关于本检查清单

准备 ISO/IEC 42001 认证的第一步,是明确组织当前存在的差距。该标准规定了有效运行的人工智能管理体系(AIMS)应具备的要求,包括如何治理人工智能相关风险、如何确保数据管理和透明度,以及如何管理所开发或部署人工智能系统的全生命周期。本自评估工具按照不同评估领域逐项梳理相关要求,帮助您了解组织哪些方面已具备认证准备条件,以及在正式审核前仍需进一步完善的领域。

请逐项查看每个章节,并针对每一项要求选择“是”或“否”。在此过程中,如实评估比乐观判断更有助于识别实际差距。

关于后续认证流程的说明

认证并非一次性事件,而是一个持续开展的过程。通常,认证审核包括第一阶段审核和第二阶段审核:第一阶段审核主要关注文件、方针政策及风险评估等内容;第二阶段审核则用于验证组织建立的控制措施是否能够在实际运行中有效实施。获得认证后,组织仍需按照规定周期接受监督审核,并通常每三年进行一次再认证审核,以维持认证有效性。请将本检查清单作为认证准备过程中的辅助工具,帮助您提前识别差距并做好准备。但需要注意的是,本检查清单不能替代正式认证审核。

如何使用本检查清单

为每个章节指定相应的责任人,而不是由个人独自完成整份检查清单。大多数问题涉及不同职能部门(如风险管理、IT、人力资源和法务),单个人通常难以全面掌握所有相关情况。当组织使用的人工智能系统发生变化,或其风险状况发生变化时,应重新进行评估。六个月前的评估结果可能已不再适用。最后的评分结果旨在帮助您确定优先改进的领域,而不是预测正式认证审核的结果。
 

ISO/IEC 42001 Readiness Checklist

ISO/IEC 42001 Readiness Checklist

Assess your organization's preparedness for responsible AI governance.

22 questions · 6 sections · Yes / No
Your progress 0 of 22 answered
1

Foundation & Awareness

Have you reviewed the ISO/IEC 42001 standard and understood its scope and objectives?

Have you engaged relevant stakeholders to raise awareness about the importance of responsible AI governance and certification?

Have you identified internal and external resources (people, systems, infrastructure) required to implement the AIMS?

2

Status Check & Risk Perspective

Have you assessed your existing processes against the ISO/IEC 42001 requirements?

Is there a risk management framework in place specifically addressing AI-related risks (e.g., bias, data misuse, unintended outcomes)?

Have you documented your AI policies, risk assessments, and AI impact assessments?

3

System Design & Implementation

Are roles and responsibilities for AI governance clearly defined within the organization?

Have relevant personnel been trained on AI risks, governance practices, and ISO/IEC 42001 expectations?

Are technical controls in place for managing AI systems, including monitoring, updates, and access controls?

4

Internal Audit and Corrective Actions

Have you conducted an internal audit to assess conformity with the standard?

Are non-conformities addressed with corrective actions and follow-up?

5

Controls Based on Annex A (ISO/IEC 42001)

A.2 - Alignment: Are your AI-related policies aligned with organizational policies and periodically reviewed?

A.3 - Responsibility: Are internal responsibilities for AI systems and their lifecycle clearly assigned?

A.4 - Resources: Have you identified and documented all resources relevant to your AI systems (data, tools, infrastructure)?

A.5 - Impact Assessment: Is there a formal process for conducting AI impact assessments on individuals, groups, or society?

A.6 - Lifecycle: Do you have lifecycle management processes for AI systems, including monitoring and ethical design?

A.7 - Data: Are data quality, provenance, and handling procedures defined for AI systems?

A.8 - Transparency: Are stakeholders and users informed about AI system behavior, risks, and reporting channels?

A.9 - Ethical Use: Do you have measures to ensure ethical and responsible use of AI technologies?

A.10 - Supply Chain: Are supplier and partner relationships aligned with your AI governance framework?

6

Certification Preparation

Have you selected an accredited certification body for ISO/IEC 42001?

Are all relevant documents compiled and the team prepared for the certification audit?

Your Readiness Score

0 of 22 points

Results by section

下一步行动

完成自检后,DQS将根据贵组织的认证范围及所使用的AI系统,开展独立的ISO/IEC 42001认证审核。请联系DQS,确认具体审核方案并安排认证审核工作。

联系我们