Last Updated on October 6, 2026 by Narendra Sahoo
An ISO 42001 gap analysis compares how you govern AI today with what ISO/IEC 42001:2023 requires. Do it before you commit to audit dates. You’ll learn what’s missing, what you can’t yet prove and what to fix first.
What it is: a structured review of your AI management system (AIMS) against ISO/IEC 42001:2023 clauses 4–10 and the applicable Annex A controls.
Is it mandatory? No. The standard requires an internal audit and management review, not a gap analysis.
What you get: prioritised gaps, each tied to a requirement, an owner and the missing evidence.
What Is an ISO 42001 Gap Analysis?
An ISO 42001 gap analysis measures the distance between your current AI governance and the requirements of ISO/IEC 42001:2023, which is a management system standard, not an AI security standard.
So the review goes past security controls into accountability, risk, impact on people, data, suppliers and how the system gets audited.
The question isn’t “do we have a policy?” It’s whether your AIMS is properly designed, actually implemented, operating consistently and able to produce evidence.
A gap analysis usually runs in six steps: confirm scope and inventory, review documents, interview owners, sample records, rate each area, agree priorities.
Gap Analysis vs Readiness Assessment vs Internal Audit vs Certification Audit
The internal audit (ISO/IEC 42001, clause 9.2) and the certification audit (ISO/IEC 17021-1, ISO/IEC 42006) are defined by standards. The other two are industry terms that firms use differently. Here’s how we use them.
| Activity | Purpose | Who performs it | Typical timing | What it examines | Expected output |
|---|---|---|---|---|---|
| Gap analysis | Find what’s missing | In-house or independent assessor | Before or during the build | Current practice against clauses 4–10 and Annex A | Gap register and remediation plan |
| Internal audit | Check the AIMS conforms and is effectively implemented | Objective, impartial auditors | At planned intervals | The AIMS against the standard and your own requirements | Audit report and nonconformities |
| Readiness assessment | Confirm you’re audit-ready | In-house or independent assessor | After remediation, before Stage 1 | Whether the AIMS is operating and evidenced | Go/no-go view with open issues |
| Certification audit | Independent certification decision | Certification body, ideally accredited | Stage 1, then Stage 2 | Stage 1: design and readiness. Stage 2: implementation and effectiveness | Findings and certification decision |
When Should You Conduct an ISO 42001 Gap Analysis?
Earlier than feels necessary. The useful moments:
- •You’re starting ISO 42001 and need a baseline.
- •AI is already live and governance grew up informally.
- •You’re about to book a certification body.
- •You hold ISO 27001 or run another management system.
- •Your AI use has changed: new use case, model, data or role.
- •Third-party or generative AI tools arrived faster than policy.
What Should an ISO 42001 Gap Analysis Check?
Clauses 4 to 10, plus the Annex A controls your risk treatment calls for. Annex A lists 38 reference controls in nine areas; your Statement of Applicability (SoA) justifies each inclusion and exclusion.
Clause numbers mark ISO requirements. “VISTA” marks our own method. The rest is good practice.
| Area and clause | Questions to ask | Evidence to look for | Weakness and next action |
|---|---|---|---|
| Context, scope, AI inventory (4.1–4.3; inventory is good practice) | Is every AI system listed, including AI inside SaaS tools? Is your role for each determined (AI provider, producer, customer)? | Scope statement; AI inventory; interested-party needs; roles | Scope copied from the ISMS; embedded AI missing. Run discovery first. |
| Leadership, AI policy, roles, objectives (5, 6.2) | Who’s accountable for AI, by name? Is the policy approved, with measurable objectives? | Approved policy; role assignments; objectives | A committee owns AI and nobody decides. Name owners. |
| AI risk assessment and treatment (6.1.2–6.1.3, 8.2–8.3) | Are criteria defined and results repeatable? Are consequences for individuals and societies assessed? | Method; register; treatment plan; residual-risk approval | A security risk register relabelled “AI”. Add AI risk sources (Annex C). |
| AI system impact assessment (6.1.4, 8.4) | Is there a defined process covering consequences for individuals, groups and societies? Do results feed the risk assessment? | Documented assessment per system; re-assessment triggers | A privacy DPIA standing in for it. ISO/IEC 42005 gives guidance. |
| Annex A and SoA (6.1.3) | Was every Annex A control considered? Is each inclusion and exclusion justified? | SoA with justifications traced to risks | Everything “applicable”, no reasoning. Rebuild it from the treatment plan. |
| AI lifecycle, data, responsible use (8.1, A.6, A.7, A.9) | Are validation, monitoring, logging, data provenance and intended use defined per system? | Validation records; release approvals; event logs | Controls cover in-house models only. Extend them to bought-in AI. |
| Third-party AI providers (A.10) | Were suppliers assessed before use? Are responsibilities allocated between you, suppliers and customers? | Due diligence; contract terms; supplier reviews | Generative AI bought outside procurement. Bring it in. |
| Competence, awareness, documentation (7.2, 7.3, 7.5) | Can people in AI roles show competence? Are records controlled? | Competence records; training logs; document control | One generic awareness course. Define role-based competence. |
| Monitoring, audit, review, improvement (9, 10) | Has a full internal audit and management review been completed? Are nonconformities closed? | Metrics; audit report; review minutes; corrective actions | No full cycle before certification. Schedule both early. |
The VISTA 4-Level Evidence Test
A checklist shows something exists, not whether it would survive an audit. We test each important activity at four levels:
- ✓Documented: is the process formally defined?
