/

  / The ISO 42001 Gap Analysis Checklist Consultants Actually Use

The ISO 42001 Gap Analysis Checklist Consultants Actually Use

A consultant-grade ISO 42001 gap analysis checklist has 38 Annex A controls, roughly 80 clause-level “shall” statements, and one question attached to every line: where is the evidence, and would a certification body accept it? That last question is what separates the checklists consultants use from the free self-assessment spreadsheets that rank for the same search.

This article lays out the checklist itself: what a consultant checks before the engagement starts, the clause-by-clause and control-by-control checkpoints, how evidence gets sampled, how gaps get scored, what the deliverables look like, and what fails most often. Use it to run your own assessment, or to check whether the consultant you’re about to hire is doing the job properly.

What Makes a Consultant-Grade ISO 42001 Gap Analysis Checklist Different​

Depth of Evidence Review vs. Self-Assessment Tools

A self-assessment tool asks whether you have an AI policy. A consultant asks to see it, checks the approval date and version, reads clause 5.2 against it, and then asks three people in engineering whether they’ve read it. The checklist item is the same. The evidence standard is not.

Consultants score every item on three levels: documented, implemented, and effective. A policy that exists but nobody follows scores as “ad hoc,” not “defined.” A control that runs but produces no record scores as unverifiable, which for audit purposes is the same as absent. Self-assessment tools collapse those three levels into a single yes/no, which is why companies that score 85% on a free tool routinely receive major nonconformities at Stage 2.

Alignment with Certification Body Expectations

Certification bodies auditing against ISO/IEC 42001:2023 now work under ISO/IEC 42006:2025, which sets competence, audit-time, and impartiality requirements for AIMS auditors and builds on ISO/IEC 17021-1. A consultant-grade checklist is written with 42006 in mind: it organizes findings by clause and control identifier, because that’s how the auditor works, and it records evidence locations, because that’s what the auditor will sample.

The practical difference shows up in the report. A gap register that says “AI governance needs improvement” is useless in front of an auditor. One that says “A.5.2 not conformant: no documented impact assessment process; two of four in-scope systems have no assessment on file” maps directly to the audit plan.

Risk-Weighted Scoring Methodology

Self-assessments count gaps. Consultants weight them. A missing AI policy under clause 5.2 and an incomplete competence matrix under 7.2 are both gaps, but the first will block certification and the second will earn you a minor finding. A consultant-grade checklist carries two scores per line: a maturity rating (how far the control is from working) and a certification criticality (what happens at audit if it stays this way). Effort estimates live in the remediation plan, never in the gap score, because mixing them produces a roadmap that fixes easy things first rather than important ones.

Insider Note: The fastest tell that a checklist is consultant-grade rather than a marketing download is whether it has a column for evidence location. Auditors don’t accept “yes” as evidence. If the checklist has nowhere to record where the proof lives, it wasn’t built by someone who has sat through a Stage 2.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Pre-Engagement Preparation Consultants Complete Before the Gap Analysis

Client AI Inventory and Use Case Cataloging

Nothing in the checklist works without a complete AI inventory, and it’s the input clients get wrong most often. The inventory records every AI system in use: purpose, the role you play (developer, provider, deployer, or user), data consumed, outputs produced, whether a human sits between the output and the decision, and which third-party model or API it depends on. Consultants push hard on shadow AI here: SaaS tools that added AI features, agents running under employee credentials, and internal scripts calling model APIs. Every one of those is in scope until you document why it isn’t.

Defining AIMS Scope Boundaries

Clause 4.3 requires a scope statement naming which AI systems, business units, locations, and lifecycle stages the AIMS covers. Consultants draft this from the inventory, not before it. Scope discipline matters commercially too: certification bodies price audits by audit days, and audit days scale with scope. A narrow, well-justified first scope (the customer-facing AI product, say, rather than every internal tool) is usually the right call for a first certification.

Stakeholder Interview Planning

The checklist needs answers from people who don’t write policies. A typical interview plan covers the executive sponsor (clause 5), the AI or product lead (clauses 6 and 8), data engineering (A.7), procurement or vendor management (A.10), legal or privacy (A.5, A.8), and at least one front-line user of the AI system (A.9). Consultants interview the doers separately from the document owners, because the distance from what the procedure says to what actually happens is the finding.

