# ISO 42001 Gap Analysis Template

**Organisation:** [ORGANISATION NAME]
**Assessment owner:** [NAME / ROLE]
**Date:** [DATE]
**Version:** 1.0

---

## Purpose

ISO 42001 is the world's first international standard for AI Management Systems. Whether you are pursuing certification or simply want to assess your AI governance maturity, this template walks you through every clause, helping you identify gaps, prioritise remediation, and build an audit-ready evidence base.

---

## How to Use This Template

1. Work through each clause with your AI governance team.
2. Assign a maturity rating to every requirement: Not Started / Partially Met / Largely Met / Fully Met.
3. Document the supporting evidence and identify gaps with their root cause.
4. Build a remediation roadmap with owners and dates (see the roadmap table at the end).

**Rating scale:** Not Started · Partially Met · Largely Met · Fully Met

---

## Clause 4 — Context of the Organisation

Understanding your AI context, stakeholders, and the scope of your AI Management System.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 4.1 Understanding the organisation and its context — document internal and external factors affecting AI use: business objectives, regulatory environment, competitive landscape, and AI risk appetite. | | | |
| 4.2 Understanding stakeholder needs — identify all parties with an interest in your AI systems (customers, regulators, employees, suppliers, society) and document their requirements. | | | |
| 4.3 Determining the scope of the AI MS — define the boundaries of your AI Management System. Which systems, processes, and units are in scope? Document exclusions with justification. | | | |
| 4.4 AI Management System — establish, implement, maintain, and continually improve an AI MS in accordance with ISO 42001. Assign ownership and integrate with existing management systems. | | | |

---

## Clause 5 — Leadership

Top management commitment, AI policy, and organisational roles and responsibilities.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 5.1 Leadership and commitment — evidence that top management actively supports the AI MS: assigns resources, integrates AI risk into enterprise risk management, and champions responsible AI. | | | |
| 5.2 AI Policy — a documented AI policy signed by top management stating AI objectives, commitment to compliance, and continual improvement. Published internally. | | | |
| 5.3 Roles, responsibilities, and authorities — defined roles for AI governance (AI owner, risk officer, DPO where applicable, operational AI teams), communicated and understood. | | | |

---

## Clause 6 — Planning

Risk and opportunity assessment, AI objectives, and planning for change.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 6.1 Actions to address risks and opportunities — systematic process for identifying AI-specific risks (bias, safety, security, privacy) and opportunities. Risks assessed, treated, and monitored. | | | |
| 6.1.2 AI risk assessment — documented AI risk assessment methodology. Risks scored by likelihood and impact. Repeated when AI systems change materially. | | | |
| 6.1.3 AI risk treatment — risk treatment plan with selected controls, treatment options (avoid, reduce, transfer, accept), and residual risk sign-off by accountable executives. | | | |
| 6.2 AI objectives and planning — measurable AI objectives aligned to the AI policy, with owners, timelines, success measures, reviewed at management reviews. | | | |

---

## Clause 7 — Support

Resources, competence, awareness, communication, and documented information.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 7.1 Resources — adequate human, technical, and financial resources allocated to the AI MS. Resource needs reviewed annually and escalated when insufficient. | | | |
| 7.2 Competence — competency requirements defined for all AI-related roles. Training records maintained. Gaps identified and addressed through development plans. | | | |
| 7.3 Awareness — all staff with AI responsibilities are aware of the AI policy, their contribution to AI MS effectiveness, and the consequences of non-conformance. | | | |
| 7.4 Communication — internal and external communication plan for AI governance matters. Stakeholders know how to report AI concerns and how updates will be shared. | | | |
| 7.5 Documented information — AI MS documentation is controlled: created, updated, and retained with appropriate access controls, version management, and retention schedules. | | | |

---

## Clause 8 — Operation

Operational planning, AI system lifecycle management, and supply chain controls.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 8.1 Operational planning and control — AI systems developed, deployed, and operated according to documented processes. Changes assessed for AI risk before implementation. | | | |
| 8.2 AI risk assessment (operational) — risk assessments conducted for each AI system in scope, updated when systems change, and reviewed annually at minimum. | | | |
| 8.3 AI risk treatment (operational) — risk treatment plans implemented and effectiveness monitored. Residual risks formally accepted by the accountable owner. | | | |
| 8.4 AI system impact assessment — impact assessments conducted for high-risk AI systems, assessing effects on individuals, groups, and society. Results documented and reviewed before deployment. | | | |
| 8.5 AI system lifecycle — documented lifecycle processes covering design, development, testing, deployment, monitoring, and decommissioning. Each phase has defined gates and sign-offs. | | | |
| 8.6 Related organisational controls — controls addressing data governance, third-party AI use, responsible AI practices, and human oversight are documented and operationalised. | | | |

---

## Clause 9 — Performance Evaluation

Monitoring, measurement, internal audit, and management review.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 9.1 Monitoring, measurement, analysis, and evaluation — KPIs for AI system performance, fairness, reliability, and security defined, measured regularly, and reported to management. | | | |
| 9.2 Internal audit — annual internal audit programme covering all in-scope clauses. Auditors are competent and independent. Non-conformities tracked to closure. | | | |
| 9.3 Management review — annual management review of the AI MS covering audit results, risks, objectives, resource needs, and stakeholder feedback. Minutes and action items documented. | | | |

---

## Clause 10 — Improvement

Non-conformity management, corrective action, and continual improvement.

| Requirement | Maturity rating | Evidence | Gap / action |
|-------------|-----------------|----------|--------------|
| 10.1 Non-conformity and corrective action — process for identifying, documenting, and closing AI MS non-conformities. Root cause analysis performed. Corrective actions tracked and verified. | | | |
| 10.2 Continual improvement — systematic approach to continually improving the suitability, adequacy, and effectiveness of the AI MS. Improvement initiatives tracked and measured. | | | |

---

## Remediation Roadmap

| Gap | Clause | Priority | Owner | Target date | Status |
|-----|--------|----------|-------|-------------|--------|
| [Gap description] | [e.g. 6.1.2] | High / Med / Low | [Owner] | [Date] | Open |
| | | | | | |
| | | | | | |

---

*This template is provided free by Aona AI and is general guidance, not a substitute for the ISO/IEC 42001 standard or accredited certification advice. See `/resources/templates` for related governance and risk templates.*
