Most organisations don’t fail an ISO/IEC 42001 audit because they lack an AI policy — they fail because they can’t prove a control operates, only that it exists on paper. Published in December 2023, ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence, pairing ten management clauses with 38 Annex A controls scored against a five-level maturity model. Auditors don’t ask whether you have a policy; they ask for evidence — a Statement of Applicability, a completed AI system impact assessment, a gap register with named owners and dates. This toolkit shows you exactly where your AIMS stands, clause by clause, before an auditor or a regulator finds the gap first.
Who should read this: CISOs · CIOs · CTOs · AI & Data Governance Leads · Compliance Officers Boards & Executive Leadership · AI System Owners & Product Teams
✔ The anatomy of ISO/IEC 42001 — 10 clauses on a Plan–Do–Check–Act cycle
✔ The 3 artefacts every auditor asks for: AISIA, risk treatment plan, and Statement of Applicability
✔ A 5-step gap-assessment method, from scope to a prioritised gap register
✔ A 5-level maturity model for scoring every clause and control against evidence
✔ The full checklist covering all 38 Annex A controls across nine objectives
✔ A worked example — gap-assessing a customer-service chatbot to audit-ready
✔ The evidence pack auditors expect before a Stage 1 audit
✔ A mapping from ISO/IEC 42001 to the EU AI Act’s high-risk obligations
✔ How to integrate a new AIMS with your existing ISO 27001/27701 setup
✔ Common gap-assessment mistakes, plus a 90-day roadmap to certification
VISTA InfoSec LLC,347 Fifth Ave,
Suite 1402-526, New York, NY 10016
© Copyright 2026. VISTA InfoSec. All Rights Reserved. | Disclosure Policy | Privacy Policy | Sitemap
Enquire Now
WhatsApp us