Document Request List (DRL) Consultants Send Clients

The DRL goes out one to two weeks before fieldwork. A standard ISO 42001 DRL asks for the AI inventory; existing AI, security, and data policies; org chart with AI governance roles; any AI risk assessments or impact assessments; model documentation (model cards, system cards, or whatever exists); training-data provenance and data quality records; supplier contracts for third-party models; incident and change logs; training records; any ISO 27001 ISMS documentation; and the last internal audit and management review minutes if they exist. Missing items become findings rather than delays.

Pro Tip: Return an Honest DRL

Return the DRL with a column that says "does not exist" wherever that's true. Consultants would rather know on day one than discover it in a workshop. An honest DRL shortens fieldwork by days and makes the maturity scores more accurate, which makes the remediation plan cheaper.

Clause-by-Clause Checklist Consultants Use (ISO 42001 Clauses 4 to 10)

ISO 42001 follows the Harmonized Structure shared with ISO 27001 and ISO 9001, so clauses 4 to 10 will look familiar to anyone who has run an ISMS. What’s different is the content each clause demands.

Clause 4 – Context of the Organization Checkpoints

Consultants check for a documented analysis of internal and external issues relevant to AI (4.1), including the organization’s role in the AI value chain and its climate-related considerations; a register of interested parties and their AI-related requirements, covering regulators, customers, affected individuals, and the public (4.2); a scope statement that names AI systems and boundaries (4.3); and evidence that the AIMS is established as a system of interacting processes, not a policy binder (4.4).

Clause 5 – Leadership and AI Policy Evidence

Evidence of top-management commitment (5.1) means budget, named sponsorship, and management review attendance, not a signed statement. The AI policy (5.2) must be approved, communicated, available to interested parties, and aligned with the organization’s AI objectives and principles. Roles and responsibilities (5.3) must be assigned and communicated, with a named accountable owner for the AIMS. Consultants specifically check whether that owner has authority over AI development decisions or is a compliance manager with no say in the roadmap.

Clause 6 – Planning and AI Risk Assessment

This is where first-time assessments break. The checklist looks for AI risk criteria approved by management before assessment started (6.1.2); a risk assessment run per AI system, not per organization; a risk treatment plan with selected controls compared against Annex A and a Statement of Applicability justifying any exclusions (6.1.3); and a separate AI system impact assessment process that considers consequences for individuals, groups, and society (6.1.4). Measurable AI objectives with owners and timelines (6.2) and a controlled change process for the AIMS itself (6.3) complete the clause.

Clause 7 – Support, Resources, and AI Literacy

Consultants verify resources are allocated (7.1), competence is defined and evidenced for AI governance roles (7.2), awareness of the AI policy reaches everyone whose work touches AI systems (7.3), internal and external communication about the AIMS is planned (7.4), and documented information is controlled with versioning and approval (7.5). AI literacy is now a regulatory expectation as well as a standards one: Article 4 of the EU AI Act requires providers and deployers to ensure sufficient AI literacy among staff, and consultants check whether training records would satisfy both.

Clause 8 – Operational Controls and AI Impact Assessments

Clause 8 asks whether the plans in clause 6 actually operate. The checklist tests documented operational processes for AI systems across the lifecycle (8.1); risk assessments repeated on defined triggers such as retraining, new data sources, or vendor model updates, not just annually (8.2); risk treatment plan implementation with evidence each control is running (8.3); and impact assessments completed for every in-scope system, dated, and reviewed (8.4). Consultants sample here rather than review everything, and the sampling approach is covered below.

Clause 9 – Performance Evaluation and Internal Audit

Monitoring and measurement (9.1) needs defined metrics for AI performance and AIMS effectiveness, with records showing they’re tracked. The internal audit program (9.2) must cover the whole AIMS over a cycle, use auditors independent of the areas audited, and produce findings with follow-up. Management review (9.3) must have happened at least once with the inputs the standard names, including risk assessment results and nonconformities, and minutes showing decisions. A management review that has never occurred is the most common reason a Stage 1 audit gets rescheduled. 

Clause 10 – Improvement and Nonconformity Handling

Consultants look for a working corrective action process (10.2): nonconformities logged, root cause recorded, action taken, effectiveness checked. If the client has an ISO 27001 CAPA process, it can be reused with an AI category added. Continual improvement (10.1) is evidenced through a log of changes to the AIMS itself, which is the Plan-Do-Check-Act loop the standard is built on.

