The ISO 42001 Gap Assessment is a free tool that measures your organization against ISO/IEC 42001:2023, the international standard for Artificial Intelligence Management Systems (AIMS). Assess the Clause 4 to 10 management system requirements at a Basic (Level 1) scope, or a Standard (Level 2) scope; generate a downloadable report that includes a remediation roadmap.
The ISO 42001 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems (AIMS) published by ISO and IEC. You choose your scope: Basic (Level 1) covers the mandatory management system requirements of Clauses 4 to 10, and Standard (Level 2) adds all 38 reference control objectives and controls from Annex A. You assess each requirement and control, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
ISO 42001, formally ISO/IEC 42001:2023, is the international standard for Artificial Intelligence Management Systems (AIMS) and the first certifiable management system standard for AI governance, published by ISO and IEC in December 2023. It defines the mandatory management system requirements in Clauses 4 to 10 (27 requirements) and 38 reference controls in Annex A that organizations use to develop, provide, and use AI systems responsibly. Organizations of any size or industry can implement it, and accredited certification bodies can audit and certify conformance, in the same way ISO 27001 certification works for information security.
The assessment is built for small and medium organizations, startups, and growing companies that develop, provide, or use AI systems and want to understand where they stand against ISO/IEC 42001 before pursuing certification or formalizing AI governance. The Basic (Level 1) scope is the right starting point for organizations building their first AI management system, while the Standard (Level 2) scope suits teams preparing for certification readiness or a full Statement of Applicability.
Enter your company name, website, and a description of what the company does, choose the Basic (Level 1) or Standard (Level 2) assessment scope, and add your logo for the report.
Work through the Clause 4 to 10 AI management system requirements, plus the 38 Annex A controls at the Standard scope, mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.
Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.
Not loading? Open the ISO 42001 Gap Assessment tool in a new tab.
This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice, and it is not affiliated with or endorsed by ISO or IEC. We recommend you seek advice from a Virtual CISO. Learn more about our AI Governance services.
An ISO 42001 gap analysis, also called a gap assessment, is a structured comparison of your organization's current AI governance practices against the requirements of ISO/IEC 42001:2023, identifying which clause requirements and Annex A controls you already meet, where you fall short, and what to fix first. It is the standard starting point for any AI Management System (AIMS) implementation or certification project.
A good gap assessment, sometimes called an ISO 42001 readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which of the mandatory Clause 4 to 10 requirements and the 38 Annex A controls apply to you, given your role as an AI provider, developer, or user? Secondly, Conformance: for each applicable requirement, do you have the process, the documentation, and the evidence an auditor would ask for?
Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your compliance obligations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.
Run your first gap assessment before you spend anything on implementation or certification. The typical ISO 42001 journey for a small or medium organization has five stages: gap assessment, remediation, internal audit (required by Clause 9.2), management review (Clause 9.3), and then the two-stage certification audit with an accredited certification body. The gap assessment sets the scope, budget, and timeline for everything that follows; organizations that skip it routinely discover missing risk assessments or undocumented AI system life cycles mid-audit, when fixes are most expensive.
Repeat the assessment after major remediation work, when you deploy or materially change an AI system, when your role with respect to AI changes (for example, you start fine-tuning models instead of only consuming APIs), and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.
Annex A of ISO/IEC 42001 provides 38 reference controls organized into nine control objectives, A.2 through A.10. They are not all mandatory: you select the controls your AI risk treatment requires and justify inclusions and exclusions in your Statement of Applicability. Together they span the full life of an AI system, from policy and accountability through data management, impact assessment, transparency, responsible use, and third-party relationships.
| Objective | Control family | Controls | What it covers |
|---|---|---|---|
| A.2 | Policies related to AI | 3 | An AI policy for developing or using AI systems, alignment with other organizational policies, and scheduled policy reviews. |
| A.3 | Internal organization | 2 | Defined AI roles and responsibilities, and a process for reporting concerns about AI systems across their life cycle. |
| A.4 | Resources for AI systems | 5 | Documenting the data, tooling, system, computing, and human resources behind each AI system life cycle stage. |
| A.5 | Assessing impacts of AI systems | 4 | A repeatable AI system impact assessment process covering individuals, groups of individuals, and societies, with documented, retained results. |
| A.6 | AI system life cycle | 9 | Responsible development objectives and processes, requirements and specifications, design documentation, verification and validation, deployment, operation and monitoring, technical documentation, and event logging. |
| A.7 | Data for AI systems | 5 | Data management for AI development: acquisition and selection, data quality requirements, provenance recording, and data preparation criteria. |
| A.8 | Information for interested parties | 4 | User documentation, channels to report adverse impacts, incident communication plans, and reporting obligations to interested parties. |
| A.9 | Use of AI systems | 3 | Processes and objectives for responsible use of AI systems, and ensuring systems are used according to their intended uses. |
| A.10 | Third-party and customer relationships | 3 | Allocating AI life cycle responsibilities across partners, suppliers, customers, and third parties, and keeping supplier usage aligned with your responsible AI approach. |
The Statement of Applicability (SoA) is the document Clause 6.1.3 requires: a list of the controls you consider necessary, with justification for every inclusion and exclusion. Auditors treat it as the index to your whole AIMS, and it is usually the first document a certification body asks for.
