/

  / The ISO 42001 Gap Analysis Checklist Consultants Actually Use

The ISO 42001 Gap Analysis Checklist Consultants Actually Use

A consultant-grade ISO 42001 gap analysis checklist has 38 Annex A controls, roughly 80 clause-level “shall” statements, and one question attached to every line: where is the evidence, and would a certification body accept it? That last question is what separates the checklists consultants use from the free self-assessment spreadsheets that rank for the same search.

This article lays out the checklist itself: what a consultant checks before the engagement starts, the clause-by-clause and control-by-control checkpoints, how evidence gets sampled, how gaps get scored, what the deliverables look like, and what fails most often. Use it to run your own assessment, or to check whether the consultant you’re about to hire is doing the job properly.

What Makes a Consultant-Grade ISO 42001 Gap Analysis Checklist Different​

Depth of Evidence Review vs. Self-Assessment Tools

A self-assessment tool asks whether you have an AI policy. A consultant asks to see it, checks the approval date and version, reads clause 5.2 against it, and then asks three people in engineering whether they’ve read it. The checklist item is the same. The evidence standard is not.

Consultants score every item on three levels: documented, implemented, and effective. A policy that exists but nobody follows scores as “ad hoc,” not “defined.” A control that runs but produces no record scores as unverifiable, which for audit purposes is the same as absent. Self-assessment tools collapse those three levels into a single yes/no, which is why companies that score 85% on a free tool routinely receive major nonconformities at Stage 2.

Alignment with Certification Body Expectations

Certification bodies auditing against ISO/IEC 42001:2023 now work under ISO/IEC 42006:2025, which sets competence, audit-time, and impartiality requirements for AIMS auditors and builds on ISO/IEC 17021-1. A consultant-grade checklist is written with 42006 in mind: it organizes findings by clause and control identifier, because that’s how the auditor works, and it records evidence locations, because that’s what the auditor will sample.

The practical difference shows up in the report. A gap register that says “AI governance needs improvement” is useless in front of an auditor. One that says “A.5.2 not conformant: no documented impact assessment process; two of four in-scope systems have no assessment on file” maps directly to the audit plan.

Risk-Weighted Scoring Methodology

Self-assessments count gaps. Consultants weight them. A missing AI policy under clause 5.2 and an incomplete competence matrix under 7.2 are both gaps, but the first will block certification and the second will earn you a minor finding. A consultant-grade checklist carries two scores per line: a maturity rating (how far the control is from working) and a certification criticality (what happens at audit if it stays this way). Effort estimates live in the remediation plan, never in the gap score, because mixing them produces a roadmap that fixes easy things first rather than important ones.

Insider Note: The fastest tell that a checklist is consultant-grade rather than a marketing download is whether it has a column for evidence location. Auditors don’t accept “yes” as evidence. If the checklist has nowhere to record where the proof lives, it wasn’t built by someone who has sat through a Stage 2.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Pre-Engagement Preparation Consultants Complete Before the Gap Analysis

Client AI Inventory and Use Case Cataloging

Nothing in the checklist works without a complete AI inventory, and it’s the input clients get wrong most often. The inventory records every AI system in use: purpose, the role you play (developer, provider, deployer, or user), data consumed, outputs produced, whether a human sits between the output and the decision, and which third-party model or API it depends on. Consultants push hard on shadow AI here: SaaS tools that added AI features, agents running under employee credentials, and internal scripts calling model APIs. Every one of those is in scope until you document why it isn’t.

Defining AIMS Scope Boundaries

Clause 4.3 requires a scope statement naming which AI systems, business units, locations, and lifecycle stages the AIMS covers. Consultants draft this from the inventory, not before it. Scope discipline matters commercially too: certification bodies price audits by audit days, and audit days scale with scope. A narrow, well-justified first scope (the customer-facing AI product, say, rather than every internal tool) is usually the right call for a first certification.

Stakeholder Interview Planning

The checklist needs answers from people who don’t write policies. A typical interview plan covers the executive sponsor (clause 5), the AI or product lead (clauses 6 and 8), data engineering (A.7), procurement or vendor management (A.10), legal or privacy (A.5, A.8), and at least one front-line user of the AI system (A.9). Consultants interview the doers separately from the document owners, because the distance from what the procedure says to what actually happens is the finding.