Annex A Control Checklist: Consultants Apply (All 38 Controls)

Annex A lists 38 controls across nine objective groups, A.2 through A.10. Unlike ISO 27001, where most organizations apply nearly all 93 controls, ISO 42001 applicability depends heavily on your role in the AI value chain. A deployer of third-party models will exclude several A.6 lifecycle controls with a justification; a model developer will apply almost all of them. Consultants record the current state for all 38 first, then decide applicability after the risk assessment.

A.2 – Policies Related to AI

Three controls: an AI policy (A.2.2), alignment with other organizational policies (A.2.3), and periodic review (A.2.4). Consultants check the policy addresses the topics Annex B recommends, covers the whole lifecycle, and doesn’t conflict with security, privacy, or acceptable-use policies already in force.

A.3 – Internal Organization and Roles

A.3.2 requires defined roles and responsibilities for AI; A.3.3 requires a process for reporting concerns about AI systems. The second one is checked by asking a front-line employee how they’d raise a concern about a model output. If the answer is “I’d message my manager,” there’s no process.

A.4 – Resources for AI Systems

Five controls covering resource documentation (A.4.2), data resources (A.4.3), tooling (A.4.4), system and computing resources (A.4.5), and human resources (A.4.6). Consultants confirm each in-scope AI system has a resource record naming its data sources, models, infrastructure, and the people responsible for it.

A.5 – AI System Impact Assessment

Four controls: a documented process (A.5.2), documented results (A.5.3), and assessments considering impact on individuals and groups (A.5.4) and on society (A.5.5). This is the group auditors probe hardest because it doesn’t exist in any other management system standard. ISO/IEC 42005:2025 provides the method and harm taxonomy, and consultants check whether the client’s template follows it.

A.6 – AI System Lifecycle

Nine controls in two sub-groups: management guidance for development (objectives for responsible development, A.6.1.2, and lifecycle processes, A.6.1.3) and the lifecycle itself (requirements and specification, design and development, verification and validation, deployment, operation and monitoring, technical documentation, and event logging, A.6.2.2 through A.6.2.8). Consultants request the artifact for each stage of one real system and check that the chain is unbroken.

A.7 – Data for AI Systems

Five controls: data management process (A.7.2), acquisition (A.7.3), quality (A.7.4), provenance (A.7.5), and preparation (A.7.6). Provenance is the usual failure: consultants ask for the origin, license, and consent basis of training or fine-tuning datasets, and a surprising number of companies cannot answer for data they’ve been using for years.

A.8 – Information for Interested Parties

Four controls covering system documentation for users (A.8.2), external reporting of AI-related concerns (A.8.3), incident communication (A.8.4), and information for interested parties on the AI system (A.8.5). With the EU AI Act’s Article 50 transparency obligations in force since August 2, 2026, consultants map A.8 evidence to those obligations at the same time.

A.9 – Use of AI Systems

Three controls: a responsible-use process (A.9.2), objectives for responsible use (A.9.3), and documented intended use (A.9.4). For organizations that mostly use rather than build AI, this group and A.10 carry most of the weight.

A.10 – Third-Party and Customer Relationships

Three controls: allocating responsibilities across the value chain (A.10.2), a supplier process for AI (A.10.3), and understanding customer requirements (A.10.4). Consultants sample supplier contracts for foundation-model providers and check whether they address model updates, data use, and incident notification. Standard SaaS terms almost never do.

Evidence Sampling Techniques Consultants Rely On

A gap analysis is a diagnostic, not an audit, so consultants sample rather than review everything. The sampling must be defensible, though, because the auditor will do the same.

Reviewing AI Model Cards and System Documentation

For each in-scope system, consultants ask for whatever documentation exists and score it against A.6.2.7 and A.8.2. A model card that lists intended use, training data summary, evaluation results, known limitations, and version history satisfies most of what the standard wants. A README does not. Where the model is third-party, the consultant checks whether the vendor’s documentation has been reviewed and filed, since that becomes the client’s evidence.

Verifying Data Provenance Records

Consultants pick one dataset, usually the one used for the highest-risk system, and trace it backward: where it came from, under what license or consent, what transformations were applied, and who approved its use. If the trail breaks at any step, A.7.5 is nonconformant, and the finding usually extends to A.7.3 and A.7.4.

