An ISO 42001 gap analysis tells you exactly where your AI management system falls short of the standard before an auditor finds the gaps for you. It compares what you're doing today against every clause and Annex A control in ISO/IEC 42001, then gives you a prioritised list of fixes.
Why this matters
ISO/IEC 42001, published in December 2023, is the first international standard for AI management systems. UK tech companies building or deploying AI products are increasingly asked for it in procurement and enterprise sales cycles, the same way ISO 27001 became a baseline ask a decade ago.
Skipping the gap analysis and walking straight into a certification audit is the most common way companies fail stage 1. A structured ISO 42001 AI management system certification process starts with knowing where you stand, not guessing.
A gap analysis in 2026 costs you time now to save weeks of audit delays later. Get it wrong and you're re-scoping evidence mid-audit while the clock on your Series B due diligence or enterprise contract keeps running.
What you need before you start
- An up-to-date inventory of every AI system, model, or third-party AI tool your business builds, deploys, or uses in production
- A named AI governance owner — someone accountable for the management system, not just IT
- Existing ISO 27001 documentation if you're certified already, since ISO 42001 shares structure with it
- Two to four weeks of stakeholder time across engineering, legal, and product
- A copy of the ISO/IEC 42001:2023 standard text and its Annex A control list
If you're starting from spreadsheets and shared drives, expect the gap analysis itself to surface how scattered your evidence is. That's normal — it's the point of doing this before the auditor does.
The 7 steps to run an ISO 42001 gap analysis
1. Inventory every AI system in use
List every AI system your business owns, builds, or depends on — internal models, vendor APIs, embedded AI features in SaaS tools you've bought. This becomes the scope of your management system.
Miss a system here and it stays out of scope for the whole certification, which auditors flag immediately. Expected outcome: a single register with system name, purpose, data inputs, and risk level.
Common mistake: teams list only the AI products they sell and forget the AI tools they use internally, like coding assistants or support chatbots.
2. Map ISO/IEC 42001 clauses and Annex A controls
ISO 42001 splits into management system clauses (4-10) and Annex A controls covering AI-specific risk, impact assessment, and lifecycle management. Go through each one and note whether you have a documented practice, a partial practice, or nothing.
If you've already run an ISO 27001 gap analysis, the methodology transfers directly — same clause-by-clause comparison, same scoring logic, different control set. Teams that have already mapped ISO 27001 Annex A controls to existing IT controls move faster here because a lot of the underlying infrastructure controls overlap.
Expected outcome: a control-by-control matrix with a status for each item.
3. Compare current practice against each control
For every control marked partial or missing, write down exactly what's missing — not "we need better documentation" but "no documented process for AI impact assessment before model deployment."
Vague gap descriptions produce vague remediation plans that stall in 2026 as much as they did in 2023. Specificity here saves weeks later.
4. Score and prioritise every gap
Rank each gap by two factors: risk if left unaddressed, and effort to close. High-risk, low-effort gaps go first — these are your quick wins.
A missing AI risk register is high risk and low effort to build. A missing bias-testing pipeline for a production model is high risk and high effort — it needs a project plan, not a checklist item.
Common mistake: treating every gap as equal priority, which buries the two or three critical items that actually block certification under a pile of minor documentation gaps.
5. Assign owners and deadlines
Every open gap needs one named owner and one date. Gaps without an owner don't get closed — they get discussed in the next three review meetings instead.
Build this into whatever project tracker your team already uses. Expected outcome: a remediation plan with 100% of gaps assigned, not just the easy ones.
6. Automate evidence collection as you close gaps
As each gap closes, you need evidence an auditor can check — policies, logs, sign-offs, training records. Manual evidence-chasing is where certification timelines slip hardest.
Teams that automate evidence collection for audits cut the admin load significantly because the evidence gets captured as the work happens, not reconstructed the week before the audit. OneClickComply handles this end-to-end so evidence collection stops being a separate project.
7. Re-run the gap analysis before the certification audit
Don't treat the gap analysis as a one-time event. Re-run it two to four weeks before your stage 1 audit to confirm the gaps you closed are still closed and nothing new opened up.
Common mistake: closing 90% of gaps, declaring victory, and never checking the remaining 10% again until the auditor asks.
Automate your ISO 42001 evidence trail
OneClickComply handles compliance end-to-end so you're not chasing screenshots before audit day.
Troubleshooting: common gap analysis problems
Problem: Nobody owns the AI governance function. Fix: assign a single accountable owner before you start the gap analysis, even if it's a part-time role initially. Without ownership, gaps don't close.
Problem: The AI system inventory keeps growing mid-analysis. Fix: freeze the scope for the current gap analysis cycle, log new systems separately, and fold them in on the next review.
Problem: Gaps overlap heavily with existing ISO 27001 controls. Fix: that's expected. Cross-reference rather than duplicating documentation — one policy can satisfy both frameworks if it's written broadly enough.
Problem: Engineering teams see the gap analysis as a compliance-only exercise. Fix: tie specific gaps to product risk — a missing model monitoring control is an engineering risk, not just a paperwork gap.
Problem: The gap list is too long to action before the target audit date. Fix: re-score by risk and push the low-risk, high-effort items to a post-certification roadmap. Certification doesn't require zero gaps, it requires a documented management system with evidence of continual improvement.
Tools and resources
- The ISO/IEC 42001:2023 standard text and Annex A control list
- Your existing ISO 27001 policy set, if certified, as a starting template
- A shared AI system inventory, updated on a fixed schedule
- Automated evidence collection so gap-closure work generates its own audit trail
- OneClickComply for managing the gap analysis, remediation tracking, and evidence in one place instead of spreadsheets and shared drives
What to do next
Once your gap analysis is scored and owned, the next task is deciding whether you're running ISO 42001 alongside an existing framework or building it from scratch. Either way, the automated evidence collection process is what turns your remediation plan into something an auditor can actually verify in 2026, rather than a list of promises.
Frequently asked questions
One last thing
The teams that pass ISO 42001 certification on the first attempt aren't the ones with zero gaps — they're the ones who scored their gaps honestly and closed the high-risk ones first. Certification doesn't require a perfect management system, it requires evidence that you know where the gaps are and you're closing them. That's the whole exercise, and it's Seriously Simple Cyber Compliance when you treat it that way.
