ISO 42001 Gap Assessmentby Agent Trust Cloud

ISO 42001 gap assessment for Australian organisations

Rate your AI management system against ISO/IEC 42001 and see how it lines up with Australia's Voluntary AI Safety Standard. You get a score by clause, prioritised gaps with target dates and a draft Statement of Applicability for Word and Excel.

Nothing you enter leaves your browser. A self-assessment, not an audit or certification.

Also for: United States and international · United Kingdom · Deutsch (EU AI Act) · Canada

Clause 4 Context of the organisation

You have recorded the internal and external issues that affect your AI work and the roles you play (for example developer, provider or user of AI systems).

You know who has a stake in your AI systems (customers, regulators, affected people, staff) and which of their requirements you will meet.

The boundaries are written down: which AI systems, teams, sites and activities are in or out of scope, and why.

The processes of the AI management system and how they connect are set up, run, maintained and improved.

Clause 5 Leadership

Top management visibly backs the AI management system: it provides resources, builds it into business processes and directs people to support it.

Top management has approved an AI policy that sets direction, commits to meeting requirements and to improvement, and has been communicated.

Responsibility for the AI management system is assigned, including who reports on its performance to top management.

Clause 6 Planning

Risks and opportunities that could affect what the management system achieves are identified, and actions are planned.

A defined, repeatable method assesses AI risks, with criteria for when a risk is acceptable.

Each AI risk has a chosen treatment; controls were compared with Annex A; a Statement of Applicability and a treatment plan are approved by the risk owners.

A process exists to assess the possible consequences of your AI systems for individuals, groups and society.

AI objectives are measurable, have owners, resources and deadlines, and are tracked.

Changes to the AI management system are planned and made in a controlled way.

Clause 7 Support

The people, budget and tools needed for the management system are identified and provided.

The competence needed for AI work is defined, and gaps are closed through training, mentoring or hiring.

People know the AI policy, how they contribute, and what happens if the system isn't followed.

You have decided what to communicate about the AI management system, when, to whom and how.

Required documents and records are created, approved, version-controlled, protected and kept.

Clause 8 Operation

AI processes run to defined criteria and controls, including processes you outsource.

AI risk assessments are run at planned intervals and when significant changes happen, and the results are kept.

The AI risk treatment plan is being implemented and its effect is checked.

Impact assessments are completed for your AI systems at planned intervals and on significant change.

Clause 9 Performance evaluation

You have decided what to monitor and measure, how and when, and you evaluate the results.

An internal audit programme checks the management system at planned intervals, with objective auditors.

Top management reviews the management system at planned intervals and records its decisions.

Clause 10 Improvement

You keep improving how suitable, adequate and effective the management system is.

Nonconformities are corrected, root causes are found, corrective actions are taken and records are kept.

Annex A · A.2 Policies related to AI

A documented policy guides how you develop, provide or use AI systems.

The AI policy fits with your other policies, such as security, privacy and quality.

The AI policy is reviewed at planned intervals and when something significant changes.

Annex A · A.3 Internal organisation

Roles and responsibilities for AI are defined and allocated to named people.

People can raise concerns about AI systems through a defined channel, without fear of reprisal.

Annex A · A.4 Resources for AI systems

The resources each AI system needs across its life cycle are identified and documented.

The data used by each AI system is documented.

Tools, frameworks, libraries and models in use are documented.

Computing and infrastructure resources are documented.

The people and skills needed at each life cycle stage are documented.

Annex A · A.5 Assessing impacts of AI systems

A process assesses the potential consequences of AI systems before and during use.

Impact assessment results are documented and kept for a defined period.

Impacts on people's rights, fairness, safety and wellbeing are assessed.

Wider effects on society (for example environment, employment, public trust) are assessed.

Annex A · A.6 AI system life cycle

Objectives for responsible AI development are set and built into the development process.

Design and development follow defined processes with responsible-AI checkpoints.

Requirements for new AI systems, or significant changes, are specified and agreed.

Design choices and development work are documented.

AI systems are tested against defined acceptance criteria before release and after changes.

A deployment plan is followed and release requirements are met before go-live.

AI systems in use are monitored for performance, errors, drift and misuse, with a plan to act.

Technical documentation is available to those who need it (users, partners, authorities).