The two assessment scopes in the tool map directly onto SoA preparation. The Basic (Level 1) scope covers the Clause 4 to 10 management system requirements, which are mandatory for every organization and are never excluded in an SoA; assessing them first tells you whether the management system itself (context, leadership, risk processes, support, operation, evaluation, and improvement) stands up.
The Standard (Level 2) scope adds all 38 Annex A controls, which is precisely the set you must dispose of in the SoA. Your assessment results give each control a status: compliant controls become "implemented" entries, partially compliant and non-compliant controls become "planned" entries tied to your remediation roadmap dates, and controls you mark not applicable become documented exclusions with your reasoning. Run the Standard scope and you have effectively drafted the evidence base for your first SoA.
A gap assessment is a diagnostic you run for yourself before building your AIMS; an internal audit is the recurring conformance check Clause 9.2 requires once the AIMS exists; a certification audit is the independent, two-stage examination by an accredited body that results in an ISO/IEC 42001 certificate. They answer different questions at different times, and none replaces the others.
| Gap assessment | Internal audit (Clause 9.2) | Certification audit | |
|---|---|---|---|
| Purpose | Measure your current AI management system against ISO/IEC 42001 to find and prioritize gaps before you invest in remediation. | Verify that your implemented AIMS conforms to ISO/IEC 42001 and your own requirements, and is effectively maintained. | Independent verification by an accredited certification body that your AIMS conforms to ISO/IEC 42001, leading to a certificate. |
| Who performs it | You (self-assessment) or a consultant. No independence requirement. | Internal staff or an outsourced auditor who is objective and impartial (they cannot audit their own work). | An accredited third-party certification body. |
| Required by the standard | No. It is a preparatory best practice, not a requirement. | Yes. Clause 9.2 requires internal audits at planned intervals. | Only if you want certification. Conformance without certification is possible. |
| Typical timing | At the start of your ISO 42001 journey, and again after major remediation or AI system changes. | After the AIMS is implemented, then on a recurring audit programme. | After at least one internal audit and management review cycle. Stage 1 reviews documentation, Stage 2 audits implementation. |
| Output | A gap report: compliance score, risk-ranked findings, and a remediation roadmap. | Audit report with nonconformities and observations feeding corrective action (Clause 10.2). | Audit findings and, on success, an ISO/IEC 42001 certificate with surveillance audits in following years. |
| What happens with findings | Findings become your remediation plan and inform your Statement of Applicability. Nothing is reported externally. | Findings are reported to management and tracked to closure as corrective actions. | Major nonconformities block certification until resolved; minors require a corrective action plan. |
The table below summarizes every mandatory requirement in Clauses 4 to 10 of ISO/IEC 42001:2023 and the evidence auditors typically expect to see for each. The summaries are condensed guidance prepared by IRM Consulting & Advisory, not verbatim standard text; the assessment tool above walks you through all 27 of these requirements at either scope.