Document Request List (DRL) Consultants Send Clients

The DRL goes out one to two weeks before fieldwork. A standard ISO 42001 DRL asks for the AI inventory; existing AI, security, and data policies; org chart with AI governance roles; any AI risk assessments or impact assessments; model documentation (model cards, system cards, or whatever exists); training-data provenance and data quality records; supplier contracts for third-party models; incident and change logs; training records; any ISO 27001 ISMS documentation; and the last internal audit and management review minutes if they exist. Missing items become findings rather than delays.

Pro Tip: Return an Honest DRL

Return the DRL with a column that says "does not exist" wherever that's true. Consultants would rather know on day one than discover it in a workshop. An honest DRL shortens fieldwork by days and makes the maturity scores more accurate, which makes the remediation plan cheaper.

Clause-by-Clause Checklist Consultants Use (ISO 42001 Clauses 4 to 10)

ISO 42001 follows the Harmonized Structure shared with ISO 27001 and ISO 9001, so clauses 4 to 10 will look familiar to anyone who has run an ISMS. What’s different is the content each clause demands.

Clause 4 – Context of the Organization Checkpoints

Consultants check for a documented analysis of internal and external issues relevant to AI (4.1), including the organization’s role in the AI value chain and its climate-related considerations; a register of interested parties and their AI-related requirements, covering regulators, customers, affected individuals, and the public (4.2); a scope statement that names AI systems and boundaries (4.3); and evidence that the AIMS is established as a system of interacting processes, not a policy binder (4.4).

Clause 5 – Leadership and AI Policy Evidence

Evidence of top-management commitment (5.1) means budget, named sponsorship, and management review attendance, not a signed statement. The AI policy (5.2) must be approved, communicated, available to interested parties, and aligned with the organization’s AI objectives and principles. Roles and responsibilities (5.3) must be assigned and communicated, with a named accountable owner for the AIMS. Consultants specifically check whether that owner has authority over AI development decisions or is a compliance manager with no say in the roadmap.

Clause 6 – Planning and AI Risk Assessment

This is where first-time assessments break. The checklist looks for AI risk criteria approved by management before assessment started (6.1.2); a risk assessment run per AI system, not per organization; a risk treatment plan with selected controls compared against Annex A and a Statement of Applicability justifying any exclusions (6.1.3); and a separate AI system impact assessment process that considers consequences for individuals, groups, and society (6.1.4). Measurable AI objectives with owners and timelines (6.2) and a controlled change process for the AIMS itself (6.3) complete the clause.

Clause 7 – Support, Resources, and AI Literacy

Consultants verify resources are allocated (7.1), competence is defined and evidenced for AI governance roles (7.2), awareness of the AI policy reaches everyone whose work touches AI systems (7.3), internal and external communication about the AIMS is planned (7.4), and documented information is controlled with versioning and approval (7.5). AI literacy is now a regulatory expectation as well as a standards one: Article 4 of the EU AI Act requires providers and deployers to ensure sufficient AI literacy among staff, and consultants check whether training records would satisfy both.

Clause 8 – Operational Controls and AI Impact Assessments

Clause 8 asks whether the plans in clause 6 actually operate. The checklist tests documented operational processes for AI systems across the lifecycle (8.1); risk assessments repeated on defined triggers such as retraining, new data sources, or vendor model updates, not just annually (8.2); risk treatment plan implementation with evidence each control is running (8.3); and impact assessments completed for every in-scope system, dated, and reviewed (8.4). Consultants sample here rather than review everything, and the sampling approach is covered below.

Clause 9 – Performance Evaluation and Internal Audit

Monitoring and measurement (9.1) needs defined metrics for AI performance and AIMS effectiveness, with records showing they’re tracked. The internal audit program (9.2) must cover the whole AIMS over a cycle, use auditors independent of the areas audited, and produce findings with follow-up. Management review (9.3) must have happened at least once with the inputs the standard names, including risk assessment results and nonconformities, and minutes showing decisions. A management review that has never occurred is the most common reason a Stage 1 audit gets rescheduled. 

Clause 10 – Improvement and Nonconformity Handling

Consultants look for a working corrective action process (10.2): nonconformities logged, root cause recorded, action taken, effectiveness checked. If the client has an ISO 27001 CAPA process, it can be reused with an AI category added. Continual improvement (10.1) is evidenced through a log of changes to the AIMS itself, which is the Plan-Do-Check-Act loop the standard is built on.

