One of the free compliance gap assessments from Governance Docs.
Most organisations are further into AI than they think, and less able to show how they govern it than they assume. Someone is already using a generative tool on customer data. A model is already shaping a decision that affects a person. The question is not whether you have AI to govern — it is whether you could demonstrate that you do.
This assessment scores you against every requirement of ISO/IEC 42001:2023 — the management system clauses and all 38 Annex A controls. Free, saved as you go, about an hour.
First question: are you a provider or a deployer?
This is clause 4.1, and nearly everything downstream depends on it. The same organisation is usually both — a provider of the model it built, a deployer of the three tools it bought — and the obligations diverge sharply.
| Your role | What it means | Where the weight falls |
|---|---|---|
| Developer / provider | You build, train or substantially modify an AI system, then make it available to others | A.6 life cycle, A.7 data, A.8 information for users |
| Deployer / user | You use someone else’s AI system in your own operations | A.9 responsible use, A.5 impact assessment, A.10 supplier relationships |
| Both | The usual position for anyone shipping a product with AI in it | Everything — and you must record which role applies to which system |
The assessment does not make you choose globally, because a single answer would be wrong for most organisations. It asks about each requirement on its own terms, and the report records what you excluded and whether the exclusion holds together.
What this assessment covers
67 requirements: 29 across the management system clauses, and all 38 Annex A controls.
| Domain | Requirements | What it asks about |
|---|---|---|
| Clause 4 — Context | 4 | Your role, scope by AI system, interested parties including affected individuals |
| Clause 5 — Leadership | 3 | The AI policy, executive commitment, who is accountable for an outcome |
| Clause 6 — Planning | 6 | AI risk assessment and treatment, impact assessment, the Statement of Applicability |
| Clause 7 — Support | 7 | Competence, AI literacy, communication, document control |
| Clause 8 — Operation | 4 | Running the risk and impact processes and keeping the records |
| Clause 9 — Performance evaluation | 3 | Monitoring, drift, internal audit, management review |
| Clause 10 — Improvement | 2 | Nonconformity and corrective action reaching into model behaviour |
| A.2 — Policies related to AI | 3 | The AI policy, its alignment with your other policies, its review |
| A.3 — Internal organization | 2 | Roles, and a route for staff to raise a concern |
| A.4 — Resources for AI systems | 5 | Data, tooling, compute and people, documented per system |
| A.5 — Assessing impacts | 4 | Impact on individuals, groups and society, and the record of it |
| A.6 — AI system life cycle | 9 | Design, requirements, verification, deployment, monitoring, logging |
| A.7 — Data for AI systems | 5 | Acquisition, provenance, quality and preparation of training data |
| A.8 — Information for interested parties | 4 | User documentation, external reporting, incident communication |
| A.9 — Use of AI systems | 3 | Responsible use, intended use, and what to do about shadow AI |
| A.10 — Third parties and customers | 3 | Responsibility across the value chain, suppliers, customers |
Our breakdown of the ISO 42001 Annex A controls goes into what each one asks for, and the ISO 42001 checklist sets out the order to work through them.
The EU AI Act overlap
These are different instruments — one a voluntary certifiable standard, the other law — and a certificate is not compliance with the Act. The artefacts do overlap, though: an AI system inventory, an impact assessment process, technical documentation and a clear accountability record serve both. Building them once is worth doing deliberately. We have set out where the two meet, and where they do not, in ISO 42001 vs the EU AI Act.
