A fixed-fee $3,500 gap assessment of your AI Management System — with Annex A control mapping, a current-state read, and a prioritised remediation roadmap your leadership can action this quarter.
Fixed fee · delivered in 5 business days · fee credited toward a full audit
The window to get ahead of mandatory AI governance is closing. A gap assessment turns "we should look at this" into a dated, board-ready plan.
In March 2026 NIST released guidance on red-teaming AI agents — signalling that autonomous, tool-using agents are now an explicit governance and assurance expectation, not an edge case.
The EU AI Act's high-risk obligations — including risk management, data governance, and human oversight for covered AI systems — phase in through August 2026. ISO/IEC 42001 is the recognised management-system standard for demonstrating conformity.
Every gap assessment delivers the same three artifacts. No vague maturity scores — specific clauses, specific gaps, specific fixes.
We map your current AI governance, policies, and technical controls against the ISO/IEC 42001:2023 Annex A control set — clause by clause — so you see precisely what exists and what is missing.
A clear read on where your AI Management System (AIMS) already meets the standard and where the gaps sit — scoped to your actual models, agents, and data, not a generic checklist.
Each gap ranked by risk and effort, with the specific policies, processes, and technical controls needed to close it — sequenced so your team can start in the next sprint.
Clauses 4–6 and 9 (context, leadership, planning, governance) reviewed so the management commitment an auditor expects is evidenced, not assumed.
Every gap assessment cross-references ISO/IEC 42001 Annex A controls to the EU AI Act and the NIST AI Risk Management Framework, so legal, security, and product share one source of truth.
Every gap assessment ships with these artifacts. No slideware — every finding ties to a clause and a fix.
Board-ready language, an overall readiness verdict, and a one-page summary of gaps by severity and clause.
Your current controls mapped to each Annex A control, marked met / partial / gap, with the clause cited.
What already conforms to ISO 42001 today, and the evidence an auditor would accept for each.
Gaps ranked by risk and effort, with the specific policies, processes, and controls to close each one.
Clauses 4–6 and 9 gaps (context, leadership, planning, governance) laid out with owner-ready actions.
Walkthrough of the findings and the path to a certification-ready AIMS, live with your leadership team.
The governance entry point into GaleOps. The full fee is credited when you expand into a full audit.
The gap assessment is your governance baseline. The full AI Security Audit builds on it — adding adversarial technical testing and deeper compliance evidence — and your $3,500 is credited in full.
| Capability | Gap Assessment · $3,500 | Full Audit · $5,000 |
|---|---|---|
| Annex A control mapping | Included | Included |
| Current-state vs ISO 42001 | Included | Included |
| Prioritised remediation roadmap | Included | Included |
| Technical AI security testing | Not included | Prompt injection, jailbreaks, tool misuse |
| Red-team & proof-of-concept | Not included | Included |
| EU AI Act + NIST AI RMF mapping | Governance scope | Full technical + governance |
| Certification-ready evidence pack | Not included | Included |
| Fixed fee | $3,500 (credited) | $5,000 |
Book a short fit call for the ISO 42001 Gap Assessment. We will confirm your scope, your model inventory, and whether the fixed-fee assessment is the right starting point.