Annex A Control Checklist: Consultants Apply (All 38 Controls)

Annex A lists 38 controls across nine objective groups, A.2 through A.10. Unlike ISO 27001, where most organizations apply nearly all 93 controls, ISO 42001 applicability depends heavily on your role in the AI value chain. A deployer of third-party models will exclude several A.6 lifecycle controls with a justification; a model developer will apply almost all of them. Consultants record the current state for all 38 first, then decide applicability after the risk assessment.

A.2 – Policies Related to AI

Three controls: an AI policy (A.2.2), alignment with other organizational policies (A.2.3), and periodic review (A.2.4). Consultants check the policy addresses the topics Annex B recommends, covers the whole lifecycle, and doesn’t conflict with security, privacy, or acceptable-use policies already in force.

A.3 – Internal Organization and Roles

A.3.2 requires defined roles and responsibilities for AI; A.3.3 requires a process for reporting concerns about AI systems. The second one is checked by asking a front-line employee how they’d raise a concern about a model output. If the answer is “I’d message my manager,” there’s no process.

A.4 – Resources for AI Systems

Five controls covering resource documentation (A.4.2), data resources (A.4.3), tooling (A.4.4), system and computing resources (A.4.5), and human resources (A.4.6). Consultants confirm each in-scope AI system has a resource record naming its data sources, models, infrastructure, and the people responsible for it.

A.5 – AI System Impact Assessment

Four controls: a documented process (A.5.2), documented results (A.5.3), and assessments considering impact on individuals and groups (A.5.4) and on society (A.5.5). This is the group auditors probe hardest because it doesn’t exist in any other management system standard. ISO/IEC 42005:2025 provides the method and harm taxonomy, and consultants check whether the client’s template follows it.

A.6 – AI System Lifecycle

Nine controls in two sub-groups: management guidance for development (objectives for responsible development, A.6.1.2, and lifecycle processes, A.6.1.3) and the lifecycle itself (requirements and specification, design and development, verification and validation, deployment, operation and monitoring, technical documentation, and event logging, A.6.2.2 through A.6.2.8). Consultants request the artifact for each stage of one real system and check that the chain is unbroken.

A.7 – Data for AI Systems

Five controls: data management process (A.7.2), acquisition (A.7.3), quality (A.7.4), provenance (A.7.5), and preparation (A.7.6). Provenance is the usual failure: consultants ask for the origin, license, and consent basis of training or fine-tuning datasets, and a surprising number of companies cannot answer for data they’ve been using for years.

A.8 – Information for Interested Parties

Four controls covering system documentation for users (A.8.2), external reporting of AI-related concerns (A.8.3), incident communication (A.8.4), and information for interested parties on the AI system (A.8.5). With the EU AI Act’s Article 50 transparency obligations in force since August 2, 2026, consultants map A.8 evidence to those obligations at the same time.

A.9 – Use of AI Systems

Three controls: a responsible-use process (A.9.2), objectives for responsible use (A.9.3), and documented intended use (A.9.4). For organizations that mostly use rather than build AI, this group and A.10 carry most of the weight.

A.10 – Third-Party and Customer Relationships

Three controls: allocating responsibilities across the value chain (A.10.2), a supplier process for AI (A.10.3), and understanding customer requirements (A.10.4). Consultants sample supplier contracts for foundation-model providers and check whether they address model updates, data use, and incident notification. Standard SaaS terms almost never do.

Evidence Sampling Techniques Consultants Rely On

A gap analysis is a diagnostic, not an audit, so consultants sample rather than review everything. The sampling must be defensible, though, because the auditor will do the same.

Reviewing AI Model Cards and System Documentation

For each in-scope system, consultants ask for whatever documentation exists and score it against A.6.2.7 and A.8.2. A model card that lists intended use, training data summary, evaluation results, known limitations, and version history satisfies most of what the standard wants. A README does not. Where the model is third-party, the consultant checks whether the vendor’s documentation has been reviewed and filed, since that becomes the client’s evidence.

