Skip to content

ISO/IEC 42001

Gamut supports an organisation-level AI management system (AIMS) conformity-readiness assessment aligned to ISO/IEC 42001:2023. It covers clauses 4 to 10 as atomic assessor checks and maintains a Statement of Applicability for the Annex A reference controls.

The central question is:

Within the approved AIMS scope, what evidence supports conformity with each requirement, which Annex A controls are applicable, and what nonconformities or limitations prevent a defensible readiness conclusion?

If you need to…Read
Define the AIMS scope and understand clauses 4–10 and Annex AScope, clauses and Annex A
Complete the assessmentAssessment workflow
Explain conformity, assurance and the SoAConformity, assurance and SoA
Prepare evidence, audit tests and findingsEvidence, audit and findings
Use per-requirement or complete-scope AI assistanceAI Assist and security
Produce a readiness conclusion without overstating certificationReporting and certification readiness
Look up labels and definitionsReference and glossary
PropertyGamut assessment
StandardISO/IEC 42001:2023, edition 1
NatureCertifiable AI management-system requirements standard
ScopeApproved organisation-level AIMS boundary
StructureClauses 4–10 plus Annex A reference controls
Assessment checks173 atomic clause checks plus 38 Annex A controls
Conformity labelsNot assessed, Conformity supported, Partial evidence, Nonconformity
Assurance depthUnverified, Documented, Implemented, Assured
Annex A applicabilityUndetermined, Applicable, or justified Not applicable
Evidence boundaryScope-, period- and requirement-specific
AI supportPer requirement and, after completion, whole-scope readiness analysis
Human accountabilityScope approval, SoA decisions, findings and final conclusion remain human-owned
SectionChecksPurpose
Context of the Organisation14Context, interested parties, AIMS scope and management-system processes
Leadership21Commitment, AI policy, responsibilities and authorities
Planning49Risks and opportunities, risk assessment, treatment, impacts, objectives and change
Support26Resources, competence, awareness, communication and documented information
Operation19Operational control, AI risk work and impact assessment
Performance Evaluation32Monitoring, measurement, internal audit and management review
Improvement12Nonconformity, corrective action and continual improvement
Annex A Reference Controls38Applicability and implementation of AI-specific reference controls

Atomic checks make compound requirements assessable without treating one strong sub-part as proof of the whole clause.

How Gamut operationalises the AIMS assessment

Section titled “How Gamut operationalises the AIMS assessment”
Approved organisation-level AIMS scope
→ clauses 4–10 assessed atomically
→ Annex A applicability and implementation decisions
→ requirement-level conformity and assurance depth
→ evidence, audit tests, nonconformities and corrective action
→ coverage and readiness gates
→ human conformity-readiness conclusion
→ management review and continual improvement
  • Named AIMS scope, boundaries, functions, sites and activities.
  • Included AI systems and justified exclusions.
  • Interested parties, owner, approver, version and approval date.
  • A conformity result and rationale for every applicable atomic check.
  • Separate assurance depth showing how strongly the result was verified.
  • A complete, risk-linked Statement of Applicability.
  • Accepted objective evidence and representative audit tests.
  • Nonconformities, owners, corrective action and verification.
  • Evidence cutoff, limitations, next review and accountable conclusion.

It does not by itself prove:

  • ISO/IEC 42001 certification.
  • That a management system operates outside the defined scope.
  • That an Annex A control is effective because it is marked applicable.
  • That a policy is implemented.
  • Legal compliance in every jurisdiction.
  • That a mapped framework score satisfies an ISO requirement.
  • That AI-generated analysis is an audit opinion.
  1. Scope, clauses and Annex A
  2. Assessment workflow
  3. Conformity, assurance and SoA
  4. Evidence, audit and findings
  5. AI Assist and security
  6. Reporting and certification readiness
  7. Reference and glossary