
Evaluate
ISO/IEC 42001 gap analysis
The distance between where you are and a certifiable AI management system, clause by clause and control by control, with what closing it costs. Written so it can be read alongside your ISO 27001 position rather than as a separate world.
Duration
3–4 weeks
Built on
ISO/IEC 42001 · ISO/IEC 27001:2022
Indicative price
€8,500–19,000 per engagement
Who this is for
CISO or head of governance
Runs an ISMS already and is being asked to extend it to AI.
Chief compliance officer
Needs certification to answer client questions.
CEO
Is losing or winning deals on the answer to 'what is your AI governance'.
Quality manager
Runs other management systems and wants this one to integrate rather than duplicate.
The first certifiable standard for AI governance, and most of it is not about AI
ISO/IEC 42001 is the first international standard that certifies an AI management system, and its arrival changed the conversation — because for the first time there is an answer to 'how do we know your AI governance is real' that is not a slide.
What surprises people is how much of it is management system machinery rather than AI specifics. Scope, leadership, risk process, competence, documented information, internal audit, management review — if you hold ISO/IEC 27001 you already operate most of that, and the gap analysis should tell you which parts you can reuse rather than rebuild.
The genuinely new material is where the value sits. An AI system inventory that reflects reality. Impact assessment that considers effects on the people a system acts upon, not only risk to the organisation — a distinction that does not exist in an ISMS and is the one most often missed. Data and model lifecycle controls. Human oversight designed to be operable rather than nominal.
That last point deserves emphasis, because 'a human reviews the output' is written into a great many designs and survives contact with almost no auditor. If the human has three seconds, no context, and no realistic path to disagree, the oversight is decorative. An auditor will test it.
We assess against every clause and every Annex A control, mark what your existing management systems already satisfy, and cost the remainder. Where you hold ISO/IEC 27001, expect a meaningful proportion to be reusable — and expect the AI-specific gaps to be the real work.
How we do it
- 01
Scope and integration
3 days
What the AI management system will cover, and how it relates to management systems you already run. Getting the integration right here avoids duplicating an entire documentation set.
- 02
AI inventory
1 week
What AI you build, buy, embed and use. The same problem as the EU AI Act inventory and, where both engagements run, the same piece of work done once.
- 03
Clause assessment
1 week
Every clause, with what your existing systems already satisfy marked explicitly.
- 04
Annex A control assessment
1 week
Control by control, on evidence. Impact assessment, data governance, model lifecycle and human oversight examined properly rather than confirmed.
- 05
Gap costing
3–5 days
Effort and cost per gap, separating documentation work from things requiring budget or a procurement cycle.
- 06
Readout and plan
2 days
Sequenced plan, certification timeline worked back from your target, and an indication of certification body fees.
Named artefacts
What you receive
- Scope recommendation, including how it integrates with existing management systems
- AI system inventory
- Clause-by-clause assessment, marking what existing systems already satisfy
- Annex A control assessment on evidence
- Human oversight design review — whether it is operable or nominal
- Costed remediation plan with effort per gap
- Certification timeline worked back from your target date
- Indicative certification body fees
What we need from you
- Your existing management system documentation. The more you have, the more we can mark as reusable.
- Access to whoever knows what AI is actually in use, including outside IT.
- Product or engineering time where you build systems rather than only use them.
- Your commercial reason for certifying. It genuinely changes the scope we recommend.
What changes
- 01You know what certification would cost before committing.
- 02You know how much of your ISO 27001 work counts towards it.
- 03The AI-specific gaps are separated from the management system gaps.
- 04Human oversight is assessed as it would be by an auditor rather than as designed.
- 05One inventory serves both this and your EU AI Act position.
What it costs
€8,500–19,000 per engagement
All prices exclude VAT.
Questions
We hold ISO 27001. How much carries over?
The management system machinery largely does — scope, leadership, competence, documented information, internal audit, management review. The AI-specific requirements do not: inventory, impact assessment on affected people, data and model lifecycle, human oversight. In practice clients with a mature ISMS find the effort materially lower, and the gap analysis tells you by how much rather than promising it.
Is certification worth it, or is conformity enough?
It depends who is asking you. If clients or tenders ask for evidence of AI governance, a certificate ends the conversation and a self-assessment does not. If nobody is asking, conformity without certification captures most of the operational benefit at lower cost. We will give you a view rather than assume you want the certificate.
How long to certification?
Typically six to twelve months from this assessment, depending on the gaps and how much of an existing management system you can reuse.
Can you implement as well as assess?
Yes — that is the ISO 42001 implementation engagement, and the assessment fee is credited against it if you proceed within ninety days. We cannot perform your certification audit; that must come from an accredited body independent of us.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.