ISO 42001 gap assessment for UK organisations
Check how close your AI management system is to ISO/IEC 42001 before an internal audit or a certification body's visit. Rate the clause 4 to 10 requirements and the Annex A controls, then download a gap list, remediation plan and draft Statement of Applicability.
Nothing you enter leaves your browser. A self-assessment, not an audit or certification.
Also for: United States and international · Deutsch (EU AI Act) · Australia · Canada
Your ISO/IEC 42001 readiness
| Area | Score | Progress |
|---|
Paid options
AI Governance Toolkit (instant download)
AI Governance Toolkit Starter
$199 one-time
AI use and governance policy (Word), AI system inventory and risk register (Excel), AI system risk assessment (Excel) and a 30-day start-here plan.
AI Governance Toolkit Professional
$599 one-time
Everything in Starter, plus an ISO/IEC 42001 gap assessment workbook, a NIST AI RMF mapping, AI vendor contract clauses and a days 31–90 plan toward an ISO/IEC 42001 certification audit.
Pay by card · instant download · all sales final (refund policy)
Prices in US dollars.
Save & monitor this free in Agent Trust Cloud
Gap list and remediation plan
| Priority | Ref | Requirement | Current | Target date |
|---|
Statement of Applicability (draft)
| Control | Topic | Applicable | Status |
|---|
Evidence checklist
What to collect for each gap. Tick items off as you go (nothing is saved).
ISO 42001 in the UK
The UK government's Introduction to AI assurance (DSIT) describes assurance techniques such as risk assessments, impact assessments, audits and conformity with standards. An ISO/IEC 42001 gap assessment is a practical first step: it shows which parts of an AI management system you can already evidence, and what to fix before an internal audit or a certification body's audit.
UK GDPR still applies to personal data used by your AI systems; record that work under Annex A data controls (A.7) and impact assessments (A.5).
How the score works
Rate each requirement from 0 (not in place) to 3 (in place with evidence). Annex A controls can be marked not applicable. Each area's score is the points you have divided by 3 × the applicable items; unanswered items count as 0.
- Under 40%: early stage
- 40 to 69%: developing
- 70 to 89%: advanced
- 90% or more: strong, ready for an internal audit
Every requirement in clauses 4 to 10 is mandatory, so if any of them is not in place at all, the band stays at "developing" whatever the percentage.
Gaps are prioritised: clause requirements at level 0 or 1 are high priority, at level 2 medium. Annex A controls at level 0 are high priority for core controls (AI policy, AI roles, impact assessment, verification and validation, monitoring, event logs, data quality, user information, incident communication, intended use and suppliers) and medium otherwise; level 1 is medium and level 2 low. Target dates are 30, 90 and 180 days from today.
What you can download
- Excel workbook: Summary (scores by clause and Annex A objective, overall readiness and band), Clauses, Statement of Applicability and remediation Plan. Levels and applicability are input cells; every score, status and justification is a formula.
- Word report: scores, gap list with target dates, the draft Statement of Applicability and the evidence checklist.
- CSV gap checklist: one row per gap, highest priority first, with what good looks like, the evidence to collect, the target date and empty Owner and Done columns. Opens in Excel, Google Sheets or Numbers.
- PDF: use "Print or save as PDF".
See all 38 ISO 42001 Annex A controls with evidence examples, or work through the ISO 42001 checklist.
About ISO/IEC 42001
ISO/IEC 42001:2023 is the international standard for an AI management system: the policies, roles, risk and impact assessments, controls, monitoring and improvement an organisation uses to develop, provide or use AI responsibly. Organisations can be certified against it by accredited certification bodies (see ISO 42001 certification). This tool summarises the requirement topics in its own words; the standard itself is available from ISO (iso.org/standard/42001).
ISO 42001 guides
- ISO 42001 checklist: tick off the documents, clause requirements and Annex A controls, then download the list as CSV or Word.
- ISO 42001 controls (Annex A): every Annex A control in plain language, with what good looks like and typical evidence.
- ISO 42001 certification: how accredited certification works: Stage 1 and Stage 2 audits, surveillance and published audit fees.
- What is ISO 42001?: what the standard covers, how it is structured, who it is for and where to get the official text.
- ISO 42001 Statement of Applicability: what the SoA records for each Annex A control, how to justify exclusions, and a template of all the controls.
Questions
Is this an ISO 42001 certification?
No. It's a self-assessment that finds gaps before an internal audit or a certification body's audit. Only an accredited certification body can certify an AI management system.
Can we exclude Annex A controls?
Yes, where a control isn't relevant to the AI systems in scope. Choose 'Not applicable' and the draft Statement of Applicability records it as excluded; write down your reason. The requirements in clauses 4 to 10 can't be excluded.
Is anything I enter stored or sent?
No. The score and the Word and Excel files are built in this page. Nothing is stored after you close the tab, and the page blocks outgoing requests.
How does ISO 42001 relate to the EU AI Act?
The AI Act is EU law; ISO/IEC 42001 is a voluntary management system standard. A working AI management system gives you the risk, documentation, logging and oversight processes many AI Act obligations rely on, but on its own it doesn't show that you meet the Act.
Does the Excel file recalculate?
Yes. Levels (0 to 3) and Yes/No applicability are input cells. Every clause score, Annex A score, status, justification, total and the readiness band are formulas, so the workbook stays correct as you close gaps.