AI Governance 13 min read

Most Common ISO 42001 Gaps and How Long Each Takes to Close

J

September 13, 2026

Five gaps account for most of what we write up in an ISO 42001 gap assessment: no inventory of the AI systems in use, an AI policy that nobody owns, no AI system impact assessment, no evidence that the human oversight the policy promises actually happens, and AI-generated records released without a qualified review. The first two usually close in two to four weeks. The middle two take two to three months, because the auditor wants to see them running and a procedure written last week has no run behind it. The last is the least common across the market and the most serious for anyone FDA regulates, since April 2026 turned it into a citable condition. The order below is the order we find them, most frequent first, and it happens that the quickest fixes come first as well.

The five gaps at a glance

Gap Where it sits in the standard How often we see it Typical time to close
No AI system inventory Clause 4.3 scope; Annex A resource documentation Nearly every first assessment 2 to 4 weeks
AI policy with no owner Clauses 5.2, 5.3 and 6.2 Most first assessments 1 to 3 weeks
No AI system impact assessment Clause 6.1.4; Annex A impact controls Most first assessments 4 to 8 weeks
No human-oversight evidence Annex A responsible-use and life-cycle controls; clause 9.1 Common 6 to 12 weeks
AI-generated records with no review Clause 7.5; 21 CFR 211.22(c) for FDA-regulated firms Common in regulated manufacturers 2 to 6 weeks for the procedure, longer for remediation

ISO/IEC 42001:2023 is an Annex SL standard, so clauses 4 to 10 mirror ISO 9001 and ISO 27001. An organisation that already runs one of those usually has document control, internal audit and management review working, and those parts of the assessment come back clean. The five gaps above are the AI-specific content that has never been plugged in.

Gap 1. Nobody can list the AI systems in use

We ask for the list of AI systems inside the proposed scope and get a partial answer. IT names the chatbot licence, quality names the document tool, and nobody mentions the résumé screener inside the HR platform, the forecasting feature the ERP vendor switched on last year, or the browser extension three engineers installed. The standard never uses the word inventory in a heading, and in my experience that is part of why the list is missing. Clause 4.3 requires you to define the scope of the management system, Annex A expects you to document the resources behind each AI system (data, tooling, people, computing), and clause 6.1 asks you to assess the risks and impacts of each one. None of that can be done for a system you do not know you have.

A Stage 1 auditor reads the scope statement and then walks the floor. If she finds an AI-assisted decision the scope does not mention, the question becomes whether your scope is wrong or your inventory is, and either answer is a finding. In our experience an undefined scope is the single thing most likely to stop a Stage 1 from proceeding to Stage 2.

To close it, build one table. Each row is one AI system, with the vendor or model, the business process it sits in, the decision it influences, whether it touches personal data, the named owner, and your organisation's role for that system (the standard treats developing, providing and using an AI system differently). Populate the rows from a software licence review, a walk through each department asking what they use that suggests, ranks, predicts, drafts or decides, and the vendor contracts, because a surprising amount of AI arrives as a feature inside a product you already bought. For a GMP manufacturer, the validated computerised systems list is the natural home.

Two to four weeks, most of it interviews. It is the fastest gap to close and the one everything else keys off, so do it first.

Gap 2. The AI policy exists and nobody owns it

There is almost always an AI policy. Sometimes it was downloaded, sometimes it is the information security policy with the word AI pasted in, and sometimes it is a thoughtful page the general counsel wrote. What it lacks is a named role accountable for it, roles for the people who operate the AI systems, and objectives that would let anyone tell whether it is being followed. Clause 5.2 requires top management to establish the AI policy, clause 5.3 requires roles and responsibilities to be assigned and communicated, and clause 6.2 requires AI objectives that can be measured. The gap is usually all three at once, and it traces back to one missing decision about who is in charge.

The auditor's first interview question is some version of "who owns this?" When the answer is a pause and a glance around the table, everything downstream looks unowned as well, and auditors read ownership as the signal of whether the system is real.

