ISO 42001 Gap Assessmentby Agent Trust Cloud

What is ISO 42001?

ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS): the policy, roles, risk and impact assessments, controls, monitoring and improvement an organisation uses to develop, provide or use AI responsibly. ISO and IEC published the first edition in December 2023, and organisations can be certified against it by accredited certification bodies.

Run the free ISO 42001 gap assessment

Key facts

Full referenceISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system
PublishedDecember 2023, edition 1, 51 pages
Written byISO/IEC JTC 1/SC 42, the joint ISO and IEC committee on artificial intelligence
CertifiableYes, by accredited certification bodies (see ISO 42001 certification)
Rules for certifiersISO/IEC 42006:2025, published July 2025
Where to get itiso.org/standard/42001 or your national standards body

How ISO/IEC 42001 is structured

Clauses 1 to 3 cover scope, references and terms. Clauses 4 to 10 are the requirements, and every one of them applies. Annex A lists 38 reference controls you select through risk treatment. Annex B gives guidance on implementing those controls, Annex C lists possible AI objectives and risk sources, and Annex D covers using the management system across domains and sectors.

PartWhat it covers (our summary)Items in our gap assessment
Clause 4Context of the organisation: Your context and AI roles, interested parties, the scope of the system, and the system itself4
Clause 5Leadership: Top management commitment, the AI policy, and roles and responsibilities3
Clause 6Planning: Risks and opportunities, AI risk assessment and treatment, the Statement of Applicability, AI system impact assessment, AI objectives and planned changes6
Clause 7Support: Resources, competence, awareness, communication and documented information5
Clause 8Operation: Running the processes, and carrying out risk assessments, risk treatment and impact assessments4
Clause 9Performance evaluation: Monitoring and measurement, internal audit and management review3
Clause 10Improvement: Continual improvement, nonconformity and corrective action2
A.2Policies related to AI3
A.3Internal organisation2
A.4Resources for AI systems5
A.5Assessing impacts of AI systems4
A.6AI system life cycle9
A.7Data for AI systems5
A.8Information for interested parties4
A.9Use of AI systems3
A.10Third-party and customer relationships3
Total65

Clause numbers and Annex A area names follow ISO/IEC 42001:2023; descriptions are our own.

Who it is for

Any organisation, of any size or sector, that develops, provides or uses AI systems. The standard asks you to state which of those roles you play for each AI system (clause 4.1), because a company that builds models faces different risks from one that buys an AI feature inside its CRM. The controls you select follow from that.

ISO 42001 and other AI frameworks

Getting the ISO 42001 PDF

The official text is copyrighted and sold by ISO and national standards bodies as a PDF or print copy. ISO's page offers a preview of the opening pages. Copies offered free elsewhere are usually unauthorised, and they may be drafts rather than the published standard. Everything on this site describes the requirements in our own words, so you can start the work before you buy.

Where to start

  1. Score your gaps against every clause requirement and Annex A control.
  2. Work through the ISO 42001 checklist of documents, requirements and controls.
  3. Read the plain-language Annex A controls.
  4. Plan the audits and budget with ISO 42001 certification.

Questions

What is ISO/IEC 42001:2023?

The international standard for an AI management system, published by ISO and IEC in December 2023. It sets requirements for how an organisation governs the AI systems it develops, provides or uses, and organisations can be certified against it.

Is there a free ISO 42001 PDF?

No legitimate one. The standard is copyrighted and sold by ISO and national standards bodies; ISO's page lets you preview the opening pages. Free summaries, checklists and templates (like the ones on this site) describe it in their own words.

Who needs ISO 42001?

No one is required to have it by law. It suits any organisation that develops, provides or uses AI systems and wants a structured way to manage the risks, often because customers ask for evidence of responsible AI.

How is ISO 42001 different from ISO 27001?

Both are management system standards with the same clause 4 to 10 structure, so they combine well. ISO/IEC 27001 is about information security; ISO/IEC 42001 is about the responsible development, provision and use of AI, including impact assessments for people and society.

How does ISO 42001 relate to the EU AI Act and the NIST AI RMF?

The EU AI Act is law in the EU; the NIST AI RMF is a voluntary US framework; ISO/IEC 42001 is a certifiable international standard. A working AI management system supplies much of the risk, documentation and oversight evidence the other two expect, but it doesn't by itself show that you meet the AI Act.

Sources