Back to Insights
AI Governance

ISO 42001 AIMS Scoping Checklist

Step-by-step ISO 42001 scoping checklist. Boundary definition, AI inventory, applicability mapping, and the SoA that satisfies certification auditors.

By Al Rashdan
10 min read
#ISO 42001 scope#AIMS scoping#AI Management System boundary#ISO 42001 SoA

Scoping is the single biggest decision in an ISO 42001 programme: the right boundary keeps a programme focused on the systems that matter and holds up at certification. Here is the working checklist we use with clients.

Step 1

Inventory every AI system

Step 1 of 6
1.

Bespoke ML and deep-learning models built in-house.

2.

Third-party AI APIs (OpenAI, Anthropic, Azure OpenAI, Bedrock, Vertex).

3.

AI features embedded in SaaS (Salesforce Einstein, HubSpot Breeze, ServiceNow Now Assist, Microsoft Copilot, Google Workspace Gemini).

4.

Robotic process automation with ML components.

5.

Predictive analytics and recommendation engines.

Step 2

Classify each system

Step 2 of 6
1.

DimensionOptions
RoleProvider, Developer, User, Customer
Use caseDecision support, automation, content generation, prediction, classification
Risk levelMinimal, limited, high, unacceptable
Data sensitivityPublic, internal, confidential, regulated (PII, PHI, financial)
AudienceInternal staff, customers, regulators, public

Step 3

Define the boundary

Step 3 of 6
1.

Organizational, which legal entities and business units are included?

2.

Functional, which AI roles (provider, developer, user)?

3.

Technical: which systems, lifecycle stages, and supporting infrastructure?

Step 4

Identify interfaces and exclusions

Step 4 of 6
1.

Any AI system excluded from scope must have a documented justification and a clean interface definition (what data crosses the boundary, what controls apply at the boundary).

Step 5

Run the applicability assessment

Step 5 of 6
1.

Walk every Annex A control of ISO 42001 and decide: applicable, applicable with modification, or not applicable. Justify exclusions in the Statement of Applicability (SoA).

Step 6

Validate with stakeholders

Step 6 of 6
1.

Workshop the scope and SoA with: legal, privacy, security, business owners, and internal audit. Surface disagreements before the certification body does.

07

Common scoping mistakes

01

Excluding embedded SaaS AI on the basis that "we did not build it." Wrong, the User role still applies.

02

Picking only one pilot system for scope. Auditors expect the boundary to reflect actual organizational AI activity.

03

Excluding training data lifecycle. Data preparation is in scope.

04

Ignoring shadow AI. Address it through policy and controls, not through scope exclusion.

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Stay up to date

Get notified when new compliance guides and cybersecurity articles are published.

By submitting, you consent to Allo Technologies using these details to email you when a new guide is published, after you confirm your address. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

Related Reading

More insights from the Allo Technologies practice

AI Governance

AI Governance ROI: Business Case for Executives

AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.

Read more
AI Governance

AI Risk Assessment: Gulf-Specific Use Cases

AI risks vary by industry and region. Healthcare, finance, and smart cities in the Gulf face unique challenges requiring tailored assessment approaches.

Read more
AI Governance

Building Your AI Governance Team: Roles & Skills

Effective AI governance requires dedicated roles including AI Ethics Officer and governance committees. Here is how to structure your team for success.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%