Last updated
What's in the gap checklist?
The full structure of ISO/IEC 42001. The management-system clauses and every Annex A control. Translated from standards language into questions a normal person can answer, each with a status column (in place / partial / missing) and a notes field for evidence.
- Context and scope (clause 4). Which AI systems the management system covers, and the interested parties that shape it.
- Leadership and policy (clause 5). The AI policy, roles and accountabilities the auditor will ask to see first.
- Planning and risk (clause 6). AI risk assessment, AI system impact assessment and objectives.
- Support and operation (clauses 7–8). Resources, competence, awareness and the operational lifecycle controls.
- Evaluation and improvement (clauses 9–10). Internal audit, management review and corrective action.
- Annex A controls. All of them. From data governance and third-party AI to transparency, human oversight and incident handling. As check-able items rather than headings.
- A scoring summary that turns the answers into a one-page readiness picture for your executive team.
Who is this for?
Teams deciding whether ISO/IEC 42001 certification is worth pursuing, teams that have decided and want to know the size of the job, and anyone whose enterprise customers have started sending AI governance questions. If the gaps turn out to be substantial, that's exactly what our ISO 42001 readiness engagements close. And if you're weighing this standard against alternatives, read ISO 42001 vs NIST AI RMF.
About Ironbark Cyber
Ironbark Cyber is an Australian AI security and penetration testing consultancy, founded in 2025 by Luke Stephens (hakluke) and part of the Haksec group. We ground governance work in adversarial testing, which keeps the paperwork honest. The companion AI Security Assessment Checklist covers the technical side.
Download
Get the gap checklist
Tell us who you are and we'll send it over.