Add-on service
ISO 42001 gap assessment
ISO/IEC 42001 is the international standard for an AI management system, and it is increasingly what enterprise buyers and public sector tenders ask about. This assessment tells you honestly how far away you are, what the gap costs to close, and whether certification is worth pursuing at all for a business your size.
Best for: Businesses being asked about ISO 42001 in tenders or client security reviews, or planning certification in the next 12–18 months.
What's included
- Clause-by-clause review against ISO/IEC 42001 Annex A controls
- Mapping of your existing Trestano register, policy and risk assessments to specific clauses
- RAG-rated gap register with the effort and owner for each item
- A prioritised roadmap split into quick wins, medium work and genuine projects
- An assessment of whether certification, or alignment without certification, fits your business case
- Evidence pack index showing what an auditor would expect to see
- Debrief call with your leadership team
Why ISO 42001 is showing up in your sales process
Large buyers have started asking suppliers how AI use is governed, and ISO 42001 gives them a standard to point at. For an SME, answering "we are working towards alignment, here is our gap assessment and roadmap" is usually enough to clear a procurement gate — a full certification is not always necessary, and knowing which one you need is worth more than starting either blind.
How the assessment runs
We work from what already exists rather than starting a document project. Your register, AI usage policy, risk assessments and any existing ISO 27001 or Cyber Essentials work all count towards the standard, and a surprising proportion of the clauses are already partly met.
- Week 1 — document review and evidence request
- Week 2 — interviews with the people who own AI decisions
- Week 3 — gap register, roadmap and costed options
- Debrief — a call with leadership to agree the route forward
What the gap register looks like
Every clause gets a status, an owner, an effort estimate and a plain-English description of what closing it involves. There is no consultant jargon and no padding — where a clause is genuinely disproportionate for a business of your size we say so and record the justification, which is itself a defensible position.
Overlap with UK GDPR and the EU AI Act
ISO 42001 is a management system standard, not a legal requirement, but the evidence it demands overlaps heavily with what UK GDPR accountability and EU AI Act risk management already ask for. The assessment shows that overlap explicitly, so a single piece of work serves all three rather than three parallel efforts.
Common questions
Do you certify us?
No. Certification must come from an accredited certification body, and we are deliberately independent of that. We prepare you and tell you honestly when you are ready.
Is £950 the whole cost?
It covers the assessment for a typical single-site SME. Multi-entity or regulated businesses are quoted individually, always with a fixed fee agreed before we start.
We already have ISO 27001 — does that help?
Considerably. The management-system clauses are structurally similar, and much of your existing evidence carries across. The assessment identifies exactly what does and what does not.
Not sure which you need?
Run the free AI register first — it takes about ten minutes and usually makes the answer obvious. Or tell us what you're dealing with and we'll point you at the right thing.
Not legal advice. Trestano provides governance tooling, documentation and practical guidance. It isn't a substitute for advice from a qualified solicitor or your own compliance team.
