One of the free compliance gap assessments from Governance Docs.

Most organisations are further into AI than they think, and less able to show how they govern it than they assume. Someone is already using a generative tool on customer data. A model is already shaping a decision that affects a person. The question is not whether you have AI to govern — it is whether you could demonstrate that you do.

This assessment scores you against every requirement of ISO/IEC 42001:2023 — the management system clauses and all 38 Annex A controls. Free, saved as you go, about an hour.

First question: are you a provider or a deployer?

This is clause 4.1, and nearly everything downstream depends on it. The same organisation is usually both — a provider of the model it built, a deployer of the three tools it bought — and the obligations diverge sharply.

Your roleWhat it meansWhere the weight falls
Developer / providerYou build, train or substantially modify an AI system, then make it available to othersA.6 life cycle, A.7 data, A.8 information for users
Deployer / userYou use someone else’s AI system in your own operationsA.9 responsible use, A.5 impact assessment, A.10 supplier relationships
BothThe usual position for anyone shipping a product with AI in itEverything — and you must record which role applies to which system

The assessment does not make you choose globally, because a single answer would be wrong for most organisations. It asks about each requirement on its own terms, and the report records what you excluded and whether the exclusion holds together.

What this assessment covers

67 requirements: 29 across the management system clauses, and all 38 Annex A controls.

DomainRequirementsWhat it asks about
Clause 4 — Context4Your role, scope by AI system, interested parties including affected individuals
Clause 5 — Leadership3The AI policy, executive commitment, who is accountable for an outcome
Clause 6 — Planning6AI risk assessment and treatment, impact assessment, the Statement of Applicability
Clause 7 — Support7Competence, AI literacy, communication, document control
Clause 8 — Operation4Running the risk and impact processes and keeping the records
Clause 9 — Performance evaluation3Monitoring, drift, internal audit, management review
Clause 10 — Improvement2Nonconformity and corrective action reaching into model behaviour
A.2 — Policies related to AI3The AI policy, its alignment with your other policies, its review
A.3 — Internal organization2Roles, and a route for staff to raise a concern
A.4 — Resources for AI systems5Data, tooling, compute and people, documented per system
A.5 — Assessing impacts4Impact on individuals, groups and society, and the record of it
A.6 — AI system life cycle9Design, requirements, verification, deployment, monitoring, logging
A.7 — Data for AI systems5Acquisition, provenance, quality and preparation of training data
A.8 — Information for interested parties4User documentation, external reporting, incident communication
A.9 — Use of AI systems3Responsible use, intended use, and what to do about shadow AI
A.10 — Third parties and customers3Responsibility across the value chain, suppliers, customers

Our breakdown of the ISO 42001 Annex A controls goes into what each one asks for, and the ISO 42001 checklist sets out the order to work through them.

The EU AI Act overlap

These are different instruments — one a voluntary certifiable standard, the other law — and a certificate is not compliance with the Act. The artefacts do overlap, though: an AI system inventory, an impact assessment process, technical documentation and a clear accountability record serve both. Building them once is worth doing deliberately. We have set out where the two meet, and where they do not, in ISO 42001 vs the EU AI Act.

How the scoring works

Five levels. Anything marked not applicable leaves the calculation rather than counting as zero — which matters more here than in most standards, because a deployer legitimately excludes a good deal of Annex A.6.

Your answerWeightWhat it means
Not started0.00No policy, process or activity exists for this requirement.
Planned0.25Approach agreed and scheduled, but nothing is in place yet.
Partially implemented0.50In place for part of the scope, or applied inconsistently.
Implemented, not evidenced0.75Operating as intended — but you could not prove it to an auditor today.
Implemented and evidenced1.00Operating as intended, with records an auditor can sample.

In AI governance the 0.75 answer is unusually common, and it is worth understanding why. Teams building models genuinely do evaluate them, genuinely do think about bias, and genuinely do decide who reviews an output — in conversation, in a notebook, in someone’s head. None of that is evidence. An AI management system is largely the discipline of recording decisions you were already making, and that is where most of the available score sits.

Free score, or the full report

FreeFull report
Work through all 67 requirementsYesYes
Save and return as often as you likeYesYes
Overall readiness scoreYesYes
Which domains hold your gapsYesYes
Your score for each domainYes
Every open gap, listed and prioritisedYes
A remediation plan, weakest control firstYes
The document that closes each gap, namedYes
Branded PDF reportYes
Your assessment as a live Excel workbookYes

A free account is needed to see your score. The report is bought once for that assessment, not by subscription, and you can regenerate it free after updating your answers.

What to do with your score

ISO 42001 scores come out lower than people expect. That reflects how new the standard is, not how badly you are managing AI.

  • Below 40% — start with the inventory, not the policy. You cannot govern systems you have not listed, and A.4 plus clause 4.3 are what everything else leans on. An AI system register with an accountable owner per entry moves more of this framework than any single document.
  • 40% to 70% — you have policy and are missing process. Look at A.5 and clause 6.1.4: impact assessment is the requirement most often written as an intention and least often performed — and the one that also serves the EU AI Act. See our guide to the AI system impact assessment.
  • Above 70% — you are ahead of most of the market. Remaining gaps are likely in A.7 data provenance and A.6.2.8 logging, which are engineering work rather than governance work and need a different conversation with a different team.

Whatever the band, check A.9 honestly. Shadow AI — staff using tools nobody approved, on data nobody assessed — is the most common real exposure and the least likely to surface in a policy review.

Where this fits

Closing the gaps

The full report includes your assessment as an Excel workbook with the scoring still live, so you can keep working in a file you control and hand it to a colleague or an auditor without them needing an account here.

If you already know where your gaps are and need the documentation, the ISO 42001 Toolkit covers every requirement in this assessment, and the EU AI Act Toolkit covers the obligations the standard does not.

Frequently asked questions

Is the ISO 42001 gap analysis free?

Yes. All 67 requirements and your overall readiness score cost nothing. A free account is needed to view the score. The detailed report is a separate one-off purchase.

We only use AI tools we bought. Does ISO 42001 still apply?

Yes, as a deployer. You will legitimately exclude much of Annex A.6, which covers building systems — but A.9 responsible use, A.5 impact assessment and A.10 supplier relationships apply squarely, and that is where most deployers find their gaps. Mark what does not apply and the report accounts for it.

Does ISO 42001 make us compliant with the EU AI Act?

No. ISO 42001 is a voluntary management system standard; the Act is law with its own obligations. The two overlap usefully, but a certificate is not a defence.

How long does it take?

About an hour for a first pass. Answers save as you give them and the assessment reopens where you stopped.

Which edition does it assess?

ISO/IEC 42001:2023, the first edition, including all 38 Annex A controls.

What happens to my answers?

They describe how you currently govern your AI systems, so they are treated as confidential: linked to your account, never shared, and used only to produce your score and report. You can request a copy or deletion at any time. See our privacy policy.