vista infosec white

ISO IEC 42001 Gap Assessment Guide

ISO IEC 42001 Gap Assessment Guide

Most organisations don’t fail an ISO/IEC 42001 audit because they lack an AI policy — they fail because they can’t prove a control operates, only that it exists on paper. Published in December 2023, ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence, pairing ten management clauses with 38 Annex A controls scored against a five-level maturity model. Auditors don’t ask whether you have a policy; they ask for evidence — a Statement of Applicability, a completed AI system impact assessment, a gap register with named owners and dates. This toolkit shows you exactly where your AIMS stands, clause by clause, before an auditor or a regulator finds the gap first.

Who should read this: CISOs · CIOs · CTOs · AI & Data Governance Leads · Compliance Officers Boards & Executive Leadership · AI System Owners & Product Teams

Download the White Paper

The anatomy of ISO/IEC 42001 — 10 clauses on a Plan–Do–Check–Act cycle

The 3 artefacts every auditor asks for: AISIA, risk treatment plan, and Statement of Applicability

A 5-step gap-assessment method, from scope to a prioritised gap register

A 5-level maturity model for scoring every clause and control against evidence

The full checklist covering all 38 Annex A controls across nine objectives

A worked example — gap-assessing a customer-service chatbot to audit-ready

The evidence pack auditors expect before a Stage 1 audit

A mapping from ISO/IEC 42001 to the EU AI Act’s high-risk obligations

How to integrate a new AIMS with your existing ISO 27001/27701 setup

Common gap-assessment mistakes, plus a 90-day roadmap to certification

Expert Auditors. Faster Certification.