Verifying Data Provenance Records

Consultants pick one dataset, usually the one used for the highest-risk system, and trace it backward: where it came from, under what license or consent, what transformations were applied, and who approved its use. If the trail breaks at any step, A.7.5 is nonconformant, and the finding usually extends to A.7.3 and A.7.4.

Testing Human Oversight and Escalation Logs

Where the AI inventory records a human-in-the-loop, consultants test it. They pull the escalation log for a recent period and check that overrides actually occurred, that reviewers had time and authority to override, and that thresholds for escalation are written down somewhere. An oversight mechanism with zero overrides in six months is either unnecessary or not functioning, and the auditor will ask which.

Sampling Supplier and Vendor Contracts

Consultants sample two or three AI supplier contracts, prioritizing foundation-model providers and any vendor processing customer data through AI. They check for AI-specific clauses: notification of model changes, restrictions on using customer data for training, incident notification timelines, and the right to audit or obtain documentation. Where those clauses are missing, the finding sits under A.10.3 and the remediation is usually a supplier addendum rather than a new contract.

Important: Sampling one system and finding it clean does not clear the control. Consultants pick the highest-risk system deliberately, because if that one fails, the control fails, and if it passes, they still note that lower-risk systems were not tested. Certification auditors sample the same way and will extend the sample if the first item shows a problem.

Gap Scoring and Maturity Rating Framework

Consultant Maturity Levels (Nonexistent to Optimized)

Most consultants use a five-level scale, with each level anchored to something observable so two assessors land within one level of each other. Certification generally requires level 3 on every applicable control and clause requirement. Level 4 is a target for the second surveillance year, not the first audit.

Prioritization Matrix (Impact vs. Remediation Effort)

Consultants plot each gap on two axes: certification impact (would this produce a major, a minor, or an observation) and remediation effort (days of work, dependencies, decisions needed). High impact and low effort gets scheduled first for momentum. High impact and high effort, which is where impact assessment processes and data provenance usually sit, gets scheduled next and drives the critical path. Low impact items are batched, and if the calendar is tight, some are candidates for scope reduction.

Mapping Gaps to Certification Blockers vs. Observations

Every gap gets a classification that predicts what the auditor would do with it. A blocker is a missing mandatory element: no scope, no AI policy, no risk assessment, no impact assessment for an in-scope system, no internal audit, no management review. These become major nonconformities and stop certification. A weakness is a partial or ineffective implementation and becomes a minor. An observation is an improvement opportunity with no audit consequence. Consultants report the counts of each up front, because a client with two blockers and forty observations is in far better shape than one with zero observations and eight blockers.

Deliverables Consultants Produce from the Gap Analysis

Executive Gap Analysis Report

A short document, usually under ten pages, written for the sponsor. It states overall readiness, counts blockers, weaknesses, and observations, summarizes the three or four root causes behind most gaps, and gives a realistic estimate of time and effort to certification readiness. The detailed gap register sits in an appendix or a separate spreadsheet.

Remediation Roadmap with Owner and Timeline

Every gap becomes an action with a named owner (an individual, never a team), a target date, and a dependency note. The roadmap is sequenced so the AIMS can operate for two to three months before Stage 2, because the auditor wants proof controls ran, not just that they were designed. Consultants group actions into sprints, which the transition section below covers.

Statement of Applicability (SoA) Draft

The gap analysis produces a first draft of the SoA: all 38 Annex A controls, with a provisional applicable/not-applicable decision, the justification for each exclusion, and current implementation status. It’s provisional because applicability is finalized only after the risk treatment plan is complete, but a draft at this stage saves weeks later.

Risk Register Populated with AI-Specific Risks

Consultants seed the AI risk register with risks identified during fieldwork: bias in training data, model drift, unexplainable outputs, automation bias in reviewers, dependence on third-party models whose behavior changes without notice, and data provenance gaps. Each entry references the AI system, the affected objective, and the Annex A controls that would treat it. The NIST AI Risk Management Framework and its Generative AI Profile are common sources for the risk taxonomy.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Cross-Standard Mapping Consultants Include in the Checklist

ISO 42001 to ISO 27001 Control Overlap

Because both standards use the Harmonized Structure, clauses 4 to 10 map almost one-to-one. Document control, competence records, internal audit, management review, and corrective action carry over directly, and a company with a working ISMS typically starts an ISO 42001 gap analysis at level 2 or 3 on most clause requirements. Annex A overlap is thinner: A.10 supplier controls map to ISO 27001’s supplier relationship controls, A.7 data controls partially map to information classification and handling, and A.3 roles map to organizational controls. The impact assessment group (A.5) and most of the lifecycle group (A.6) have no ISO 27001 equivalent.