This closes fast because it is a decision rather than a build. Name the role that owns the management system; in a company that already holds ISO 9001 or 27001 it is usually the same management representative, and what 42001 adds to a 9001 system is content rather than a second bureaucracy. Put a roles table beside the policy: who approves a new AI system, who runs the impact assessment, who reviews AI outputs before use, who reports at management review. Then write two or three objectives the owner can measure, such as every in-scope system carrying a current impact assessment, or every AI-drafted controlled document carrying a reviewer signature before release. "Use AI responsibly" is a sentiment, and the auditor will ask what number would tell you it is being met.

One to three weeks. Two meetings and one signature.

Gap 3. No AI system impact assessment

We find three versions of this gap: nothing at all, a data protection impact assessment relabelled (which covers privacy and nothing else), or an assessment done once at go-live for a system that has been retrained twice since. Clause 6.1.4 requires an AI system impact assessment process, and Annex A carries controls on documenting each assessment and on looking at the impact to individuals, to groups and to society. It is a separate exercise from the AI risk assessment in clause 6.1.2, which looks at risk to the organisation. The impact assessment looks outward, at the people the system affects.

This is the control an auditor spends the most time on, because it has no equivalent in 9001 or 27001. An organisation using AI to screen candidates, price customers or flag employees for review, with no documented look at who could be harmed and how, is in our experience carrying a major nonconformity into Stage 2.

Write a short procedure with four parts: what triggers an assessment (a new system, a new use of an existing one, a material model update, a complaint or incident), what it covers (who is affected, what harms are plausible, how severe and reversible they are, what mitigations exist), how often it is reviewed, and what happens when the residual impact is unacceptable. Then run it on every system in the inventory, starting with the ones that affect people outside the company. The procedure takes a week; running it takes longer, because it needs the system owners in the room and the auditor will want to read completed assessments rather than the template. The Statement of Applicability falls out of this step almost for free.

Four to eight weeks for an organisation with a handful of in-scope systems, longer with more.

Gap 4. The policy promises human oversight and nothing records it

Almost every AI policy says a human reviews the output before it is acted on, and very few organisations can produce the record. We ask who reviewed last Tuesday's batch of AI-ranked applications, what they checked and what they overrode, and the answer is that the reviewer looked at the screen. That may well be true, and it is still not evidence. Annex A expects you to define the processes for responsible use of AI systems, including where people stay in the decision, and clause 9.1 expects you to monitor whether the system performs as intended. A claim of oversight with no record fails both.

Stage 2 is an audit of operation. The auditor samples records over a period, and a control that produces no records cannot be sampled. This is also the gap that reappears at surveillance audits, because oversight is a habit, and habits lapse when nobody is checking the record.

For each in-scope system, decide the oversight point (before the output is used, after it, or on a sample), who performs it, what they are looking for, and where the decision is captured. The record can be light: a field in the ticket, a column in the log, a sign-off line on the report. What matters is that it exists and that someone reviews the override rate at management review, because an oversight step that never overrides anything is a step nobody is really performing. Then let it run. Most certification bodies expect the management system to have operated for roughly three months before Stage 2, so this gap sets the pace for your audit date more than any other.

Six to twelve weeks, most of it waiting for the record to accumulate.

Gap 5. AI-generated records released without qualified review

Procedures, specifications, test methods and deviation investigations get drafted by an AI tool and approved through the normal signature route, with nobody declaring that a machine wrote the first draft and nobody reading it any differently than a colleague's work. In most organisations this is a documentation weakness. In an FDA-regulated one it is now a citable condition. In April 2026 FDA issued a warning letter to Purolea citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c), the section that makes the quality unit responsible for approving specifications, procedures and master records, after AI-written quality documents were released without qualified review. It is the first time AI-generated records drew an FDA citation, and in my view it is the fact that makes ISO 42001 worth a GMP manufacturer's attention.

Clause 7.5 of 42001 requires documented information to be controlled, and Annex A expects you to know where AI is used and to keep people accountable for its outputs. An ISO auditor who learns that the SOP she is reading was AI-drafted will ask what review it received, and an FDA investigator will ask the same question with a warning letter to point at.

Add three things to your document control procedure: a declaration field for AI-assisted drafts (which tool, which version, what was asked of it), a review standard for those drafts that requires the reviewer to verify every regulatory reference, limit and method step against a primary source, and a rule that the quality unit's approval covers the content regardless of who or what drafted it. Then look backward. Pull the controlled documents issued in the last year, identify the AI-drafted ones (the authors know), and re-review the ones that carry limits, methods or regulatory claims. The procedure change takes two to six weeks. The backward review takes as long as the pile is tall.