Testing Human Oversight and Escalation Logs

Where the AI inventory records a human-in-the-loop, consultants test it. They pull the escalation log for a recent period and check that overrides actually occurred, that reviewers had time and authority to override, and that thresholds for escalation are written down somewhere. An oversight mechanism with zero overrides in six months is either unnecessary or not functioning, and the auditor will ask which.

Sampling Supplier and Vendor Contracts

Consultants sample two or three AI supplier contracts, prioritizing foundation-model providers and any vendor processing customer data through AI. They check for AI-specific clauses: notification of model changes, restrictions on using customer data for training, incident notification timelines, and the right to audit or obtain documentation. Where those clauses are missing, the finding sits under A.10.3 and the remediation is usually a supplier addendum rather than a new contract.

Important: Sampling one system and finding it clean does not clear the control. Consultants pick the highest-risk system deliberately, because if that one fails, the control fails, and if it passes, they still note that lower-risk systems were not tested. Certification auditors sample the same way and will extend the sample if the first item shows a problem.

Gap Scoring and Maturity Rating Framework

Consultant Maturity Levels (Nonexistent to Optimized)

Most consultants use a five-level scale, with each level anchored to something observable so two assessors land within one level of each other. Certification generally requires level 3 on every applicable control and clause requirement. Level 4 is a target for the second surveillance year, not the first audit.

Prioritization Matrix (Impact vs. Remediation Effort)

Consultants plot each gap on two axes: certification impact (would this produce a major, a minor, or an observation) and remediation effort (days of work, dependencies, decisions needed). High impact and low effort gets scheduled first for momentum. High impact and high effort, which is where impact assessment processes and data provenance usually sit, gets scheduled next and drives the critical path. Low impact items are batched, and if the calendar is tight, some are candidates for scope reduction.

Mapping Gaps to Certification Blockers vs. Observations

Every gap gets a classification that predicts what the auditor would do with it. A blocker is a missing mandatory element: no scope, no AI policy, no risk assessment, no impact assessment for an in-scope system, no internal audit, no management review. These become major nonconformities and stop certification. A weakness is a partial or ineffective implementation and becomes a minor. An observation is an improvement opportunity with no audit consequence. Consultants report the counts of each up front, because a client with two blockers and forty observations is in far better shape than one with zero observations and eight blockers.

Deliverables Consultants Produce from the Gap Analysis

Executive Gap Analysis Report

A short document, usually under ten pages, written for the sponsor. It states overall readiness, counts blockers, weaknesses, and observations, summarizes the three or four root causes behind most gaps, and gives a realistic estimate of time and effort to certification readiness. The detailed gap register sits in an appendix or a separate spreadsheet.

Remediation Roadmap with Owner and Timeline

Every gap becomes an action with a named owner (an individual, never a team), a target date, and a dependency note. The roadmap is sequenced so the AIMS can operate for two to three months before Stage 2, because the auditor wants proof controls ran, not just that they were designed. Consultants group actions into sprints, which the transition section below covers.

Statement of Applicability (SoA) Draft

The gap analysis produces a first draft of the SoA: all 38 Annex A controls, with a provisional applicable/not-applicable decision, the justification for each exclusion, and current implementation status. It’s provisional because applicability is finalized only after the risk treatment plan is complete, but a draft at this stage saves weeks later.

Risk Register Populated with AI-Specific Risks

Consultants seed the AI risk register with risks identified during fieldwork: bias in training data, model drift, unexplainable outputs, automation bias in reviewers, dependence on third-party models whose behavior changes without notice, and data provenance gaps. Each entry references the AI system, the affected objective, and the Annex A controls that would treat it. The NIST AI Risk Management Framework and its Generative AI Profile are common sources for the risk taxonomy.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Cross-Standard Mapping Consultants Include in the Checklist

ISO 42001 to ISO 27001 Control Overlap

Because both standards use the Harmonized Structure, clauses 4 to 10 map almost one-to-one. Document control, competence records, internal audit, management review, and corrective action carry over directly, and a company with a working ISMS typically starts an ISO 42001 gap analysis at level 2 or 3 on most clause requirements. Annex A overlap is thinner: A.10 supplier controls map to ISO 27001’s supplier relationship controls, A.7 data controls partially map to information classification and handling, and A.3 roles map to organizational controls. The impact assessment group (A.5) and most of the lifecycle group (A.6) have no ISO 27001 equivalent.

