ISO/IEC 42001 readiness

Stand up the operating controls behind your AI management system.

ISO/IEC 42001 describes how to establish, implement, and improve an AI management system. Use this checklist to operate the day-to-day controls and evidence behind it.

Why this matters

ISO/IEC 42001 sets out requirements for an AI management system, with emphasis on responsible use, risk management, transparency, and governance. Much of the standard is about operating real controls — not just writing policy.

As AI agents gain tools and permissions, the management system needs a live view of what agents can do and who approved it.

Bakara helps operate those controls: inventory, owners, risk assessments, monitoring, supplier registers, and review evidence.

The checklist

Operate the controls, not just the policy.

AI system inventory

  • Do we maintain a current list of AI agents and AI-enabled workflows?
  • Do we record the skills, tools, and connectors each can use?
  • Do we know which systems and data types each can access?

Policy and owners

  • Is there an AI policy that defines approved use?
  • Does each AI agent and loadout have a named owner?
  • Are approvers recorded for each capability?

Risk management

  • Are AI capabilities assessed for risk?
  • Are high-risk skills restricted or gated?
  • Are risks re-assessed when capabilities change?

Monitoring and review

  • Do we monitor usage and drift from approved policy?
  • Are loadouts reviewed on a schedule?
  • Do exceptions expire and get re-reviewed?

Supplier and tool register

  • Do we keep a register of AI models, MCP servers, and APIs agents can call?
  • Are third-party AI tools reviewed before use?
  • Can we restrict capabilities that reach external services?

Evidence

  • Can we export inventory, approvals, risk, monitoring, and review evidence?
  • Can we show change history for each AI capability?
  • Can we produce a management summary on demand?

How Bakara helps

From policy to governed loadouts.

Skill registry

A live inventory of AI skills, tools, prompts, workflows, connectors, permissions, and owners.

Role-based loadouts

Define what each role, team, or AI agent is allowed to access and do.

Monitoring & drift

See usage, detect drift from policy, and flag capabilities that need review.

Audit evidence

Export evidence of approved skills, access decisions, exceptions, and reviews.

Make your AI management system operational.

Bakara helps turn an AI management system from documents into live controls and exportable evidence for AI agents.

Bakara supports AI governance, security operations, and audit-readiness workflows. Regulatory obligations vary by organization, jurisdiction, use case, and implementation. This material is not legal advice.