We do this as a standalone AI-in-the-quality-system review for manufacturers who are not ready for a full 42001 project, because it is the piece an investigator will ask about first; the broader picture is on our page for GMP manufacturers.

Why the order matters

The five gaps depend on each other, and closing them out of sequence costs time. The inventory comes first because scope, risk assessment, impact assessment and oversight all hang from it. Ownership comes second because the owner runs the rest. Impact assessments come third, one per system, and they tell you where oversight matters most. Oversight records come fourth, started as early as possible, because the calendar is the limit rather than the effort. The records review runs alongside all of it for a regulated company, since it is an FDA question and does not wait for an ISO project.

Auditors differ, and the standard does not rank its own clauses, but in our experience the gaps that arrive at Stage 2 as major nonconformities are the first and third: a scope the auditor cannot verify, and a system that affects people with no documented impact assessment. Ownership and oversight gaps more often land as minors when a procedure exists and the record run is short, and a minor lets certification proceed against a corrective action plan. Organisations with a working ISO 27001 or ISO 9001 system are usually at the short end of the four-to-twelve-month range from gap assessment to certificate; our realistic timeline article walks through both ends.

What a gap assessment produces

A gap assessment is two or three days of structured work, and you should walk away with documents you can hand to whoever runs the project. Ours produces:

  1. A clause-by-clause findings report. Each requirement in clauses 4 to 10 and each Annex A control area, marked met, partly met or not met, with the evidence we looked at.
  2. A prioritised gap list with effort to close. The five gaps above, plus whatever your situation adds, each with a suggested owner and a rough week count.
  3. A draft scope statement and AI system inventory. We build the first version during the assessment, because the interviews that find the gaps are the interviews that find the systems.
  4. A first cut at the Statement of Applicability. Which Annex A controls apply, given your role for each system and what those systems can affect, with exclusions justified.
  5. A sequenced plan toward a Stage 1 date. The order above on a calendar, with the oversight records started early enough to exist by Stage 2, and a date to book the certification body, because several have reported auditor backlogs and some Stage 2 audits have waited six months or more. Booking late is a bigger schedule risk than most of the gaps.

Market pricing in 2026 runs roughly $1,500 to $2,500 for a two-day gap assessment of a small organisation using one or two AI tools, and $5,000 to $20,000 for a scoped readiness review of a larger one. Our ISO 42001 gap assessment is a fixed fee of $9,750 and produces the five deliverables above. Against a first-year total commonly quoted at $85,000 to $150,000 for a 50-to-200-person company, the assessment is a small fraction of the project, and its main value is that it stops you spending the rest in the wrong order.

A gap assessment is also where some organisations decide to wait. If the inventory shows two vendor tools and nothing that affects anyone outside the company, the honest advice may be to close the five gaps inside the quality system you already run and hold off on certification until a customer or a regulator asks for it. We say so when that is what we find. Certification is worth the money when someone is going to check, and the gap assessment is the cheapest way to learn whether that someone exists yet. If you want to know which of the five you are likely looking at, contact us and we will tell you before you spend anything.

Frequently Asked Questions

What is the most common gap in an ISO 42001 gap assessment?

A missing AI system inventory. Most organisations cannot list every AI tool in use, who owns each one and which decisions it touches, and the scope, risk assessment and impact assessment all depend on that list.

How long does it take to close ISO 42001 gaps before an audit?

The inventory and policy-ownership gaps usually close in two to four weeks. Impact assessments and human-oversight records take longer because the auditor wants evidence of operation, often two to three months. Gap assessment to certificate typically runs four to twelve months.

Does ISO 42001 cover AI-generated quality records?

Yes, through its documented-information and responsible-use requirements. In April 2026 FDA cited a manufacturer for releasing AI-written specifications and procedures without qualified review, so a gap assessment for a regulated company checks that AI-drafted records get the same review as human-written ones.

What does an ISO 42001 gap assessment produce?

A clause-by-clause findings report, a prioritised gap list with the effort to close each item, a draft scope statement and AI system inventory, and a plan sequenced toward a Stage 1 audit date.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.