ISO/IEC
ISO/IEC 42001 Gap Assessment: How to Run One
Most explainers reduce this to "compare yourself against Annex A." The real scoping question is bigger — and if your organization already has ISO 27001 or SOC 2, the honest answer is that you're probably closer to ready than a from-scratch reading of the standard would suggest.
A gap assessment that only checks Annex A hands back a falsely optimistic result, because Annex A controls don't function without the clause 4-10 management-system machinery underneath them. Most descriptions of how to run this assessment skip that half entirely, collapsing the whole exercise into one sentence — compare what you do against Annex A — and in doing so skip the one variable that most changes how much work is actually ahead of a given organization: what management-system infrastructure already exists from a prior certification.
What a gap assessment actually compares
ISO/IEC 42001 has two parts, and a real gap assessment covers both. The first is the clause 4-10 management-system requirements shared with other ISO management-system standards: organizational context, leadership commitment, planning, support (resources, competence, awareness, documentation), operational controls, performance evaluation, and continual improvement. The second is Annex A — the AI-specific controls covering things like AI system impact assessments, data governance for training data, and AI risk management processes.
Teams that assess only against Annex A tend to walk away with a falsely optimistic picture, because Annex A controls are meaningless without the management-system machinery in clauses 4-10 that's supposed to operationalize and sustain them. A documented AI risk assessment methodology (Annex A) that nobody's leadership team ever formally reviewed (clause 9, management review) isn't a functioning control — it's a document.
Running the assessment: a practical process
A gap assessment that actually produces something useful follows roughly this sequence:
Gather what already exists. Pull every relevant policy, process document, risk register, and prior audit finding — from AI-specific governance work and from adjacent programs like an existing information security management system, if one exists.
Map it against each clause and control. Go through clauses 4-10 and every applicable Annex A control, and for each one, record what evidence exists today — not what should exist in principle.
Run structured interviews, not just a document review. This is the step that separates a useful gap assessment from a paperwork exercise. A policy document proves something was written; it doesn't prove the process actually runs. Talking to the people who'd be doing the work — the ones running risk assessments, maintaining the AI system inventory, handling incident response — surfaces the gap between "documented" and "actually happening" that a desk review alone misses entirely.
Produce a severity-ranked gap register. Not every gap is equally urgent. Separate genuine absence (nothing exists) from informal-but-real practice that just needs documentation, and flag which gaps would actually block a certification audit versus which are lower-priority maturity improvements.
Turn it into a remediation roadmap with real owners and timelines. A gap register that sits in a slide deck doesn't close gaps. Each item needs an accountable owner and a realistic date, tied to whatever certification timeline leadership has actually committed to.
The variable most explainers skip: what you already have from ISO 27001 or SOC 2
This is the section that actually changes how a reader should scope their project, and it's the part generic gap-assessment guides consistently leave out. ISO/IEC 42001 follows the same Annex SL high-level structure used across ISO management-system standards — including ISO 27001. An organization with an existing, functioning information security management system already has, in large part: a document control process, an internal audit program and the people trained to run it, a management review cadence with real leadership engagement, competence and training record-keeping, and a corrective action process for handling nonconformities.
None of that has to be rebuilt from scratch for 42001 — it needs to be extended to cover AI-specific scope, not reinvented. For an organization in that position, the gap assessment should be scoped explicitly to separate "we need this AI-specific control we've genuinely never had" from "we need to extend an existing 27001 process to also cover AI systems," because those are very different amounts of work, and a gap assessment that doesn't make that distinction will systematically overstate the effort ahead and risk killing a certification project on a budget estimate that was never accurate in the first place.
The gaps that show up most often
Regardless of starting point, certain gaps recur often enough to specifically check for:
- A formal AI-specific risk assessment methodology — many organizations have general enterprise risk management but nothing that specifically addresses AI system risk in a structured, repeatable way.
- An AI system inventory and impact assessment process — knowing what AI systems exist and having assessed their impact is foundational to Annex A, and it's one of the most commonly absent pieces even in organizations that consider themselves AI-governance-mature.
- Training-data governance controls — documented provenance, quality checks, and bias considerations for training data specifically, distinct from general data governance.
- AI-role-specific competence records — evidence that people responsible for AI risk and governance roles have the relevant training and competence, not just a general security-awareness record.
- An internal audit program scoped to include the AI management system — an existing internal audit function that's never actually audited anything AI-specific.
What to do with the results
The gap register is the input to a remediation roadmap, not the deliverable itself — a list of findings with no ownership or timeline attached tends to sit unused. Whether to run the assessment internally or bring in an external reviewer comes down to how much ISO management-system experience already exists in-house: an organization that's run a 27001 or 9001 certification before has the internal expertise to self-assess credibly, while a team doing this for the first time often gets more value from an external reviewer's independence and pattern-recognition than the cost would suggest. Either way, the output should be the same — a realistic picture of what's genuinely missing, not a reassuring one, since the entire point of running this before the formal audit is to find the bad news while it's still cheap to fix.
For the full certification process this step feeds into, and how 42001 compares to the NIST AI RMF, see our ISO/IEC 42001 overview.
Frequently asked questions
- Is a gap assessment the same thing as the certification audit?
- No. A gap assessment is an internal or advisory diagnostic exercise with no formal outcome recognized by any certification body — its only purpose is to tell you, honestly, where you stand before you commit budget. The certification audit is the actual accredited, external process that results in a certificate. Running a gap assessment first exists specifically to make that later audit far less risky and expensive, by catching problems while they're still cheap to fix.
- Can an organization skip the gap assessment and go straight to a certification audit?
- Technically, yes — nothing requires it. In practice it's a bad idea: a failed or significantly delayed formal audit costs more in certification-body fees, consultant time, and credibility with the auditor than a gap assessment would have cost, and Stage 1 of the actual certification audit effectively re-does a version of this diagnostic work anyway, just with the clock and the invoice already running.
- Do you need an external consultant to run a gap assessment?
- Not necessarily. An internal team with real familiarity with the standard's clause structure and Annex A controls can run a credible one. An external reviewer adds independence and the pattern-recognition that comes from having assessed many organizations against the same standard — which matters more for a team without prior ISO management-system experience than for one that's already run a 27001 or 9001 program.
- If we're already ISO 27001 certified, how much of 42001 do we already have?
- A substantial amount of the management-system scaffolding transfers directly — document control, the internal audit process, management review cadence, competence and training records, corrective action procedures — because 42001 follows the same Annex SL high-level structure ISO 27001 does. The real remaining gap work concentrates almost entirely in the AI-specific Annex A controls that 27001 never covered: AI risk assessment methodology, system impact assessment, and training-data governance.
Sources & references
Suggested next reading
frameworks
ISO/IEC 42001
regulations eu