ISO 42001 Gap Assessment - IRM Consulting & Advisory
IRM Product

ISO 42001 Gap Assessment

The ISO 42001 Gap Assessment is a free tool that measures your organization against ISO/IEC 42001:2023, the international standard for Artificial Intelligence Management Systems (AIMS). Assess the Clause 4 to 10 management system requirements at a Basic (Level 1) scope, or a Standard (Level 2) scope; generate a downloadable report that includes a remediation roadmap.

  • ISO/IEC 42001:2023 aligned (Clauses 4 to 10 + 38 Annex A controls)
  • Risk-ranked gaps & remediation roadmap
  • FREE, built by an AI-Native vCISO for SMBs

What is the ISO 42001 Gap Assessment?

The ISO 42001 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems (AIMS) published by ISO and IEC. You choose your scope: Basic (Level 1) covers the mandatory management system requirements of Clauses 4 to 10, and Standard (Level 2) adds all 38 reference control objectives and controls from Annex A. You assess each requirement and control, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.

What is ISO 42001?

ISO 42001, formally ISO/IEC 42001:2023, is the international standard for Artificial Intelligence Management Systems (AIMS) and the first certifiable management system standard for AI governance, published by ISO and IEC in December 2023. It defines the mandatory management system requirements in Clauses 4 to 10 (27 requirements) and 38 reference controls in Annex A that organizations use to develop, provide, and use AI systems responsibly. Organizations of any size or industry can implement it, and accredited certification bodies can audit and certify conformance, in the same way ISO 27001 certification works for information security.

What you get

  • A Gap Assessment against ISO/IEC 42001:2023, the international standard for AI Management Systems (AIMS)
  • Two assessment scopes: Basic (Level 1) covers the Clause 4 to 10 management system requirements, Standard (Level 2) adds all 38 Annex A control objectives and controls
  • Likelihood and impact scoring for every gap on a 5x5 risk matrix
  • Gaps ranked Low, Medium, High, or Critical
  • An Executive Summary with your compliance score and top risks
  • A phased remediation roadmap across 30, 90, 180, and 365 day horizons, downloadable in PDF or Word format with your company logo

Who it is for

The assessment is built for small and medium organizations, startups, and growing companies that develop, provide, or use AI systems and want to understand where they stand against ISO/IEC 42001 before pursuing certification or formalizing AI governance. The Basic (Level 1) scope is the right starting point for organizations building their first AI management system, while the Standard (Level 2) scope suits teams preparing for certification readiness or a full Statement of Applicability.

How it works

Step 1

Capture your Company Profile

Enter your company name, website, and a description of what the company does, choose the Basic (Level 1) or Standard (Level 2) assessment scope, and add your logo for the report.

Step 2

Assess each requirement and control

Work through the Clause 4 to 10 AI management system requirements, plus the 38 Annex A controls at the Standard scope, mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.

Step 3

Download your Report and Remediation Roadmap

Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.

Not loading? Open the ISO 42001 Gap Assessment tool in a new tab.

This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice, and it is not affiliated with or endorsed by ISO or IEC. We recommend you seek advice from a Virtual CISO. Learn more about our AI Governance services.

ISO 42001 Gap Analysis explained

An ISO 42001 gap analysis, also called a gap assessment, is a structured comparison of your organization's current AI governance practices against the requirements of ISO/IEC 42001:2023, identifying which clause requirements and Annex A controls you already meet, where you fall short, and what to fix first. It is the standard starting point for any AI Management System (AIMS) implementation or certification project.

A good gap assessment, sometimes called an ISO 42001 readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which of the mandatory Clause 4 to 10 requirements and the 38 Annex A controls apply to you, given your role as an AI provider, developer, or user? Secondly, Conformance: for each applicable requirement, do you have the process, the documentation, and the evidence an auditor would ask for?

Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your compliance obligations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.

When to run a Gap assessment before ISO 42001 Certification

Run your first gap assessment before you spend anything on implementation or certification. The typical ISO 42001 journey for a small or medium organization has five stages: gap assessment, remediation, internal audit (required by Clause 9.2), management review (Clause 9.3), and then the two-stage certification audit with an accredited certification body. The gap assessment sets the scope, budget, and timeline for everything that follows; organizations that skip it routinely discover missing risk assessments or undocumented AI system life cycles mid-audit, when fixes are most expensive.

Repeat the assessment after major remediation work, when you deploy or materially change an AI system, when your role with respect to AI changes (for example, you start fine-tuning models instead of only consuming APIs), and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.

What the 38 Annex A Controls cover

Annex A of ISO/IEC 42001 provides 38 reference controls organized into nine control objectives, A.2 through A.10. They are not all mandatory: you select the controls your AI risk treatment requires and justify inclusions and exclusions in your Statement of Applicability. Together they span the full life of an AI system, from policy and accountability through data management, impact assessment, transparency, responsible use, and third-party relationships.

