ISO 42001 Gap Analysis: What to Check Before Starting Certification

ISO 42001 gap analysis identifying gaps before certification
5/5 - (2 votes)

Last Updated on October 6, 2026 by Narendra Sahoo

An ISO 42001 gap analysis compares how you govern AI today with what ISO/IEC 42001:2023 requires. Do it before you commit to audit dates. You’ll learn what’s missing, what you can’t yet prove and what to fix first.

Quick answer

What it is: a structured review of your AI management system (AIMS) against ISO/IEC 42001:2023 clauses 4–10 and the applicable Annex A controls.

Is it mandatory? No. The standard requires an internal audit and management review, not a gap analysis.

What you get: prioritised gaps, each tied to a requirement, an owner and the missing evidence.

What Is an ISO 42001 Gap Analysis?

An ISO 42001 gap analysis measures the distance between your current AI governance and the requirements of ISO/IEC 42001:2023, which is a management system standard, not an AI security standard.

So the review goes past security controls into accountability, risk, impact on people, data, suppliers and how the system gets audited.

The question isn’t “do we have a policy?” It’s whether your AIMS is properly designed, actually implemented, operating consistently and able to produce evidence.

A gap analysis usually runs in six steps: confirm scope and inventory, review documents, interview owners, sample records, rate each area, agree priorities.

Not sure where your AIMS stands?
Assess your current ISO 42001 readiness before committing to certification.

Take the Readiness Checklist

Gap Analysis vs Readiness Assessment vs Internal Audit vs Certification Audit

The internal audit (ISO/IEC 42001, clause 9.2) and the certification audit (ISO/IEC 17021-1, ISO/IEC 42006) are defined by standards. The other two are industry terms that firms use differently. Here’s how we use them.

Activity Purpose Who performs it Typical timing What it examines Expected output
Gap analysis Find what’s missing In-house or independent assessor Before or during the build Current practice against clauses 4–10 and Annex A Gap register and remediation plan
Internal audit Check the AIMS conforms and is effectively implemented Objective, impartial auditors At planned intervals The AIMS against the standard and your own requirements Audit report and nonconformities
Readiness assessment Confirm you’re audit-ready In-house or independent assessor After remediation, before Stage 1 Whether the AIMS is operating and evidenced Go/no-go view with open issues
Certification audit Independent certification decision Certification body, ideally accredited Stage 1, then Stage 2 Stage 1: design and readiness. Stage 2: implementation and effectiveness Findings and certification decision

When Should You Conduct an ISO 42001 Gap Analysis?

Earlier than feels necessary. The useful moments:

  • •You’re starting ISO 42001 and need a baseline.
  • •AI is already live and governance grew up informally.
  • •You’re about to book a certification body.
  • •You hold ISO 27001 or run another management system.
  • •Your AI use has changed: new use case, model, data or role.
  • •Third-party or generative AI tools arrived faster than policy.

What Should an ISO 42001 Gap Analysis Check?

Clauses 4 to 10, plus the Annex A controls your risk treatment calls for. Annex A lists 38 reference controls in nine areas; your Statement of Applicability (SoA) justifies each inclusion and exclusion.

Clause numbers mark ISO requirements. “VISTA” marks our own method. The rest is good practice.

Area and clause Questions to ask Evidence to look for Weakness and next action
Context, scope, AI inventory (4.1–4.3; inventory is good practice) Is every AI system listed, including AI inside SaaS tools? Is your role for each determined (AI provider, producer, customer)? Scope statement; AI inventory; interested-party needs; roles Scope copied from the ISMS; embedded AI missing. Run discovery first.
Leadership, AI policy, roles, objectives (5, 6.2) Who’s accountable for AI, by name? Is the policy approved, with measurable objectives? Approved policy; role assignments; objectives A committee owns AI and nobody decides. Name owners.
AI risk assessment and treatment (6.1.2–6.1.3, 8.2–8.3) Are criteria defined and results repeatable? Are consequences for individuals and societies assessed? Method; register; treatment plan; residual-risk approval A security risk register relabelled “AI”. Add AI risk sources (Annex C).
AI system impact assessment (6.1.4, 8.4) Is there a defined process covering consequences for individuals, groups and societies? Do results feed the risk assessment? Documented assessment per system; re-assessment triggers A privacy DPIA standing in for it. ISO/IEC 42005 gives guidance.
Annex A and SoA (6.1.3) Was every Annex A control considered? Is each inclusion and exclusion justified? SoA with justifications traced to risks Everything “applicable”, no reasoning. Rebuild it from the treatment plan.
AI lifecycle, data, responsible use (8.1, A.6, A.7, A.9) Are validation, monitoring, logging, data provenance and intended use defined per system? Validation records; release approvals; event logs Controls cover in-house models only. Extend them to bought-in AI.
Third-party AI providers (A.10) Were suppliers assessed before use? Are responsibilities allocated between you, suppliers and customers? Due diligence; contract terms; supplier reviews Generative AI bought outside procurement. Bring it in.
Competence, awareness, documentation (7.2, 7.3, 7.5) Can people in AI roles show competence? Are records controlled? Competence records; training logs; document control One generic awareness course. Define role-based competence.
Monitoring, audit, review, improvement (9, 10) Has a full internal audit and management review been completed? Are nonconformities closed? Metrics; audit report; review minutes; corrective actions No full cycle before certification. Schedule both early.
Found more gaps than expected?
Rank them before you schedule anything with a certification body. The fix list drives your ISO 42001 certification timeline.

