vista infosec white

ISO IEC 42001 Gap Assessment Guide

ISO IEC 42001 Gap Assessment Guide

Most organisations don’t fail an ISO/IEC 42001 audit because they lack an AI policy — they fail because they can’t prove a control operates, only that it exists on paper. Published in December 2023, ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence, pairing ten management clauses with 38 Annex A controls scored against a five-level maturity model. Auditors don’t ask whether you have a policy; they ask for evidence — a Statement of Applicability, a completed AI system impact assessment, a gap register with named owners and dates. This toolkit shows you exactly where your AIMS stands, clause by clause, before an auditor or a regulator finds the gap first.

Who should read this: CISOs · CIOs · CTOs · AI & Data Governance Leads · Compliance Officers Boards & Executive Leadership · AI System Owners & Product Teams

Download the White Paper

✔ The anatomy of ISO/IEC 42001 — 10 clauses on a Plan–Do–Check–Act cycle

✔ The 3 artefacts every auditor asks for: AISIA, risk treatment plan, and Statement of Applicability

✔ A 5-step gap-assessment method, from scope to a prioritised gap register

✔ A 5-level maturity model for scoring every clause and control against evidence

✔ The full checklist covering all 38 Annex A controls across nine objectives

✔ A worked example — gap-assessing a customer-service chatbot to audit-ready

✔ The evidence pack auditors expect before a Stage 1 audit

✔ A mapping from ISO/IEC 42001 to the EU AI Act’s high-risk obligations

✔ How to integrate a new AIMS with your existing ISO 27001/27701 setup

✔ Common gap-assessment mistakes, plus a 90-day roadmap to certification

Expert Auditors. Faster Certification.

 

European Operations
European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
Visit Zulon Audits →