose it. Answers autosave to this browser's local storage. If you use an optional AI assist, the relevant answers are sent to generate that one suggestion and are not stored on our servers or used for training.
Raksa runs DPIA, transfer, AI-risk and vendor assessments off a single common nucleus, so one intake feeds them all and teams never answer the same question twice. Start the adaptive assessment or explore the platform.