- ✓Implemented: has it actually been introduced into operations?
- ✓Operating: is it followed consistently?
- ✓Evidenced: can you produce objective records of what happened, who was responsible, what was decided and how issues were handled?
| AIMS Area | Documented | Implemented | Operating | Evidence to Look For |
|---|---|---|---|---|
| AI inventory | Inventory procedure | Systems listed with owners | Updated as tools change | Change history; review dates |
| AI risk assessment | Method and criteria | Done for in-scope systems | Repeated at intervals and on change | Register versions; residual-risk approvals |
| AI system impact assessment | Process and triggers | Completed per system | Re-run after significant change | Signed assessments linked to risks |
| Supplier AI | Supplier requirements | Due diligence before onboarding | Periodic supplier reviews | Questionnaires; contract clauses; minutes |
| Monitoring | Metrics and thresholds | Live in production | Alerts investigated and escalated | Logs; incident tickets; trends |
| Internal audit | Audit programme | Audit performed | Findings tracked to closure | Audit report; corrective-action records |
A level 1 gap is a writing job. Levels 3 and 4 take calendar time: operating evidence exists only once the process has run.
The AI Governance Traceability Test
The AI Governance Traceability Test is a VISTA practical assessment technique, not an ISO/IEC 42001 requirement. Pick one AI system and follow the thread:
Take a customer-support assistant built on a third-party large language model.
- •System, owner: inventoried; Head of Support owns it.
- •Intended use: drafts replies for agents; never sends them.
- •Risk: fabricated answers; customer data reaching the supplier.
- •Impact: customers act on wrong refund advice.
- •Control: agent approval before sending; contractual limits on data use.
- •Evidence: approval logs; signed supplier terms.
- •Monitoring: monthly accuracy sampling of drafts.
- •Review/decision: quarterly review; decision to stay draft-only recorded.
If the thread breaks, you’ve found a gap, even when every document exists. Policies, spreadsheets and risk registers that don’t connect tell different stories, and auditors follow trails like this.
How Should ISO 42001 Gaps Be Prioritised?
ISO/IEC 42001 doesn’t grade gaps. Certification bodies classify audit findings as major or minor nonconformities under ISO/IEC 17021-1, but that happens at audit. For remediation planning we use three categories, for internal prioritisation only. They are not ISO-defined certification nonconformity classifications.
A foundational AIMS capability is absent or can’t be demonstrated.
Example: no AI system impact assessment process.
A process exists but has substantial implementation or evidence weaknesses.
Example: risk assessments cover only some in-scope systems.
The process operates but could be more consistent, traceable or measurable.
Example: supplier reviews with no fixed schedule.
Fix critical gaps first.
What Does a Gap Analysis Output Look Like?
An illustrative extract: examples, not findings from a real organisation.
| Area Reviewed | What Exists | Gap Identified | Evidence Missing | Priority | Recommended Action |
|---|---|---|---|---|---|
| AI system impact assessment | DPIAs for two products | No process covering groups and societies; HR screening tool unassessed | Assessment record per system | Critical | Define process; assess highest-impact systems first |
| Statement of Applicability | Draft marking all 38 controls applicable | No justifications; no link to risks | Reasoning per control | Significant | Rebuild from the risk treatment plan |
| Third-party AI | Vendor security questionnaire | No AI-specific due diligence; responsibilities unallocated | Supplier assessments; contract terms | Significant | Add AI criteria to procurement |
| Monitoring | Model accuracy dashboard | No thresholds or escalation route | Records of alerts handled | Improvement | Set thresholds and owners |
Already ISO 27001 Certified? What Can You Reuse?
