ISO/IEC 42001
Gamut supports an organisation-level AI management system (AIMS) conformity-readiness assessment aligned to ISO/IEC 42001:2023. It covers clauses 4 to 10 as atomic assessor checks and maintains a Statement of Applicability for the Annex A reference controls.
The central question is:
Within the approved AIMS scope, what evidence supports conformity with each requirement, which Annex A controls are applicable, and what nonconformities or limitations prevent a defensible readiness conclusion?
Start here
Section titled “Start here”| If you need to… | Read |
|---|---|
| Define the AIMS scope and understand clauses 4–10 and Annex A | Scope, clauses and Annex A |
| Complete the assessment | Assessment workflow |
| Explain conformity, assurance and the SoA | Conformity, assurance and SoA |
| Prepare evidence, audit tests and findings | Evidence, audit and findings |
| Use per-requirement or complete-scope AI assistance | AI Assist and security |
| Produce a readiness conclusion without overstating certification | Reporting and certification readiness |
| Look up labels and definitions | Reference and glossary |
At a glance
Section titled “At a glance”| Property | Gamut assessment |
|---|---|
| Standard | ISO/IEC 42001:2023, edition 1 |
| Nature | Certifiable AI management-system requirements standard |
| Scope | Approved organisation-level AIMS boundary |
| Structure | Clauses 4–10 plus Annex A reference controls |
| Assessment checks | 173 atomic clause checks plus 38 Annex A controls |
| Conformity labels | Not assessed, Conformity supported, Partial evidence, Nonconformity |
| Assurance depth | Unverified, Documented, Implemented, Assured |
| Annex A applicability | Undetermined, Applicable, or justified Not applicable |
| Evidence boundary | Scope-, period- and requirement-specific |
| AI support | Per requirement and, after completion, whole-scope readiness analysis |
| Human accountability | Scope approval, SoA decisions, findings and final conclusion remain human-owned |
The eight assessment sections
Section titled “The eight assessment sections”| Section | Checks | Purpose |
|---|---|---|
| Context of the Organisation | 14 | Context, interested parties, AIMS scope and management-system processes |
| Leadership | 21 | Commitment, AI policy, responsibilities and authorities |
| Planning | 49 | Risks and opportunities, risk assessment, treatment, impacts, objectives and change |
| Support | 26 | Resources, competence, awareness, communication and documented information |
| Operation | 19 | Operational control, AI risk work and impact assessment |
| Performance Evaluation | 32 | Monitoring, measurement, internal audit and management review |
| Improvement | 12 | Nonconformity, corrective action and continual improvement |
| Annex A Reference Controls | 38 | Applicability and implementation of AI-specific reference controls |
Atomic checks make compound requirements assessable without treating one strong sub-part as proof of the whole clause.
How Gamut operationalises the AIMS assessment
Section titled “How Gamut operationalises the AIMS assessment”Approved organisation-level AIMS scope → clauses 4–10 assessed atomically → Annex A applicability and implementation decisions → requirement-level conformity and assurance depth → evidence, audit tests, nonconformities and corrective action → coverage and readiness gates → human conformity-readiness conclusion → management review and continual improvementWhat a defensible record contains
Section titled “What a defensible record contains”- Named AIMS scope, boundaries, functions, sites and activities.
- Included AI systems and justified exclusions.
- Interested parties, owner, approver, version and approval date.
- A conformity result and rationale for every applicable atomic check.
- Separate assurance depth showing how strongly the result was verified.
- A complete, risk-linked Statement of Applicability.
- Accepted objective evidence and representative audit tests.
- Nonconformities, owners, corrective action and verification.
- Evidence cutoff, limitations, next review and accountable conclusion.
What the assessment does not prove
Section titled “What the assessment does not prove”It does not by itself prove:
- ISO/IEC 42001 certification.
- That a management system operates outside the defined scope.
- That an Annex A control is effective because it is marked applicable.
- That a policy is implemented.
- Legal compliance in every jurisdiction.
- That a mapped framework score satisfies an ISO requirement.
- That AI-generated analysis is an audit opinion.