Guide

AI Governance Gap Assessment Against ISO/IEC 42001

An ISO/IEC 42001 readiness assessment examines whether an organisation has a working management system for the AI it develops, provides or uses. It identifies the gap between current governance and the organisation's chosen scope, then converts that gap into an implementation plan. Certification, if pursued, is performed independently by an external certification body.

Understand what ISO/IEC 42001 assesses

ISO/IEC 42001 is a management-system standard for organisations that develop, provide or use AI systems. It addresses how the organisation establishes responsibilities, objectives, processes and continual improvement around AI risks and opportunities. It does not certify that every model is accurate, safe, unbiased or suitable for every use.

This distinction determines the assessment. A readiness review must examine the organisational system through which AI is approved, operated, monitored and improved. Evidence about individual systems remains necessary, but it sits within a wider arrangement of leadership, ownership, risk management, competence, documentation, review and corrective action.

Decide why the organisation is using the standard

An organisation can implement ISO/IEC 42001 without seeking certification. Management may want a consistent internal system, stronger evidence for customers and procurement, integration with existing management systems, or preparation for an external certification audit.

The objective affects the work. An organisation seeking internal improvement may prioritise the highest-consequence gaps first. An organisation preparing for certification must also establish the defined scope, required documented information, internal audit, management review and evidence that the system operates. The assessment should record the chosen objective rather than assuming that certification is the only meaningful outcome.

Define the scope of the AI management system

The organisation needs a clear boundary for the management system. The scope may cover the whole organisation or defined units, products, services or AI activities. It should reflect the organisation's role as a developer, provider or user and the relationships that affect its ability to manage AI.

A scope that is too broad may create a programme the organisation cannot operate. A scope that excludes material AI use can produce an orderly system around the least important activity. The assessment therefore begins with the business context, interested parties, applicable obligations, AI inventory, organisational boundaries and dependencies on suppliers or group functions.

Examine the current management system

The gap assessment should examine both design and operation. Relevant evidence can include:

  • leadership accountability, policy and AI objectives;
  • the inventory of AI systems, uses, owners and affected decisions;
  • methods for identifying risks, opportunities and impacts;
  • approval, development, acquisition, deployment, use and retirement controls;
  • data, documentation, traceability and record-keeping arrangements;
  • responsibilities, competence, awareness and communication;
  • third-party selection, information rights, monitoring and change control;
  • performance measures, incidents, complaints and corrective action;
  • internal audit, management review and continual improvement; and
  • connections with information security, privacy, quality, risk, compliance and operational management.

A policy can satisfy a documentation need while leaving the operating gap untouched. Interviews, records and examples of recent decisions help establish whether the described process is actually used.

Connect the inventory to risk and impact

The management system needs to distinguish AI uses by purpose, context and consequence. An assistant that drafts internal text does not require the same evidence and control as a system that affects customer access, employment, money, safety or a material operation.

The assessment examines whether the organisation can identify affected people and processes, assess possible impact, decide what level of evidence and oversight is proportionate, and revisit that decision when the system or context changes. ISO/IEC 23894 provides related guidance on AI risk management, while ISO/IEC 42005 addresses AI system impact assessment. Their application must still be adapted to the organisation and its AI uses.

Map obligations without confusing them with the standard

ISO/IEC 42001 can help an organisation structure how it identifies and manages applicable obligations. It does not replace those obligations or provide a legal opinion. UAE organisations may need to consider data protection, consumer, employment, sector, outsourcing, cybersecurity and contractual requirements according to the systems and activities in scope.

The readiness assessment records where those requirements enter the management system, who interprets them and what evidence the organisation retains. Appropriately qualified legal, regulatory, privacy and cybersecurity specialists remain responsible for specialist conclusions. Certification to the management-system standard does not by itself demonstrate compliance with every applicable rule.

Turn gaps into an implementation roadmap

A useful gap register explains more than whether a requirement appears present. Each finding should identify the current evidence, the missing or ineffective condition, the significance of the gap, the responsible owner and the action needed to close it.

Marketways groups actions into a practical sequence. The organisation may need to clarify scope and accountability before writing detailed procedures. It may need an AI inventory before it can apply risk classification. It may need evaluation and monitoring evidence before management can define continued-use criteria. Dependencies, resources and decision points should be visible so the roadmap reflects how the system will operate rather than producing a collection of disconnected documents.

Prepare evidence that the system operates

Readiness develops through repeated use. The organisation needs records showing that relevant AI uses have passed through the defined processes, that performance and incidents are reviewed, that changes lead to reassessment where required and that corrective actions are completed.

Internal audit and management review test whether the management system conforms to the organisation's arrangements and remains effective. Findings should be resolved through the organisation's own improvement process. If the organisation later seeks certification, an external certification body conducts that assessment. ISO develops the standard but does not certify organisations.

What the readiness assessment should deliver

Management should receive a defined scope, an evidence-based current-state assessment, a prioritised gap register and an implementation roadmap. The result should distinguish missing design, weak operation and insufficient evidence. It should also identify decisions that only management can make, including risk appetite, permitted use, accountability, resourcing and whether external certification is commercially or contractually worthwhile.

The assessment is complete when leaders can see what must change, why it matters, who owns the work and what evidence will show that the change operates. A percentage readiness score without this reasoning is unlikely to support implementation.

How Marketways supports ISO 42001 readiness

Marketways connects the standard-specific review to the organisation's actual AI systems, decisions and operating conditions. The work can include scope definition, inventory review, stakeholder interviews, evidence assessment, process mapping, gap classification, governance design and the implementation roadmap.

AI Governance and Model Risk owns the broader service and can support implementation of accountability, risk classification, controls and monitoring. AI Agent Evaluation and Assurance is relevant when a material gap concerns evidence about a defined system. AI Vendor Selection is relevant when third-party requirements and due diligence must be built into an acquisition.

Marketways does not issue ISO certificates, act as the independent certification body or guarantee certification. We do not provide legal advice, regulatory certification, penetration testing or independent cybersecurity assurance.

What to bring to the first discussion

Useful starting material includes the intended scope, reason for using the standard, AI inventory, governance policies, organisation chart, risk and impact records, lifecycle procedures, supplier arrangements, evaluation evidence, incidents, performance reports, internal audit material and existing management systems. An incomplete inventory or immature process does not prevent an assessment. It becomes part of the current-state finding.

Independence and scope

Marketways is an independent management, analytics and AI consultancy. It is not affiliated with, appointed by or representing the UAE Government, the Government of Dubai, the Dubai Centre for Artificial Intelligence or any regulator or public initiative mentioned on this page. This article interprets public sources for workflow, implementation, evaluation and governance planning. It is not legal advice, regulatory approval, certification or an official statement of policy. Readers should confirm current requirements with the responsible authority and obtain specialist advice where needed.

References

  1. ISO, ISO/IEC 42001:2023 AI management systems
  2. ISO, Management system standards
  3. ISO, Certification
  4. ISO, ISO/IEC 23894:2023 Guidance on risk management
  5. ISO, ISO/IEC 42005:2025 AI system impact assessment