Much of the machinery, none of the conclusions. Both standards follow ISO’s harmonized structure. So you can often extend document control, internal audits, management reviews, and corrective actions. You usually do not need to rebuild them.
What your ISMS won’t give you:
- •AI roles and an AI-specific scope
- •A risk method covering harm to people and society
- •AI system impact assessments
- •AI lifecycle and data controls
- •An SoA for ISO/IEC 42001’s Annex A controls
So ISO 27001 shortens the route but doesn’t establish ISO 42001 conformity. Our ISO 42001 vs ISO 27001 comparison has the detail. Aligned to the NIST AI RMF? The crosswalk NIST publishes shows what carries over.
What Happens After the Gap Analysis?
Give every gap in the register an owner and a date. Close the critical ones, then let processes run long enough to leave records.
Then come the internal audit and management review: both are requirements (clauses 9.2, 9.3), and Stage 1 of the certification audit checks they’re planned and performed.
Frequently Asked Questions
What is an ISO 42001 gap analysis?
An ISO 42001 gap analysis, sometimes called an ISO 42001 gap assessment, is a structured review of your AI management system against ISO/IEC 42001:2023. It covers clauses 4 to 10 and the applicable Annex A controls, and shows which requirements you meet and what evidence is missing.
Is a gap analysis mandatory for ISO 42001 certification?
No. A gap analysis isn’t one of the ISO 42001 certification requirements. The standard requires an internal audit (clause 9.2) and a management review (clause 9.3), and the Stage 1 certification audit checks that both are planned and performed. A gap analysis is good practice that makes those steps less of a gamble.
When should we conduct an ISO 42001 gap analysis?
Before you commit to certification dates, and ideally before writing new documentation. Repeat it after a significant change, such as a new AI use case, model or supplier: the standard expects AI risk and impact assessments at planned intervals and when significant changes are proposed or occur (clauses 8.2, 8.4).
How long does an ISO 42001 gap analysis take?
There’s no universal figure. Effort depends on how many AI systems are in scope, how complex they are, how many teams and sites are involved, how much documentation exists and how deeply records are sampled. VISTA’s ISO 42001 certification timeline shows where the gap analysis sits in the wider schedule.
What evidence should we prepare for an ISO 42001 gap analysis?
Bring what an auditor would ask for: AIMS scope, AI policy, AI system inventory, risk method and register, AI system impact assessments, Statement of Applicability, supplier due diligence, competence records, monitoring results, internal audit reports, management review minutes and corrective actions. If something doesn’t exist yet, that’s a finding, not a failure.
Can ISO 27001 documentation be reused for ISO 42001?
Partly. Both standards use ISO’s harmonized structure, so document control, internal audit, management review and corrective action can usually be extended. The AI-specific parts can’t be inherited: AI roles and scope, AI risk criteria, AI system impact assessments, lifecycle and data controls, and a Statement of Applicability for ISO/IEC 42001’s Annex A controls.
What is the difference between a gap analysis and an internal audit?
A gap analysis is a voluntary, early check of how far you are from the standard. An internal audit is a requirement of ISO/IEC 42001 (clause 9.2), carried out at planned intervals by objective, impartial auditors on an AIMS that’s already running. Its nonconformities need corrective action.
Who should carry out an ISO 42001 gap analysis?
An internal team can, if someone has audited a management system before and isn’t assessing their own work. Otherwise, or when your AI systems shape decisions about people, bring in an independent assessor. Certificates come from certification bodies, not from ISO, and ISO/IEC 17021-1 bars those bodies from management system consultancy. Whoever certifies you can assess your gaps but can’t design the fixes.
Narendra Sahoo (PCI QSA, PCI SSFA, CISSP, CISA, CRISC, 27001 LA) is the Founder and Director of VISTA InfoSec, a global information security consulting firm. With 21 years of experience in information security consulting, assessment and compliance services, Narendra has helped organizations address complex cybersecurity and regulatory requirements across global markets.