ISO 42001 to NIST AI RMF Mapping

The NIST AI RMF’s four functions align cleanly: Govern maps to clauses 4, 5, and 7 plus A.2 and A.3; Map maps to the inventory, scope, and impact assessment (A.4, A.5); Measure maps to clause 9 and the verification controls in A.6; Manage maps to clause 6 risk treatment, clause 8 operations, and clause 10. Companies that built a NIST-aligned program can present it as ISO 42001 evidence with a mapping table and little rewriting.

ISO 42001 to EU AI Act Obligations

ISO 42001 certification is not EU AI Act compliance, and consultants say so in the report. What it provides is the management system the Act’s risk management (Article 9), documentation (Article 11), record-keeping (Article 12), transparency (Articles 13 and 50), and human oversight (Article 14) obligations assume you have. The Digital Omnibus on AI, in force since July 27, 2026, moved the high-risk obligations for standalone Annex III systems to December 2, 2027, so consultants now build the mapping into the remediation roadmap rather than treating it as urgent. Axipro’s EU AI Act compliance services run this mapping as part of the same engagement for clients with EU exposure.

Worth Knowing: A certification body auditing under ISO/IEC 42006

A certification body auditing under ISO/IEC 42006 will not assess your EU AI Act compliance, and an ISO 42001 certificate is not a conformity assessment. What the certificate does is answer most of the AI questions in enterprise security questionnaires, which is why AI-native SaaS companies are pursuing it before any regulator asks.

Common Findings Consultants Report Across Client Engagements

Across ISO 42001 gap analyses, the same four findings appear in most first-time reports.

Missing AI Impact Assessment Procedures

The most common blocker. Companies with a mature ISO 27001 risk process assume the security risk register covers it and paste “AI” into a few risk titles. It doesn’t. Clause 6.1.4 and A.5 want a separate, outward-facing assessment of consequences for individuals and society, and auditors pull the two apart at Stage 2.

Weak Data Governance for Training Datasets

Companies fine-tuning models on customer data, scraped data, or datasets inherited from a previous team rarely have provenance records. The finding lands under A.7.5 and usually cascades into A.7.3 and A.7.4. Remediation means reconstructing provenance for datasets in use and establishing a process for new ones, which is slow, decision-heavy work.

Undefined Human-in-the-Loop Thresholds

The inventory says a human reviews outputs. Nobody can say which outputs, at what confidence threshold, with what authority to override, or where the record goes. The control exists in name only, and the finding sits across A.6.2.6 operation and monitoring and A.9 responsible use.

Inadequate Supplier AI Due Diligence

Almost every client uses at least one foundation-model API under standard commercial terms that say nothing about model changes, training on customer data, or AI incident notification. A.10.3 is nonconformant, and the remediation is a supplier AI addendum plus a review record.

How Consultants Transition Clients from Gap Analysis to Implementation

Building the Remediation Sprint Plan

Consultants convert the roadmap into two- to three-week sprints ordered by dependency. Sprint one is always foundations: scope, AI policy, roles, risk criteria, and the inventory finalized. Sprint two runs the risk and impact assessments and finalizes the SoA. Sprint three builds the operational controls the SoA calls for. Sprint four runs the internal audit and management review. The AIMS then operates for at least two to three months before Stage 2, and that operating window, not the document writing, is usually the longest item on the calendar. Axipro’s breakdown of how long ISO 42001 certification takes covers the full calendar.

Preparing for Stage 1 and Stage 2 Certification Audits​

Stage 1 is a documentation review: the auditor checks scope, policy, risk methodology, SoA, and whether the internal audit and management review have run. Stage 2 tests operation: interviews, record sampling, evidence that controls produced the intended result. Consultants book the certification body during the gap analysis, not after remediation, because accredited bodies for ISO 42001 are still few and lead times run to a quarter. The body must be independent of the consultant; anyone offering to both implement and certify your AIMS is offering something accreditation rules don’t permit.

The consultant-grade ISO 42001 gap analysis checklist is one document with three questions on every line: does the requirement have evidence, would an auditor accept it, and what happens at certification if it doesn’t. Run against clauses 4 to 10 and all 38 Annex A controls, with evidence sampled from the highest-risk system and gaps scored by certification impact rather than effort, it produces a report, a roadmap, an SoA draft, and a risk register that carry straight into implementation. Axipro’s ISO 42001 gap analysis engagement delivers exactly those four artifacts in one to three weeks, and the full ISO 42001 certification program carries them through to guaranteed certification on the Achievement Plan.