The VISTA 4-Level Evidence Test

A checklist shows something exists, not whether it would survive an audit. We test each important activity at four levels:

  • ✓Documented: is the process formally defined?
  • ✓Implemented: has it actually been introduced into operations?
  • ✓Operating: is it followed consistently?
  • ✓Evidenced: can you produce objective records of what happened, who was responsible, what was decided and how issues were handled?
The VISTA 4-Level Evidence Test is a practical readiness framework developed for this article; it is not an ISO-defined maturity model or certification requirement.
AIMS Area Documented Implemented Operating Evidence to Look For
AI inventory Inventory procedure Systems listed with owners Updated as tools change Change history; review dates
AI risk assessment Method and criteria Done for in-scope systems Repeated at intervals and on change Register versions; residual-risk approvals
AI system impact assessment Process and triggers Completed per system Re-run after significant change Signed assessments linked to risks
Supplier AI Supplier requirements Due diligence before onboarding Periodic supplier reviews Questionnaires; contract clauses; minutes
Monitoring Metrics and thresholds Live in production Alerts investigated and escalated Logs; incident tickets; trends
Internal audit Audit programme Audit performed Findings tracked to closure Audit report; corrective-action records

A level 1 gap is a writing job. Levels 3 and 4 take calendar time: operating evidence exists only once the process has run.

The AI Governance Traceability Test

The AI Governance Traceability Test is a VISTA practical assessment technique, not an ISO/IEC 42001 requirement. Pick one AI system and follow the thread:

AI System→Owner→Intended Use→Risk→Impact→Control→Evidence→Monitoring→Review / Decision

Take a customer-support assistant built on a third-party large language model.

  • •System, owner: inventoried; Head of Support owns it.
  • •Intended use: drafts replies for agents; never sends them.
  • •Risk: fabricated answers; customer data reaching the supplier.
  • •Impact: customers act on wrong refund advice.
  • •Control: agent approval before sending; contractual limits on data use.
  • •Evidence: approval logs; signed supplier terms.
  • •Monitoring: monthly accuracy sampling of drafts.
  • •Review/decision: quarterly review; decision to stay draft-only recorded.

If the thread breaks, you’ve found a gap, even when every document exists. Policies, spreadsheets and risk registers that don’t connect tell different stories, and auditors follow trails like this.

How Should ISO 42001 Gaps Be Prioritised?

ISO/IEC 42001 doesn’t grade gaps. Certification bodies classify audit findings as major or minor nonconformities under ISO/IEC 17021-1, but that happens at audit. For remediation planning we use three categories, for internal prioritisation only. They are not ISO-defined certification nonconformity classifications.

CRITICAL
Readiness gap

A foundational AIMS capability is absent or can’t be demonstrated.

Example: no AI system impact assessment process.

SIGNIFICANT
Gap

A process exists but has substantial implementation or evidence weaknesses.

Example: risk assessments cover only some in-scope systems.

IMPROVEMENT
Gap

The process operates but could be more consistent, traceable or measurable.

Example: supplier reviews with no fixed schedule.

Fix critical gaps first.

What Does a Gap Analysis Output Look Like?

An illustrative extract: examples, not findings from a real organisation.

