BLOG / ISO/IEC 42001
ISO 42001 gap assessment checklist for Azure and Microsoft 365 teams
A gap assessment compares what you do today with what ISO/IEC 42001 expects from an AI management system (AIMS). This checklist follows the standard's structure (clauses 4 to 10) and adds examples of evidence that Microsoft 365 and Azure teams can usually gather.
It is a starting point for an internal conversation, not an audit. Certification is only granted by an accredited certification body, and every organization's scope is different. For help running the assessment, see my ISO 42001 consulting page.
1. Context and scope (clause 4)
- We have listed every AI system we build, buy or use, including Copilots and agents.
- We know which interested parties, such as customers, regulators and employees, have requirements for our AI.
- The AIMS scope is written down: business units, systems and locations.
- We know our role for each system: developer, provider or user.
2. Leadership and policy (clause 5)
- An approved AI policy exists and has been communicated.
- A named executive is accountable for the AIMS.
- Roles for AI risk, data, security and review are assigned.
- The policy covers acceptable use, including staff use of Copilot.
3. Planning, risk and impact (clause 6)
- A repeatable AI risk assessment method exists.
- Each in-scope system has a documented risk assessment and an impact assessment covering the people affected.
- Risk treatment decisions are recorded and owned.
- A statement of applicability records which Annex A controls apply and why.
- Measurable AI objectives are set.
4. Support (clause 7)
- People who build or approve AI have the competence they need, and training is recorded.
- Staff know the AI policy and how to raise concerns.
- Documented information is controlled: versioned, owned and easy to find.
- Tooling and resources for the AIMS are budgeted.
5. Operation (clause 8)
- Requirements, design, testing, deployment and retirement of AI systems follow a defined process.
- Data used by AI is assessed for quality, provenance and permissions.
- Third-party models and services are assessed, including Microsoft and other model providers.
- Human oversight is defined for each system, including when a person must approve an action.
- Changes such as new model versions, prompts and connectors go through change control.
- Incidents and user complaints about AI have a clear route.
6. Performance evaluation (clause 9)
- AI systems are monitored against agreed measures.
- Internal audits of the AIMS happen on a schedule.
- Management reviews the AIMS and records its decisions.
7. Improvement (clause 10)
- Nonconformities and incidents lead to recorded corrective actions.
- Lessons feed back into policy, risk assessment and controls.
Evidence you may already have
Teams on Microsoft platforms often hold more evidence than they realize:
- Microsoft Entra ID access reviews and Conditional Access policies for access to AI systems
- Microsoft Purview sensitivity labels, DLP policies and retention settings for data governance
- Microsoft Defender and Microsoft Sentinel alerts and incident records for monitoring and incident handling
- Microsoft Foundry evaluation results and traces for testing and monitoring
- Change records in Azure DevOps or GitHub for change control
How to score it
For each item, mark Yes, Partly or No and note the evidence. The Partly and No rows become your remediation plan, ordered by risk. Evidence that exists but is not documented or owned usually counts as Partly.
If you want a second pair of eyes, I offer an ISO 42001 gap assessment for teams on Azure and Microsoft 365. You can book a free session or read about my AI security work.
Related: Copilot Studio vs Microsoft Foundry: how to choose.