ISO 42001 to NIST AI RMF Mapping

The NIST AI RMF’s four functions align cleanly: Govern maps to clauses 4, 5, and 7 plus A.2 and A.3; Map maps to the inventory, scope, and impact assessment (A.4, A.5); Measure maps to clause 9 and the verification controls in A.6; Manage maps to clause 6 risk treatment, clause 8 operations, and clause 10. Companies that built a NIST-aligned program can present it as ISO 42001 evidence with a mapping table and little rewriting.

ISO 42001 to EU AI Act Obligations

ISO 42001 certification is not EU AI Act compliance, and consultants say so in the report. What it provides is the management system the Act’s risk management (Article 9), documentation (Article 11), record-keeping (Article 12), transparency (Articles 13 and 50), and human oversight (Article 14) obligations assume you have. The Digital Omnibus on AI, in force since July 27, 2026, moved the high-risk obligations for standalone Annex III systems to December 2, 2027, so consultants now build the mapping into the remediation roadmap rather than treating it as urgent. Axipro’s EU AI Act compliance services run this mapping as part of the same engagement for clients with EU exposure.

Worth Knowing: A certification body auditing under ISO/IEC 42006

A certification body auditing under ISO/IEC 42006 will not assess your EU AI Act compliance, and an ISO 42001 certificate is not a conformity assessment. What the certificate does is answer most of the AI questions in enterprise security questionnaires, which is why AI-native SaaS companies are pursuing it before any regulator asks.

Common Findings Consultants Report Across Client Engagements

Across ISO 42001 gap analyses, the same four findings appear in most first-time reports.

Missing AI Impact Assessment Procedures

The most common blocker. Companies with a mature ISO 27001 risk process assume the security risk register covers it and paste “AI” into a few risk titles. It doesn’t. Clause 6.1.4 and A.5 want a separate, outward-facing assessment of consequences for individuals and society, and auditors pull the two apart at Stage 2.

Weak Data Governance for Training Datasets

Companies fine-tuning models on customer data, scraped data, or datasets inherited from a previous team rarely have provenance records. The finding lands under A.7.5 and usually cascades into A.7.3 and A.7.4. Remediation means reconstructing provenance for datasets in use and establishing a process for new ones, which is slow, decision-heavy work.

Undefined Human-in-the-Loop Thresholds

The inventory says a human reviews outputs. Nobody can say which outputs, at what confidence threshold, with what authority to override, or where the record goes. The control exists in name only, and the finding sits across A.6.2.6 operation and monitoring and A.9 responsible use.

Inadequate Supplier AI Due Diligence

Almost every client uses at least one foundation-model API under standard commercial terms that say nothing about model changes, training on customer data, or AI incident notification. A.10.3 is nonconformant, and the remediation is a supplier AI addendum plus a review record.

How Consultants Transition Clients from Gap Analysis to Implementation

Building the Remediation Sprint Plan

Consultants convert the roadmap into two- to three-week sprints ordered by dependency. Sprint one is always foundations: scope, AI policy, roles, risk criteria, and the inventory finalized. Sprint two runs the risk and impact assessments and finalizes the SoA. Sprint three builds the operational controls the SoA calls for. Sprint four runs the internal audit and management review. The AIMS then operates for at least two to three months before Stage 2, and that operating window, not the document writing, is usually the longest item on the calendar. Axipro’s breakdown of how long ISO 42001 certification takes covers the full calendar.

Preparing for Stage 1 and Stage 2 Certification Audits​

Stage 1 is a documentation review: the auditor checks scope, policy, risk methodology, SoA, and whether the internal audit and management review have run. Stage 2 tests operation: interviews, record sampling, evidence that controls produced the intended result. Consultants book the certification body during the gap analysis, not after remediation, because accredited bodies for ISO 42001 are still few and lead times run to a quarter. The body must be independent of the consultant; anyone offering to both implement and certify your AIMS is offering something accreditation rules don’t permit.