AI systems record event logs at the right stages, and the logs are kept.

Annex A · A.7 Data for AI systems

Data management processes cover the data used to develop and improve AI systems.

Where data comes from, and your right to use it, are recorded.

Data quality requirements are defined and data is checked against them.

The origin and history of data can be traced through the life cycle.

Methods used to prepare data (cleaning, labelling, transformation) are defined and documented.

Annex A · A.8 Information for interested parties

Users receive the information they need to use the AI system appropriately, including its limits.

Interested parties can report adverse impacts of your AI systems.

There is a plan to tell users and others about AI incidents.

Obligations to report information about AI systems to interested parties are identified and met.

Annex A · A.9 Use of AI systems

Processes define how AI systems are used responsibly in your organisation.

Objectives guide the responsible use of AI systems.

AI systems are used only as intended and documented, with human oversight where it matters.

Annex A · A.10 Third-party and customer relationships

Responsibilities are split clearly between you, partners, suppliers and customers.

Suppliers of AI models, services and data are assessed and held to your responsible-AI requirements.

Customer needs and expectations are considered in how you provide AI systems.

ISO 42001 in Australia

Australia's AI Ethics Principles and the Voluntary AI Safety Standard are voluntary. Its guardrails overlap closely with ISO/IEC 42001, so one AI management system can serve both:

Voluntary AI Safety Standard guardrailWhere it sits in this assessment
Accountability and governanceClauses 5.1–5.3, A.2, A.3
Risk managementClauses 6.1.2, 6.1.3, 8.2, 8.3
Data governance and protectionA.4.3, A.7
Testing and monitoringA.6.2.4, A.6.2.6, 9.1
Human oversightA.9.4
Informing users and letting people contest outcomesA.8.2, A.8.3
Supply chain transparencyA.10
Record keeping7.5, A.6.2.8
Stakeholder engagement and impact4.2, A.5

How the score works

Rate each requirement from 0 (not in place) to 3 (in place with evidence). Annex A controls can be marked not applicable. Each area's score is the points you have divided by 3 × the applicable items; unanswered items count as 0.

Every requirement in clauses 4 to 10 is mandatory, so if any of them is not in place at all, the band stays at "developing" whatever the percentage.

Gaps are prioritised: clause requirements at level 0 or 1 are high priority, at level 2 medium. Annex A controls at level 0 are high priority for core controls (AI policy, AI roles, impact assessment, verification and validation, monitoring, event logs, data quality, user information, incident communication, intended use and suppliers) and medium otherwise; level 1 is medium and level 2 low. Target dates are 30, 90 and 180 days from today.

What you can download

See all 38 ISO 42001 Annex A controls with evidence examples, or work through the ISO 42001 checklist.

About ISO/IEC 42001

ISO/IEC 42001:2023 is the international standard for an AI management system: the policies, roles, risk and impact assessments, controls, monitoring and improvement an organisation uses to develop, provide or use AI responsibly. Organisations can be certified against it by accredited certification bodies (see ISO 42001 certification). This tool summarises the requirement topics in its own words; the standard itself is available from ISO (iso.org/standard/42001).

ISO 42001 guides

Questions

Is this an ISO 42001 certification?

No. It's a self-assessment that finds gaps before an internal audit or a certification body's audit. Only an accredited certification body can certify an AI management system.

Can we exclude Annex A controls?

Yes, where a control isn't relevant to the AI systems in scope. Choose 'Not applicable' and the draft Statement of Applicability records it as excluded; write down your reason. The requirements in clauses 4 to 10 can't be excluded.

Is anything I enter stored or sent?

No. The score and the Word and Excel files are built in this page. Nothing is stored after you close the tab, and the page blocks outgoing requests.

How does ISO 42001 relate to the EU AI Act?

The AI Act is EU law; ISO/IEC 42001 is a voluntary management system standard. A working AI management system gives you the risk, documentation, logging and oversight processes many AI Act obligations rely on, but on its own it doesn't show that you meet the Act.

Does the Excel file recalculate?

Yes. Levels (0 to 3) and Yes/No applicability are input cells. Every clause score, Annex A score, status, justification, total and the readiness band are formulas, so the workbook stays correct as you close gaps.

Sources