AI Governance & ISO 42001 Readiness
Answer a short checklist and get an instant AI governance readiness score for ISO/IEC 42001 and the EU AI Act — with your gap list and what to fix first.
You maintain a current inventory of the AI systems, models and AI features in use across the business.
A named person or team is accountable for AI governance (the AIMS owner).
You have an adopted AI acceptable-use and governance policy that staff know about.
AI systems that affect people get a documented AI impact assessment.
AI-specific risks — bias, safety, misuse, hallucination — are assessed and treated.
Training and input data is governed for quality, provenance and bias.
There is meaningful human oversight of consequential AI decisions.
People are told when they are interacting with AI or seeing AI-generated output.
You protect against prompt injection and secrets or sensitive data leaking into models.
External models and AI vendors get due-diligence and contractual controls.
AI system activity is logged and retained (EU AI Act Article 12-style record-keeping).
You monitor deployed AI for drift, performance and incidents on an ongoing basis.
0/12 answered — answer all to see your AI governance score.
A directional self-assessment, not certification or legal advice. ISO/IEC 42001 certification and EU AI Act conformity require formal work and, where applicable, an independent body. Nothing you enter leaves your browser.
AI governance, explained
What is an AI governance readiness assessment?
An AI governance readiness assessment checks whether the controls around your AI use — inventory, ownership, impact assessments, risk management, human oversight, transparency, AI security, third-party model risk, logging and monitoring — meet the expectations of frameworks like ISO/IEC 42001 (the AI Management System standard) and the EU AI Act. This free tool scores you across those areas in a few minutes and lists the gaps to close first.
What is ISO 42001 and who needs it?
ISO/IEC 42001 is the international standard for an AI Management System (AIMS) — the governance layer around building or using AI responsibly. Any organisation deploying AI systems, especially ones that affect people or make consequential decisions, benefits from it; it is fast becoming the way to demonstrate responsible-AI governance to customers, regulators and partners, much as ISO 27001 did for information security.
How is AI governance different from SOC 2 or ISO 27001?
SOC 2 and ISO 27001 govern information security. AI governance adds the concerns unique to AI: data and model provenance, bias and fairness, human oversight, transparency to users, hallucination and misuse risk, and AI-specific security like prompt injection and secret leakage. ISO 42001 sits alongside your security frameworks rather than replacing them — and CATAAM runs all of them in one place.
What are the biggest AI governance gaps companies have?
The most common gaps are: no inventory of where AI is actually used (shadow AI), no named owner for AI governance, missing impact assessments for AI that affects people, and weak AI security — secrets and sensitive data flowing into third-party models with no controls. These tend to appear first because teams adopt AI faster than the governance around it.
Does CATAAM help with ISO 42001 and AI security?
Yes. CATAAM automates an ISO/IEC 42001 AIMS — discovering your real AI workloads, generating the AI impact assessments and Statement of Applicability, and validating each Annex A control continuously. Prompt Guard closes the AI-security gap by stopping secrets and sensitive data from leaking into models like ChatGPT and Claude in the first place.