The consultant-grade ISO 42001 gap analysis checklist is one document with three questions on every line: does the requirement have evidence, would an auditor accept it, and what happens at certification if it doesn’t. Run against clauses 4 to 10 and all 38 Annex A controls, with evidence sampled from the highest-risk system and gaps scored by certification impact rather than effort, it produces a report, a roadmap, an SoA draft, and a risk register that carry straight into implementation. Axipro’s ISO 42001 gap analysis engagement delivers exactly those four artifacts in one to three weeks, and the full ISO 42001 certification program carries them through to guaranteed certification on the Achievement Plan.

Frequently Asked Questions

How long does a consultant-led ISO 42001 gap analysis take?

One to three weeks from DRL return to report delivery for most organizations, with two to five consultant days of fieldwork. The variables are the number of in-scope AI systems, how complete the AI inventory is when the engagement starts, and whether an ISO 27001 ISMS already exists to reuse. Organizations with no inventory should add a two-week discovery sprint before the gap analysis proper.

Standalone ISO 42001 gap analyses on the wider market run in the low four figures for a fixed-fee engagement, rising to $15,000 to $25,000 at large consulting firms billing day rates. Axipro’s fixed-fee ISO 42001 readiness assessment is priced at $4,500 and is also bundled into the free 30-day Compliance Accelerator Plan. The detailed breakdown of ISO 42001 consulting costs compares both delivery models phase by phase.

Both. The clause and control structure is fixed by the standard, so every credible checklist covers the same requirements. What’s proprietary is the evidence criteria per maturity level, the certification-criticality weighting, the interview scripts, and the sampling approach. Ask to see a redacted sample gap register before hiring; if it lacks evidence locations and criticality ratings, keep looking.

No. Certification bodies working under ISO/IEC 42006 and ISO/IEC 17021-1 must be impartial, and a body that provided consultancy on your AIMS cannot audit it. Consultants perform the gap analysis, implementation support, and internal audit; an accredited certification body performs Stage 1 and Stage 2. A certificate from an unaccredited body carries little weight in enterprise procurement.

A gap analysis is diagnostic and happens before the AIMS is built: it measures distance from the standard and produces a roadmap. An internal audit is a clause 9.2 requirement that happens after the AIMS operates: it tests conformity and effectiveness and produces findings for corrective action. You need the gap analysis to know what to build and the internal audit to prove it works before the certification body checks. The same consultant can do both, provided the internal auditor is independent of the areas they implemented.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