How the scoring works
Five levels. Anything marked not applicable leaves the calculation rather than counting as zero — which matters more here than in most standards, because a deployer legitimately excludes a good deal of Annex A.6.
| Your answer | Weight | What it means |
|---|---|---|
| Not started | 0.00 | No policy, process or activity exists for this requirement. |
| Planned | 0.25 | Approach agreed and scheduled, but nothing is in place yet. |
| Partially implemented | 0.50 | In place for part of the scope, or applied inconsistently. |
| Implemented, not evidenced | 0.75 | Operating as intended — but you could not prove it to an auditor today. |
| Implemented and evidenced | 1.00 | Operating as intended, with records an auditor can sample. |
In AI governance the 0.75 answer is unusually common, and it is worth understanding why. Teams building models genuinely do evaluate them, genuinely do think about bias, and genuinely do decide who reviews an output — in conversation, in a notebook, in someone’s head. None of that is evidence. An AI management system is largely the discipline of recording decisions you were already making, and that is where most of the available score sits.
Free score, or the full report
| Free | Full report | |
|---|---|---|
| Work through all 67 requirements | Yes | Yes |
| Save and return as often as you like | Yes | Yes |
| Overall readiness score | Yes | Yes |
| Which domains hold your gaps | Yes | Yes |
| Your score for each domain | — | Yes |
| Every open gap, listed and prioritised | — | Yes |
| A remediation plan, weakest control first | — | Yes |
| The document that closes each gap, named | — | Yes |
| Branded PDF report | — | Yes |
| Your assessment as a live Excel workbook | — | Yes |
A free account is needed to see your score. The report is bought once for that assessment, not by subscription, and you can regenerate it free after updating your answers.
What to do with your score
ISO 42001 scores come out lower than people expect. That reflects how new the standard is, not how badly you are managing AI.
- Below 40% — start with the inventory, not the policy. You cannot govern systems you have not listed, and A.4 plus clause 4.3 are what everything else leans on. An AI system register with an accountable owner per entry moves more of this framework than any single document.
- 40% to 70% — you have policy and are missing process. Look at A.5 and clause 6.1.4: impact assessment is the requirement most often written as an intention and least often performed — and the one that also serves the EU AI Act. See our guide to the AI system impact assessment.
- Above 70% — you are ahead of most of the market. Remaining gaps are likely in A.7 data provenance and A.6.2.8 logging, which are engineering work rather than governance work and need a different conversation with a different team.
Whatever the band, check A.9 honestly. Shadow AI — staff using tools nobody approved, on data nobody assessed — is the most common real exposure and the least likely to surface in a policy review.
Where this fits
- ISO 42001 checklist — the 7 clauses and 38 controls, in working order
- ISO 42001 risk assessment — how the risk process is meant to run
- ISO 42001 Statement of Applicability — justifying what you excluded
- ISO 42001 certification timeline — what the whole project looks like
Closing the gaps
The full report includes your assessment as an Excel workbook with the scoring still live, so you can keep working in a file you control and hand it to a colleague or an auditor without them needing an account here.
If you already know where your gaps are and need the documentation, the ISO 42001 Toolkit covers every requirement in this assessment, and the EU AI Act Toolkit covers the obligations the standard does not.
Frequently asked questions
Is the ISO 42001 gap analysis free?
Yes. All 67 requirements and your overall readiness score cost nothing. A free account is needed to view the score. The detailed report is a separate one-off purchase.
We only use AI tools we bought. Does ISO 42001 still apply?
Yes, as a deployer. You will legitimately exclude much of Annex A.6, which covers building systems — but A.9 responsible use, A.5 impact assessment and A.10 supplier relationships apply squarely, and that is where most deployers find their gaps. Mark what does not apply and the report accounts for it.
Does ISO 42001 make us compliant with the EU AI Act?
No. ISO 42001 is a voluntary management system standard; the Act is law with its own obligations. The two overlap usefully, but a certificate is not a defence.
How long does it take?
About an hour for a first pass. Answers save as you give them and the assessment reopens where you stopped.
Which edition does it assess?
ISO/IEC 42001:2023, the first edition, including all 38 Annex A controls.
What happens to my answers?
They describe how you currently govern your AI systems, so they are treated as confidential: linked to your account, never shared, and used only to produce your score and report. You can request a copy or deletion at any time. See our privacy policy.