ISO/IEC 42001 Gap Assessment and Statement of Applicability
Every ISO/IEC 42001 clause and control the records map to, with the legal duties behind each, applicability, implementation status and evidence, in the form a Statement of Applicability takes.
What's inside
- Gap sheet: each mapped clause, the duties and controls mapped to it, applicable and implemented dropdowns, evidence, gap, owner
- Statement of Applicability sheet, derived from the gap sheet by formula
- Mappings sheet: every recorded crosswalk with its confidence
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Gap assessment
| ISO/IEC 42001 reference | Duties mapped | Controls mapped | Legal duties behind it | Recorded controls | Mapping confidence | Applicable ▾ | Justification (if not applicable) | Implementation ▾ | Evidence | Gap and action | Owner |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Annex A.5.2, A.7.3 | 1 | 0 | Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights (Texas Responsible AI Governance A | medium | |||||||
| Annex A.6.1.2, A.9.4 | 1 | 0 | Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class (Texas Responsible AI Governance Act (TRAIGA)) | medium | |||||||
| Annex A.6.2.4 | 0 | 2 | Accuracy, robustness, fairness and security testing; Adversarial and red-team testing for generative AI | high | |||||||
| Annex A.6.2.4; Clause 9.2 | 1 | 0 | Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool (NYC Local Law 144 (automated employm | medium | |||||||
| Annex A.6.2.5, A.9.2, A.9.3 | 0 | 1 | Human oversight design and override procedure | medium | |||||||
| Annex A.6.2.7, A.8.2, A.10.4 | 1 | 0 | Providers of GPAI models must maintain technical documentation and inform downstream providers (EU AI Act) | high |
The references are those the recorded duties and controls map to; the mappings are editorial, with a stated confidence, not the standard's text.
Sheet: Statement of Applicability
| Reference | Applicable ƒ | Implementation ƒ | Justification ƒ |
|---|---|---|---|
| Annex A.5.2, A.7.3 | = | = | = |
| Annex A.6.1.2, A.9.4 | = | = | = |
| Annex A.6.2.4 | = | = | = |
| Annex A.6.2.4; Clause 9.2 | = | = | = |
| Annex A.6.2.5, A.9.2, A.9.3 | = | = | = |
| Annex A.6.2.7, A.8.2, A.10.4 | = | = | = |
Derived from the gap sheet by formula: complete that sheet and this one follows.
Sheet: Controls
| Control | Kind | Purpose | Typical owner | Frequency | Duties it satisfies | Duties it supports | Evidence it produces | ISO/IEC 42001 | NIST AI RMF | Record |
|---|---|---|---|---|---|---|---|---|---|---|
| AI governance policy and accountability structure | Policy | Gives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other A | Executive sponsor for AI | annual | 9 | 7 | AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility map | Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3 | GOVERN 1.1, 1.2, 1.3, 2.1, 3.1 | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability |
| AI impact and fundamental-rights impact assessment | Process | Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the | AI system owner | per_system | 4 | 7 | AI impact assessment; Impact assessment approval; Impact assessment procedure and template | Clause 6.1.4, 8.4; Annex A.5 | MAP 5.1, 5.2; MEASURE 2.11 | https://aipolicytracker.org/controls/ai-impact-assessment |
| AI incident management and regulatory reporting | Process | Ensures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and af | Incident coordinator | continuous | 9 | 5 | AI incident response playbook; AI incident record; Incident report to an authority | Clause 10.2; Annex A.8.3, A.8.4 | MANAGE 4.1, 4.3; GOVERN 4.3, 6.2 | https://aipolicytracker.org/controls/ai-incident-management-and-reporting |
| AI interaction and use disclosure notices | Process | Tells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that the | Product owner | on_material_change | 14 | 3 | AI interaction or use notice; Notice catalogue; Notice wording approval | Annex A.8.2, A.8.5 | MEASURE 2.8; GOVERN 5.1 | https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure |
| AI literacy and role-based training programme | Training | Gives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of | Learning and development lead | annual | 1 | 3 | AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materials | Clause 7.2, 7.3; Annex A.4.6 | GOVERN 2.2, 4.1 | https://aipolicytracker.org/controls/ai-literacy-and-role-based-training |
| AI risk assessment and lifecycle risk register | Process | Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from | AI system owner | per_system | 7 | 5 | AI system risk assessment; Per-system AI risk register; Residual-risk acceptance | Clause 6.1.2, 6.1.3, 8.2, 8.3 | MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1 | https://aipolicytracker.org/controls/ai-risk-assessment |
Duties this template covers (107)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
- Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
- Large frontier developers must publish a frontier AI framework
- Report critical safety incidents to the Office of Emergency Services
- Frontier developers must publish a transparency report before deploying a new frontier model
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Frontier developers must protect employees who report catastrophic-risk concerns
- Notify consumers before automated decision-making technology influences a consequential decision
- Disclose the use of the technology and the principal reasons after an adverse consequential decision
- Offer meaningful human review of an adverse consequential decision
- Keep records of consequential decisions influenced by the technology for three years
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the ISO/IEC 42001 Gap Assessment and Statement of Applicability free?
- Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 26 recorded duties are cited in it, drawn from 20 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the ISO/IEC 42001 Gap Assessment and Statement of Applicability free?
- Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 26 recorded duties are cited in it, drawn from 20 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.