Download this resource
Please enter your details to access the download.
ISO/IEC 42001:2023 introduces a structured framework for managing AI responsibly, but knowing where your organisation actually stands against its requirements is the first challenge. This free gap analysis tool walks you through every clause and Annex A control, helping you identify priorities, assign ownership, and build a clear action plan before you engage a certification body or consultant.
What the Tool Covers
The workbook maps to the full structure of ISO/IEC 42001:2023, including Annex A controls that many simplified checklists omit.
- All seven clause sections: Context, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement
- Annex A controls A.2 through A.10, covering AI ethics policy, impact assessments, data governance, transparency obligations, acceptable use, and supplier management
- A weighted scoring model (0 to 3) that auto-calculates your overall maturity level and flags critical gaps
- An auto-populated action plan drawing on your top-ranked priority items
- Deep-dive registers for AI use cases, suppliers, data governance, oversight and transparency, and incident monitoring
Who It Is For
This tool is designed for organisations that develop, provide, or use AI systems and are considering ISO 42001 certification, or want to strengthen internal AI governance ahead of regulatory scrutiny. It is particularly useful for:
- In-house compliance, risk, or IT teams conducting a readiness assessment before engaging an auditor
- Consultants supporting clients through the early stages of an ISO 42001 programme
- Organisations already certified to ISO 27001 or ISO 9001 who are extending their management system to cover AI
No prior knowledge of ISO 42001 is required. The workbook includes guidance notes, a scoring model explanation, and a navigation tab to orient first-time users.
How the Scoring Works
Each question is scored on a four-point scale:
| Score | What It Means |
|---|---|
| 0 | Not in place |
| 1 | Partially in place or informal |
| 2 | Mostly in place but inconsistent |
| 3 | Fully in place and evidenced |
The tool calculates your overall percentage score and maturity level automatically, segments results by clause section, and surfaces your highest-priority gaps using a weighted ranking model that accounts for both clause criticality and the priority you assign.
What Happens After the Assessment
A gap analysis is the starting point, not the destination. Once you have completed the workbook, your next steps will typically involve:
Engaging a certification body. Accredited ISO 42001 certification bodies in the UK, US, and Ireland can provide a formal stage-one audit against the standard. Accreditation is granted by national bodies such as UKAS in the UK, ANAB in the US, and INAB in Ireland, and is the clearest signal that an auditor's competence has been independently verified.
Working with a consultant. If significant gaps emerge, an experienced ISO 42001 consultant can help you build the policies, processes, and evidence required before your formal audit. ISOCentral lists verified consultants across the UK, US, and Ireland.
Building your documentation. The evidence column in the gap analysis identifies what you will typically need at audit. Common requirements include an AI policy, risk assessments, AI impact assessments, data governance records, and a monitoring and incident log.
About ISOCentral
ISOCentral is an independent resource for organisations navigating ISO certification. We maintain directories of accredited certification bodies, verified consultants, and software providers across the UK, US, and Ireland, covering ISO 9001, ISO 27001, ISO 14001, ISO 45001, ISO 22301, ISO 13485, and ISO 42001.