Area Reviewed What Exists Gap Identified Evidence Missing Priority Recommended Action
AI system impact assessment DPIAs for two products No process covering groups and societies; HR screening tool unassessed Assessment record per system Critical Define process; assess highest-impact systems first
Statement of Applicability Draft marking all 38 controls applicable No justifications; no link to risks Reasoning per control Significant Rebuild from the risk treatment plan
Third-party AI Vendor security questionnaire No AI-specific due diligence; responsibilities unallocated Supplier assessments; contract terms Significant Add AI criteria to procurement
Monitoring Model accuracy dashboard No thresholds or escalation route Records of alerts handled Improvement Set thresholds and owners

Already ISO 27001 Certified? What Can You Reuse?

Much of the machinery, none of the conclusions. Both standards follow ISO’s harmonized structure. So you can often extend document control, internal audits, management reviews, and corrective actions. You usually do not need to rebuild them.

What your ISMS won’t give you:

  • •AI roles and an AI-specific scope
  • •A risk method covering harm to people and society
  • •AI system impact assessments
  • •AI lifecycle and data controls
  • •An SoA for ISO/IEC 42001’s Annex A controls

So ISO 27001 shortens the route but doesn’t establish ISO 42001 conformity. Our ISO 42001 vs ISO 27001 comparison has the detail. Aligned to the NIST AI RMF? The crosswalk NIST publishes shows what carries over.

What Happens After the Gap Analysis?

Give every gap in the register an owner and a date. Close the critical ones, then let processes run long enough to leave records.

Then come the internal audit and management review: both are requirements (clauses 9.2, 9.3), and Stage 1 of the certification audit checks they’re planned and performed.

Preparing for ISO 42001?
Talk to VISTA InfoSec about an ISO 42001 readiness assessment or gap analysis before you book the audit.

Explore ISO 42001 Services

Talk to VISTA InfoSec
Ready to See Where Your AIMS Actually Stands?
Get a structured ISO 42001 gap analysis or readiness assessment from VISTA InfoSec before you commit to certification dates.

Frequently Asked Questions

What is an ISO 42001 gap analysis?

An ISO 42001 gap analysis, sometimes called an ISO 42001 gap assessment, is a structured review of your AI management system against ISO/IEC 42001:2023. It covers clauses 4 to 10 and the applicable Annex A controls, and shows which requirements you meet and what evidence is missing.

Is a gap analysis mandatory for ISO 42001 certification?

No. A gap analysis isn’t one of the ISO 42001 certification requirements. The standard requires an internal audit (clause 9.2) and a management review (clause 9.3), and the Stage 1 certification audit checks that both are planned and performed. A gap analysis is good practice that makes those steps less of a gamble.

When should we conduct an ISO 42001 gap analysis?

Before you commit to certification dates, and ideally before writing new documentation. Repeat it after a significant change, such as a new AI use case, model or supplier: the standard expects AI risk and impact assessments at planned intervals and when significant changes are proposed or occur (clauses 8.2, 8.4).

How long does an ISO 42001 gap analysis take?

There’s no universal figure. Effort depends on how many AI systems are in scope, how complex they are, how many teams and sites are involved, how much documentation exists and how deeply records are sampled. VISTA’s ISO 42001 certification timeline shows where the gap analysis sits in the wider schedule.

What evidence should we prepare for an ISO 42001 gap analysis?

Bring what an auditor would ask for: AIMS scope, AI policy, AI system inventory, risk method and register, AI system impact assessments, Statement of Applicability, supplier due diligence, competence records, monitoring results, internal audit reports, management review minutes and corrective actions. If something doesn’t exist yet, that’s a finding, not a failure.

Can ISO 27001 documentation be reused for ISO 42001?

Partly. Both standards use ISO’s harmonized structure, so document control, internal audit, management review and corrective action can usually be extended. The AI-specific parts can’t be inherited: AI roles and scope, AI risk criteria, AI system impact assessments, lifecycle and data controls, and a Statement of Applicability for ISO/IEC 42001’s Annex A controls.

What is the difference between a gap analysis and an internal audit?

A gap analysis is a voluntary, early check of how far you are from the standard. An internal audit is a requirement of ISO/IEC 42001 (clause 9.2), carried out at planned intervals by objective, impartial auditors on an AIMS that’s already running. Its nonconformities need corrective action.

Who should carry out an ISO 42001 gap analysis?

An internal team can, if someone has audited a management system before and isn’t assessing their own work. Otherwise, or when your AI systems shape decisions about people, bring in an independent assessor. Certificates come from certification bodies, not from ISO, and ISO/IEC 17021-1 bars those bodies from management system consultancy. Whoever certifies you can assess your gaps but can’t design the fixes.