ISO/IEC 42001 Annex A Control objectives and what they cover
ObjectiveControl familyControlsWhat it covers
A.2Policies related to AI3An AI policy for developing or using AI systems, alignment with other organizational policies, and scheduled policy reviews.
A.3Internal organization2Defined AI roles and responsibilities, and a process for reporting concerns about AI systems across their life cycle.
A.4Resources for AI systems5Documenting the data, tooling, system, computing, and human resources behind each AI system life cycle stage.
A.5Assessing impacts of AI systems4A repeatable AI system impact assessment process covering individuals, groups of individuals, and societies, with documented, retained results.
A.6AI system life cycle9Responsible development objectives and processes, requirements and specifications, design documentation, verification and validation, deployment, operation and monitoring, technical documentation, and event logging.
A.7Data for AI systems5Data management for AI development: acquisition and selection, data quality requirements, provenance recording, and data preparation criteria.
A.8Information for interested parties4User documentation, channels to report adverse impacts, incident communication plans, and reporting obligations to interested parties.
A.9Use of AI systems3Processes and objectives for responsible use of AI systems, and ensuring systems are used according to their intended uses.
A.10Third-party and customer relationships3Allocating AI life cycle responsibilities across partners, suppliers, customers, and third parties, and keeping supplier usage aligned with your responsible AI approach.

How the Basic and Standard scopes map to a Statement of Applicability

The Statement of Applicability (SoA) is the document Clause 6.1.3 requires: a list of the controls you consider necessary, with justification for every inclusion and exclusion. Auditors treat it as the index to your whole AIMS, and it is usually the first document a certification body asks for.

The two assessment scopes in the tool map directly onto SoA preparation. The Basic (Level 1) scope covers the Clause 4 to 10 management system requirements, which are mandatory for every organization and are never excluded in an SoA; assessing them first tells you whether the management system itself (context, leadership, risk processes, support, operation, evaluation, and improvement) stands up.

The Standard (Level 2) scope adds all 38 Annex A controls, which is precisely the set you must dispose of in the SoA. Your assessment results give each control a status: compliant controls become "implemented" entries, partially compliant and non-compliant controls become "planned" entries tied to your remediation roadmap dates, and controls you mark not applicable become documented exclusions with your reasoning. Run the Standard scope and you have effectively drafted the evidence base for your first SoA.

Gap Assessment vs Internal Audit vs Certification Audit

A gap assessment is a diagnostic you run for yourself before building your AIMS; an internal audit is the recurring conformance check Clause 9.2 requires once the AIMS exists; a certification audit is the independent, two-stage examination by an accredited body that results in an ISO/IEC 42001 certificate. They answer different questions at different times, and none replaces the others.

Comparison of ISO 42001 Gap assessment, Internal audit, and Certification audit
Gap assessmentInternal audit (Clause 9.2)Certification audit
PurposeMeasure your current AI management system against ISO/IEC 42001 to find and prioritize gaps before you invest in remediation.Verify that your implemented AIMS conforms to ISO/IEC 42001 and your own requirements, and is effectively maintained.Independent verification by an accredited certification body that your AIMS conforms to ISO/IEC 42001, leading to a certificate.
Who performs itYou (self-assessment) or a consultant. No independence requirement.Internal staff or an outsourced auditor who is objective and impartial (they cannot audit their own work).An accredited third-party certification body.
Required by the standardNo. It is a preparatory best practice, not a requirement.Yes. Clause 9.2 requires internal audits at planned intervals.Only if you want certification. Conformance without certification is possible.
Typical timingAt the start of your ISO 42001 journey, and again after major remediation or AI system changes.After the AIMS is implemented, then on a recurring audit programme.After at least one internal audit and management review cycle. Stage 1 reviews documentation, Stage 2 audits implementation.
OutputA gap report: compliance score, risk-ranked findings, and a remediation roadmap.Audit report with nonconformities and observations feeding corrective action (Clause 10.2).Audit findings and, on success, an ISO/IEC 42001 certificate with surveillance audits in following years.
What happens with findingsFindings become your remediation plan and inform your Statement of Applicability. Nothing is reported externally.Findings are reported to management and tracked to closure as corrective actions.Major nonconformities block certification until resolved; minors require a corrective action plan.

ISO 42001 Clause-by-Clause Reference

The table below summarizes every mandatory requirement in Clauses 4 to 10 of ISO/IEC 42001:2023 and the evidence auditors typically expect to see for each. The summaries are condensed guidance prepared by IRM Consulting & Advisory, not verbatim standard text; the assessment tool above walks you through all 27 of these requirements at either scope.