Frequently Asked Questions

How long does a consultant-led ISO 42001 gap analysis take?

One to three weeks from DRL return to report delivery for most organizations, with two to five consultant days of fieldwork. The variables are the number of in-scope AI systems, how complete the AI inventory is when the engagement starts, and whether an ISO 27001 ISMS already exists to reuse. Organizations with no inventory should add a two-week discovery sprint before the gap analysis proper.

Standalone ISO 42001 gap analyses on the wider market run in the low four figures for a fixed-fee engagement, rising to $15,000 to $25,000 at large consulting firms billing day rates. Axipro’s fixed-fee ISO 42001 readiness assessment is priced at $4,500 and is also bundled into the free 30-day Compliance Accelerator Plan. The detailed breakdown of ISO 42001 consulting costs compares both delivery models phase by phase.

Both. The clause and control structure is fixed by the standard, so every credible checklist covers the same requirements. What’s proprietary is the evidence criteria per maturity level, the certification-criticality weighting, the interview scripts, and the sampling approach. Ask to see a redacted sample gap register before hiring; if it lacks evidence locations and criticality ratings, keep looking.

No. Certification bodies working under ISO/IEC 42006 and ISO/IEC 17021-1 must be impartial, and a body that provided consultancy on your AIMS cannot audit it. Consultants perform the gap analysis, implementation support, and internal audit; an accredited certification body performs Stage 1 and Stage 2. A certificate from an unaccredited body carries little weight in enterprise procurement.

A gap analysis is diagnostic and happens before the AIMS is built: it measures distance from the standard and produces a roadmap. An internal audit is a clause 9.2 requirement that happens after the AIMS operates: it tests conformity and effectiveness and produces findings for corrective action. You need the gap analysis to know what to build and the internal audit to prove it works before the certification body checks. The same consultant can do both, provided the internal auditor is independent of the areas they implemented.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Compliance software collects the evidence. A consultant builds the system that evidence is meant to prove. That’s the real difference in the ISO 27001 consultant vs software decision, and most teams only figure it out after they’ve bought one and realized they still need the other. Below, we compare what each route covers, where it breaks down, and what it costs you in time, money, and your team’s hours. Short version: software on its own works for a small group of companies. For most SaaS and tech scale-ups trying to get an enterprise deal over the line, consultant-led implementation on a compliance platform is the faster and safer path to a certificate. Quick Answer: Consultant, Software, or Both? Software-only works if you already have an in-house security lead who’s taken a company through ISO/IEC 27001 before and has the time to own the project. Consultant-only still makes sense if you run mostly on-premise or legacy systems that platforms barely integrate with. For everyone else, which means most cloud-native companies under a few hundred people, a hybrid works best: a platform to handle evidence and monitoring, and a consultant to build the management system and stand behind it in front of an auditor. Here’s why. What an ISO 27001 Consultant Handles ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 cover how you run information security, and Annex A lists 93 controls you pick from based on risk. Almost none of it is box-ticking. Most of it comes down to judgment calls about your business, and that’s what you’re paying a consultant for. Scoping, Gap Analysis and Risk Assessment Scope is the first decision you make, and the most expensive one to get wrong. Go too wide and you’ll spend months on controls for systems no customer asks about. Go too narrow and the certificate won’t get through the procurement review it was supposed to pass. A consultant scopes around the deals you’re trying to close, runs a gap analysis, and builds a risk assessment based on your real assets and threats. That’s the document auditors dig into hardest. ISMS Documentation and Policy Writing The standard asks for a specific set of documents: the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan, and evidence of competence, monitoring, internal audit, and management review. A consultant writes these around how your company works day to day, instead of how a template imagines it works. Auditors check whether you follow your own procedures, so a mismatch shows up fast. Internal Audit and Certification Audit Support You need an internal audit before certification, and Clause 9.2 says the auditor has to be objective and impartial. In a small company, the people who built the ISMS can’t credibly audit it, so most teams outsource it through ISO 27001 internal audit services. A good consultant also gets your team ready for the Stage 1 and Stage 2 audits, joins the conversations that matter, and handles corrective actions if the auditor raises nonconformities.  What ISO 27001 Compliance Software Handles Compliance automation platforms, often called GRC platforms, have changed how cloud-native companies get certified. They’re very good at the repetitive, evidence-heavy side of the work. Automated Evidence Collection and Continuous Control Monitoring The platform plugs into your cloud provider, identity provider, code repos, HR system, and device management tools, then pulls evidence on its own. It’ll flag an unencrypted storage bucket, an ex-employee who still has access, or a laptop without disk encryption. For technical controls, that saves weeks of screenshots and spreadsheet tracking. Policy Templates and Annex A Control Mapping Most platforms come with a policy library and map each control to the ISO 27001 clauses and Annex A. You get a starting point and a clear view of which controls have evidence and which don’t. Auditor Access and Ongoing Compliance Tracking Auditors can log in and review evidence themselves, which cuts down fieldwork. After you’re certified, dashboards show when controls slip between surveillance audits, so you aren’t rebuilding evidence from scratch every year. Where Each Approach Falls Short Neither route covers everything by itself. The good news is that the ways each one fails are predictable, so you can plan around them. Limits of Compliance Automation Platforms A platform can tell you a control is failing. It can’t decide your scope, run your risk assessment, write a policy that matches your operations, convince your CTO to change the offboarding process, or explain to an auditor why you excluded a control from your Statement of Applicability. Templates can also make you feel further along than you are. A dashboard at 90% can hide an ISMS that won’t survive Stage 1, because the missing 10% is the management system itself. Insider Note: The Stage 1 problem we see most on software-only projects is a risk assessment copied straight from the platform’s default risk library. The risks are generic, the scores are almost identical, and nothing ties back to the company’s own assets. Auditors notice within minutes, and it weakens the Statement of Applicability that’s built on it. The other problem is ownership. Software assumes someone inside the company will drive the project. At most startups that’s a CTO or ops lead who already has a full-time job, and the subscription renews whether the work gets done or not. Limits of a Consultant-Only Approach A consultant working without automation spends billable days on things a platform does for free, like chasing screenshots, updating evidence trackers, and collecting the same proof again before every surveillance audit. You pay more and wait longer. You also end up with a program that’s only accurate on the day it’s handed over. Once the engagement ends, the evidence goes stale and year-two surveillance turns into a scramble. ISO 27001 Consultant vs Software: Side-by-Side Comparison Factor Consultant only Software only Hybrid (consultant + platform) Time to audit readiness 3 to 6+ months Highly variable; depends on internal expertise As little as 6 weeks for well-scoped