| Clause | Requirement | Summary | Evidence auditors expect |
|---|---|---|---|
| 4.1 | Understanding the organization and its context | Determine the internal and external issues relevant to your AI management system, and your roles with respect to AI systems (provider, producer, user, partner, subject, authority). | Documented context analysis and AI role determination. |
| 4.2 | Needs and expectations of interested parties | Identify the interested parties relevant to the AIMS, their requirements, and which requirements the AIMS will address. | Interested party and requirements register. |
| 4.3 | Scope of the AI management system | Define the boundaries and applicability of the AIMS, considering context and interested party requirements. | A documented, approved scope statement. |
| 4.4 | AI management system | Establish, implement, maintain, continually improve, and document the AIMS and its processes. | AIMS documentation and process interactions. |
| 5.1 | Leadership and commitment | Top management demonstrates leadership: AI policy and objectives set, AIMS integrated into business processes, resources provided, improvement promoted. | Management meeting records and resourcing decisions. |
| 5.2 | AI policy | Establish an AI policy appropriate to the organization that frames AI objectives and commits to requirements and continual improvement. | The approved, communicated AI policy document. |
| 5.3 | Roles, responsibilities and authorities | Assign and communicate responsibilities for AIMS conformance and for reporting AIMS performance to top management. | Role descriptions or a RACI matrix. |
| 6.1.1 | Risks and opportunities (general) | Determine the risks and opportunities the AIMS must address and establish AI risk criteria. | Documented AI risk criteria and risk register. |
| 6.1.2 | AI risk assessment | Define a repeatable AI risk assessment process that identifies, analyses, and evaluates AI risks against your criteria. | Risk assessment procedure and assessment records. |
| 6.1.3 | AI risk treatment | Select treatment options, determine necessary controls, compare against Annex A, and produce a Statement of Applicability and treatment plan. | Statement of Applicability and approved risk treatment plan. |
| 6.1.4 | AI system impact assessment | Define a process to assess consequences of AI systems for individuals, groups, and societies. | Impact assessment procedure and documented results. |
| 6.2 | AI objectives and planning | Set measurable, monitored, communicated AI objectives at relevant functions, with plans to achieve them. | Documented objectives with owners, timelines, and evaluation methods. |
| 6.3 | Planning of changes | Carry out changes to the AIMS in a planned manner. | Change plans and records. |
| 7.1 | Resources | Provide the resources needed to establish, implement, maintain, and improve the AIMS. | Budgets, staffing, and tooling decisions. |
| 7.2 | Competence | Determine and ensure the competence of people whose work affects AI performance. | Competency matrix and training records. |
| 7.3 | Awareness | Ensure people know the AI policy, their contribution, and the implications of nonconformance. | Awareness training and communication evidence. |
| 7.4 | Communication | Determine what to communicate about the AIMS, when, with whom, and how. | A communication plan. |
| 7.5 | Documented information | Create, update, and control the documented information the AIMS requires, including protection, versioning, retention, and disposition. | Document control procedure and controlled records. |
| 8.1 | Operational planning and control | Plan and control the processes that implement your Clause 6 actions, including externally provided processes and services. | Process criteria, operating records, and supplier controls. |
| 8.2 | AI risk assessment (operational) | Perform AI risk assessments at planned intervals and on significant change. | Dated risk assessment results. |
| 8.3 | AI risk treatment (operational) | Implement the risk treatment plan, verify effectiveness, and treat newly identified risks. | Treatment implementation and verification records. |
| 8.4 | AI system impact assessment (operational) | Perform AI system impact assessments at planned intervals and on significant change. | Dated impact assessment results. |
| 9.1 | Monitoring, measurement, analysis, evaluation | Decide what to monitor and measure, with what methods and timing, and evaluate AIMS performance. | Metrics definitions and evaluation reports. |
| 9.2 | Internal audit | Run an internal audit programme at planned intervals with objective auditors and defined criteria and scope. | Audit programme, audit reports, and auditor selection rationale. |
| 9.3 | Management review | Top management reviews the AIMS at planned intervals with defined inputs and documented results. | Management review minutes and decisions. |
| 10.1 | Continual improvement | Continually improve the suitability, adequacy, and effectiveness of the AIMS. | Improvement log and implemented changes. |
| 10.2 | Nonconformity and corrective action | React to nonconformities, correct them, address root causes, and verify corrective action effectiveness. | Nonconformity register and corrective action records. |
Closing the gaps is where most organizations want help. IRM's AI Governance services build right-sized AI management systems for SMBs and startups, and our Virtual CISO services take teams from gap assessment through certification readiness for ISO 42001, ISO 27001, CMMC and SOC 2.
Yes. The ISO 42001 Gap Assessment is a free, self-serve tool. You capture your company profile, choose your assessment scope, assess each ISO/IEC 42001:2023 requirement and Annex A control, and download a professional report with a remediation roadmap at no cost.
ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems (AIMS), published by ISO and IEC. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, so organizations that develop, provide, or use AI systems do so responsibly. Clauses 4 to 10 define the mandatory management system requirements, and Annex A provides 38 reference control objectives and controls.
Basic (Level 1) assesses the mandatory AI management system requirements of Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, and improvement. Standard (Level 2) covers everything in Basic plus all 38 Annex A control objectives and controls, spanning AI policies, internal organization, resources, impact assessments, the AI system life cycle, data, transparency, responsible use, and third-party relationships.
Each requirement and control is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).
The report includes an executive summary with your compliance score and top risks, detailed findings for every assessed clause requirement and Annex A control, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.
No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.
No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice, and it is an independent tool that is not affiliated with or endorsed by ISO or IEC. We recommend you seek advice from a Virtual CISO to validate findings, build your Statement of Applicability, and prepare for certification.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