A consultant-grade ISO 42001 gap analysis checklist has 38 Annex A controls, roughly 80 clause-level “shall” statements, and one question attached to every line: where is the evidence, and would a certification body accept it? That last question is what separates the checklists consultants use from the free self-assessment spreadsheets that rank for the same search. This article lays out the checklist itself: what a consultant checks before the engagement starts, the clause-by-clause and control-by-control checkpoints, how evidence gets sampled, how gaps get scored, what the deliverables look like, and what fails most often. Use it to run your own assessment, or to check whether the consultant you’re about to hire is doing the job properly. What Makes a Consultant-Grade ISO 42001 Gap Analysis Checklist Different​ Depth of Evidence Review vs. Self-Assessment Tools A self-assessment tool asks whether you have an AI policy. A consultant asks to see it, checks the approval date and version, reads clause 5.2 against it, and then asks three people in engineering whether they’ve read it. The checklist item is the same. The evidence standard is not. Consultants score every item on three levels: documented, implemented, and effective. A policy that exists but nobody follows scores as “ad hoc,” not “defined.” A control that runs but produces no record scores as unverifiable, which for audit purposes is the same as absent. Self-assessment tools collapse those three levels into a single yes/no, which is why companies that score 85% on a free tool routinely receive major nonconformities at Stage 2. Alignment with Certification Body Expectations Certification bodies auditing against ISO/IEC 42001:2023 now work under ISO/IEC 42006:2025, which sets competence, audit-time, and impartiality requirements for AIMS auditors and builds on ISO/IEC 17021-1. A consultant-grade checklist is written with 42006 in mind: it organizes findings by clause and control identifier, because that’s how the auditor works, and it records evidence locations, because that’s what the auditor will sample. The practical difference shows up in the report. A gap register that says “AI governance needs improvement” is useless in front of an auditor. One that says “A.5.2 not conformant: no documented impact assessment process; two of four in-scope systems have no assessment on file” maps directly to the audit plan. Risk-Weighted Scoring Methodology Self-assessments count gaps. Consultants weight them. A missing AI policy under clause 5.2 and an incomplete competence matrix under 7.2 are both gaps, but the first will block certification and the second will earn you a minor finding. A consultant-grade checklist carries two scores per line: a maturity rating (how far the control is from working) and a certification criticality (what happens at audit if it stays this way). Effort estimates live in the remediation plan, never in the gap score, because mixing them produces a roadmap that fixes easy things first rather than important ones. Insider Note: The fastest tell that a checklist is consultant-grade rather than a marketing download is whether it has a column for evidence location. Auditors don’t accept “yes” as evidence. If the checklist has nowhere to record where the proof lives, it wasn’t built by someone who has sat through a Stage 2. Pre-Engagement Preparation Consultants Complete Before the Gap Analysis Client AI Inventory and Use Case Cataloging Nothing in the checklist works without a complete AI inventory, and it’s the input clients get wrong most often. The inventory records every AI system in use: purpose, the role you play (developer, provider, deployer, or user), data consumed, outputs produced, whether a human sits between the output and the decision, and which third-party model or API it depends on. Consultants push hard on shadow AI here: SaaS tools that added AI features, agents running under employee credentials, and internal scripts calling model APIs. Every one of those is in scope until you document why it isn’t. Defining AIMS Scope Boundaries Clause 4.3 requires a scope statement naming which AI systems, business units, locations, and lifecycle stages the AIMS covers. Consultants draft this from the inventory, not before it. Scope discipline matters commercially too: certification bodies price audits by audit days, and audit days scale with scope. A narrow, well-justified first scope (the customer-facing AI product, say, rather than every internal tool) is usually the right call for a first certification. Stakeholder Interview Planning The checklist needs answers from people who don’t write policies. A typical interview plan covers the executive sponsor (clause 5), the AI or product lead (clauses 6 and 8), data engineering (A.7), procurement or vendor management (A.10), legal or privacy (A.5, A.8), and at least one front-line user of the AI system (A.9). Consultants interview the doers separately from the document owners, because the distance from what the procedure says to what actually happens is the finding. Document Request List (DRL) Consultants Send Clients The DRL goes out one to two weeks before fieldwork. A standard ISO 42001 DRL asks for the AI inventory; existing AI, security, and data policies; org chart with AI governance roles; any AI risk assessments or impact assessments; model documentation (model cards, system cards, or whatever exists); training-data provenance and data quality records; supplier contracts for third-party models; incident and change logs; training records; any ISO 27001 ISMS documentation; and the last internal audit and management review minutes if they exist. Missing items become findings rather than delays. Pro Tip: Return an Honest DRL Return the DRL with a column that says “does not exist” wherever that’s true. Consultants would rather know on day one than discover it in a workshop. An honest DRL shortens fieldwork by days and makes the maturity scores more accurate, which makes the remediation plan cheaper. Clause-by-Clause Checklist Consultants Use (ISO 42001 Clauses 4 to 10) ISO 42001 follows the Harmonized Structure shared with ISO 27001 and ISO 9001, so clauses 4 to 10 will look familiar to anyone who has run an ISMS. What’s different is the content each clause demands. Clause 4 – Context of the Organization Checkpoints Consultants check for a documented analysis of

Scigeniq, a UAE life sciences software vendor, completed SOC 2 Type 2 and ISO 27001 in one three-month engagement with Axipro and Vamu.