ISO/IEC 42001 Clauses 4 to 10 requirement summaries and typical audit evidence
ClauseRequirementSummaryEvidence auditors expect
4.1Understanding the organization and its contextDetermine the internal and external issues relevant to your AI management system, and your roles with respect to AI systems (provider, producer, user, partner, subject, authority).Documented context analysis and AI role determination.
4.2Needs and expectations of interested partiesIdentify the interested parties relevant to the AIMS, their requirements, and which requirements the AIMS will address.Interested party and requirements register.
4.3Scope of the AI management systemDefine the boundaries and applicability of the AIMS, considering context and interested party requirements.A documented, approved scope statement.
4.4AI management systemEstablish, implement, maintain, continually improve, and document the AIMS and its processes.AIMS documentation and process interactions.
5.1Leadership and commitmentTop management demonstrates leadership: AI policy and objectives set, AIMS integrated into business processes, resources provided, improvement promoted.Management meeting records and resourcing decisions.
5.2AI policyEstablish an AI policy appropriate to the organization that frames AI objectives and commits to requirements and continual improvement.The approved, communicated AI policy document.
5.3Roles, responsibilities and authoritiesAssign and communicate responsibilities for AIMS conformance and for reporting AIMS performance to top management.Role descriptions or a RACI matrix.
6.1.1Risks and opportunities (general)Determine the risks and opportunities the AIMS must address and establish AI risk criteria.Documented AI risk criteria and risk register.
6.1.2AI risk assessmentDefine a repeatable AI risk assessment process that identifies, analyses, and evaluates AI risks against your criteria.Risk assessment procedure and assessment records.
6.1.3AI risk treatmentSelect treatment options, determine necessary controls, compare against Annex A, and produce a Statement of Applicability and treatment plan.Statement of Applicability and approved risk treatment plan.
6.1.4AI system impact assessmentDefine a process to assess consequences of AI systems for individuals, groups, and societies.Impact assessment procedure and documented results.
6.2AI objectives and planningSet measurable, monitored, communicated AI objectives at relevant functions, with plans to achieve them.Documented objectives with owners, timelines, and evaluation methods.
6.3Planning of changesCarry out changes to the AIMS in a planned manner.Change plans and records.
7.1ResourcesProvide the resources needed to establish, implement, maintain, and improve the AIMS.Budgets, staffing, and tooling decisions.
7.2CompetenceDetermine and ensure the competence of people whose work affects AI performance.Competency matrix and training records.
7.3AwarenessEnsure people know the AI policy, their contribution, and the implications of nonconformance.Awareness training and communication evidence.
7.4CommunicationDetermine what to communicate about the AIMS, when, with whom, and how.A communication plan.
7.5Documented informationCreate, update, and control the documented information the AIMS requires, including protection, versioning, retention, and disposition.Document control procedure and controlled records.
8.1Operational planning and controlPlan and control the processes that implement your Clause 6 actions, including externally provided processes and services.Process criteria, operating records, and supplier controls.
8.2AI risk assessment (operational)Perform AI risk assessments at planned intervals and on significant change.Dated risk assessment results.
8.3AI risk treatment (operational)Implement the risk treatment plan, verify effectiveness, and treat newly identified risks.Treatment implementation and verification records.
8.4AI system impact assessment (operational)Perform AI system impact assessments at planned intervals and on significant change.Dated impact assessment results.
9.1Monitoring, measurement, analysis, evaluationDecide what to monitor and measure, with what methods and timing, and evaluate AIMS performance.Metrics definitions and evaluation reports.
9.2Internal auditRun an internal audit programme at planned intervals with objective auditors and defined criteria and scope.Audit programme, audit reports, and auditor selection rationale.
9.3Management reviewTop management reviews the AIMS at planned intervals with defined inputs and documented results.Management review minutes and decisions.
10.1Continual improvementContinually improve the suitability, adequacy, and effectiveness of the AIMS.Improvement log and implemented changes.
10.2Nonconformity and corrective actionReact to nonconformities, correct them, address root causes, and verify corrective action effectiveness.Nonconformity register and corrective action records.

Closing the gaps is where most organizations want help. IRM's AI Governance services build right-sized AI management systems for SMBs and startups, and our Virtual CISO services take teams from gap assessment through certification readiness for ISO 42001, ISO 27001, CMMC and SOC 2.

floating circle
Frequently Asked Questions

ISO 42001 Gap Assessment FAQs

Yes. The ISO 42001 Gap Assessment is a free, self-serve tool. You capture your company profile, choose your assessment scope, assess each ISO/IEC 42001:2023 requirement and Annex A control, and download a professional report with a remediation roadmap at no cost.

ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems (AIMS), published by ISO and IEC. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, so organizations that develop, provide, or use AI systems do so responsibly. Clauses 4 to 10 define the mandatory management system requirements, and Annex A provides 38 reference control objectives and controls.

Basic (Level 1) assesses the mandatory AI management system requirements of Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, and improvement. Standard (Level 2) covers everything in Basic plus all 38 Annex A control objectives and controls, spanning AI policies, internal organization, resources, impact assessments, the AI system life cycle, data, transparency, responsible use, and third-party relationships.

Each requirement and control is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).

The report includes an executive summary with your compliance score and top risks, detailed findings for every assessed clause requirement and Annex A control, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.

No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.

No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice, and it is an independent tool that is not affiliated with or endorsed by ISO or IEC. We recommend you seek advice from a Virtual CISO to validate findings, build your Statement of Applicability, and prepare for certification.

Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.