Uzbekistan regulates artificial intelligence through two documents. The first is Law ZRU-1115, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of Ethical Rules approved by Order No. 3787, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do. Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next. Uzbekistan AI Regulation at a Glance (TL;DR) Instrument Date What it does Who it binds Law ZRU-1115 Signed 21 January 2026 Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data State bodies, organizations, website owners, anyone processing personal data with AI Order No. 3787 (Ethical Rules) Registered 14 March 2026, in force 17 June 2026 Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users Individuals and companies developing, implementing, or using AI in Uzbekistan Law No. 1125 (Personal Data amendments) Adopted 26 March 2026 Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions Personal data operators, including AI providers AI Strategy until 2030 (RP-358) 14 October 2024 Sets national targets for AI adoption, infrastructure, and skills Government bodies What Is Law ZRU-1115? The law’s official title is a mouthful: “On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.” Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books. When It Was Signed and When It Took Effect The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in Lex.uz, Uzbekistan’s national legislation database. The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying. Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them. So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster. Which Laws ZRU-1115 Changes For businesses, two amendments matter most. The Law “On Informatization” (ZRU-560-II, 2003) now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge. The Code on Administrative Liability now includes an offense for processing and spreading personal data unlawfully using AI. The Legal Definition of Artificial Intelligence in Uzbekistan Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do. That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the AI system: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts. Key Rules Introduced by Law ZRU-1115 General Principles for Using AI in Information Systems and Resources The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights. The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined. Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, they can’t rely only on conclusions produced by AI systems or AI-built information resources. AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call. Insider Note: In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one. Powers of the Authorized State Body (Ministry of Digital Technologies) ZRU-1115 makes the Ministry of Digital Technologies the authorized state body for AI. Among its new jobs, it’s