ISO/IEC 42001:2023 asks for three assessments, and most teams try to squeeze them into one spreadsheet: a gap analysis against clauses 4 to 10 and Annex A, an AI risk assessment under clause 6.1.2, and an AI system impact assessment under clause 6.1.4. Treat them as one exercise and the auditor pulls them apart for you at Stage 2. Treat them as three unrelated projects and you triple the workshops, the registers, and the remediation lists. What works is a single methodology with distinct outputs that share inputs, share a traceability matrix, and feed one remediation plan. This article lays out that methodology end to end: how gap analysis and risk assessment fit together under ISO 42001, how to prepare, the step-by-step process for each, how to merge the outputs into one risk treatment plan, the registers and templates you’ll need, and what a certification body expects to see when you’re done. Why Gap Analysis and Risk Assessment Must Work Together Under ISO 42001 A gap analysis measures distance from the standard. A risk assessment measures exposure from your AI systems. They answer different questions, and ISO 42001 makes them depend on each other in a way ISO 27001 only implies. Clause 6.1.3 requires you to compare the controls you select through risk treatment against Annex A, and to justify any Annex A control you leave out in the Statement of Applicability (SoA). So your Annex A gap analysis has no defensible baseline until the risk assessment tells you which controls you need. Run the gap analysis on its own, and you end up scoring yourself against all 38 controls, including ones your risk profile never called for. Run the risk assessment on its own, and you pick treatments with no idea what already exists to deliver them. The methodology below interleaves the two. A clause-level gap review sets the scope and evidence base, the risk and impact assessments decide which controls are required, and a control-level gap review then scores only what matters. How AI-specific risks shape the methodology Traditional information security risk works from confidentiality, integrity, and availability. AI risk adds categories that don’t map neatly onto any of those: model drift, bias in training data, outputs nobody can explain, automation bias in the humans doing the reviewing, and dependence on third-party foundation models whose behavior changes without warning. ISO/IEC 23894, the companion guidance on AI risk management, adapts the ISO 31000 cycle (establish context, identify, analyze, evaluate, treat) to these sources rather than inventing a new one. That’s why the methodology here keeps the familiar ISO 31000 shape and changes the inputs, not the process. Regulatory and business drivers for a formal methodology The commercial driver is procurement. Enterprise security questionnaires now ask whether you ran an AI impact assessment, whether a human reviews high-stakes outputs, and which third-party models touch customer data. A documented methodology answers those questions with evidence instead of assurances. The regulatory driver is the EU AI Act, and its timeline moved in July. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026, and pushed the high-risk obligations for standalone Annex III systems from August 2, 2026 to December 2, 2027. Annex I embedded systems moved to August 2, 2028. The Article 50 transparency obligations still kicked in on August 2, 2026, as originally planned. Article 9 of the AI Act text on EUR-Lex requires a risk management system for high-risk AI that runs continuously across the system lifecycle, which is exactly what an ISO 42001 methodology gives you. Sixteen extra months is time to build it properly, not a reason to shelve it. Core Principles of an ISO 42001 Gap Analysis and Risk Assessment Methodology Four principles keep the methodology defensible in front of a certification body. Alignment with clauses 4 to 10 and Annex A. Every finding in the gap register cites a clause or an Annex A control identifier. Auditors work clause by clause, so a gap register organized any other way forces a translation step during the audit that nobody enjoys. Integration with the AI system impact assessment. Clause 6.1.4 is what separates ISO 42001 from every other Annex SL standard. The impact assessment looks outward at individuals, groups, and society. The risk assessment under 6.1.2 looks inward at the organization. The standard wants both as separate documented outputs, and the consequences you find in the impact assessment have to feed back into the risk assessment. So the methodology runs the impact assessment as a scheduled input to risk analysis, not something bolted on the week before the audit. Risk-based thinking applied to the AIMS itself. Clause 6.1.1 also asks you to consider risks and opportunities to the management system: someone leaving the AI governance function, a vendor retiring a model, a regulator changing its classification rules. These go in the same register with a different category tag. Defined inputs, outputs, and success criteria. Inputs are the AI system inventory, the scope statement, existing policies, data flow diagrams, model documentation, and your risk criteria. Outputs are the gap register, the AI risk register, impact assessment reports, the SoA, and the risk treatment plan. Success means each output traces to the others, every gap and risk has an owner, and an internal auditor could repeat the process and land somewhere similar. Insider Note: Impact assessments are where certification auditors probe hardest, because they’re the most distinctive part of ISO 42001 compared with ISO 27001. A recycled security risk register with “AI” pasted into the risk titles gets picked apart in Stage 2. Build the impact assessment methodology properly the first time. It’s far cheaper than rebuilding it under a nonconformity deadline. Preparing for the Gap Analysis and Risk Assessment Preparation is where most of the calendar time goes, and where most later problems start. Define scope, boundaries, and the AI system inventory. Scope under clause 4.3 has to name which AI systems, business units, and lifecycle stages the AIMS covers. You can’t write