You can get a SaaS company ready for a SOC 2 audit in six weeks, but you’ll feel every one of them. Most published timelines say three to six months. For a company with no project owner, no identity provider, and nothing written down, that’s about right. A cloud-native startup that already has the basics in place and can protect some time is a different story, and it can fit the work into six hard weeks. This plan walks through that route one week at a time. Each week has an owner, an hour estimate, and a clear test for when it’s finished. The free Google Sheet version turns the plan into a tracker you can hand out to owners and update in your weekly standup. Before you start, know what you’re signing up for. At the end of week 6 you’ll be audit-ready, which isn’t the same as holding a Type II report. Nobody can get you a Type II in six weeks. This is also the do-it-yourself route, and it takes a lot of hours. We’ll show you where those hours go and what the faster option looks like. Is Six Weeks Realistic for Your Company? Six weeks works when most of the plumbing already exists and your job is to formalize it, fill the gaps, and prove it all works. It falls apart when you’re building the foundations and documenting them at the same time. Go through this table honestly before you promise a customer a date. Six weeks is realistic if… Plan for 10 to 16 weeks if… Your product runs on a major cloud provider You host on-premise or across several data centers You already use an identity provider with SSO Every tool has its own login and password You have fewer than about 50 employees You have multiple offices, subsidiaries, or products in scope One named person owns the project with 10 to 15 hours a week Compliance is “everyone’s job,” so in practice nobody owns it An engineer can give you 15 to 20 hours in weeks 3 and 4 Engineering is fully committed to a launch You only need the Security criteria You need Availability, Confidentiality, or Privacy on day one Landing mostly in the right-hand column doesn’t mean you should throw the plan out. Give each week two weeks instead of one and follow the same order. What “SOC 2 Ready” Means at the End of Week 6 SOC 2 doesn’t give you a certificate. An independent CPA firm examines your controls against the AICPA Trust Services Criteria and writes a report, and which of the two report types you go for decides what you can show a buyer after week 6. A Type I report checks whether your controls are designed properly on a single date. Once you’re ready, a Type I audit can start almost right away. A Type II report checks whether those controls kept working over an observation period of at least three months, and usually six to twelve. Most enterprise procurement teams want Type II in the end. Being “ready” at the end of this plan means your in-scope controls are in place, you can pull evidence for any of them on request, and your auditor is booked. From there you either start a Type I audit or open your Type II observation window. Plenty of buyers will sign with a Type I report plus a letter from your auditor saying the Type II period is underway. Important: The Type II clock doesn’t start until your controls are running. If readiness slips by a week, your Type II report slips by a week too. Founders who tell a prospect “we’ll have SOC 2 in Q3” often forget this and end up renegotiating the deal. Before Week 1: Four Decisions to Make First Settle these before the clock starts. If you change any of them halfway through, you’ll redo work. Scope. Decide which systems, teams, and data the report covers. For most SaaS companies that’s the production environment, the code repository, the identity provider, customer data stores, and any support tools that touch customer data. Corporate systems that never see customer data can usually stay out. Trust Services Criteria. Security (also called the Common Criteria) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional. Report type. Pick Type I if a deal is blocked right now and the buyer will accept it. If there’s no deadline, go straight to Type II. You’ll need it eventually, and skipping Type I saves you an audit fee. Owner and tooling. Name one person who’s accountable for the plan, and decide where your controls and evidence will live. The tooling choice gets its own section below. Pro Tip: Adding Criteria Only add optional criteria when a customer contract or security questionnaire asks for them. Each one brings more controls to set up and more evidence to collect, and you can widen the scope in next year’s audit. Spreadsheet or Compliance Software: Choosing Your Tracking Tool Every SOC 2 program needs a system of record, meaning one place where each control, its owner, its status, and its evidence live. You can run it yourself in a spreadsheet or a GRC platform, or have a consultant implement it for you. The right choice depends mostly on which report you’re after and how much of your team’s time you can spare. A spreadsheet is free and familiar. It also makes you understand your own environment before you automate any of it. For a Type I, or for a small team with a tight scope, a well-built spreadsheet can take you all the way to the audit. Axipro’s free GRC workbook for SOC 2 and ISO 27001 covers all 33 SOC 2 Common Criteria plus the optional criteria, with evidence, risk, policy, and gap trackers built in. It has no macros and opens straight in Google Sheets or Excel. A GRC platform connects to your cloud, identity provider, code repository, and HR system.