What It Covers Deliverable Pricing Full Audit FAQ Book a Fit Call →
Governance entry point for AI-first teams

Know exactly where your AI governance stands against ISO/IEC 42001.

A fixed-fee $3,500 gap assessment of your AI Management System — with Annex A control mapping, a current-state read, and a prioritised remediation roadmap your leadership can action this quarter.

Book a 15-Min Fit Call → See the $3,500 Flat Fee

Fixed fee · delivered in 5 business days · fee credited toward a full audit

ISO/IEC 42001:2023 | EU AI Act & NIST AI RMF | Annex A control mapped
$3,500
Fixed fee, no retainer
5 days
Assessment delivery
100%
Of the $3,500 credited to a full audit
📜 ISO/IEC 42001:2023 AIMS
🇪🇺 EU AI Act (Reg 2024/1689)
🏛️ NIST AI RMF 1.0
🤖 NIST AI-Agent Red-Teaming Guidance (Mar 2026)

Two regulators just raised the bar for AI governance

The window to get ahead of mandatory AI governance is closing. A gap assessment turns "we should look at this" into a dated, board-ready plan.

🤖

NIST's AI-Agent Red-Teaming Guidance (Mar 2026)

In March 2026 NIST released guidance on red-teaming AI agents — signalling that autonomous, tool-using agents are now an explicit governance and assurance expectation, not an edge case.

  • Agent risk is now a documented control area
  • Procurement teams expect a testing posture
  • Investors ask for evidence, not assurances
🇪🇺

EU AI Act pressure is phasing in

The EU AI Act's high-risk obligations — including risk management, data governance, and human oversight for covered AI systems — phase in through August 2026. ISO/IEC 42001 is the recognised management-system standard for demonstrating conformity.

  • High-risk obligations arriving in 2026
  • ISO 42001 is the conformity playbook
  • Customers now request it in security reviews

Three outputs that move you from unknown to audit-ready

Every gap assessment delivers the same three artifacts. No vague maturity scores — specific clauses, specific gaps, specific fixes.

🗺️

Annex A Control Mapping

We map your current AI governance, policies, and technical controls against the ISO/IEC 42001:2023 Annex A control set — clause by clause — so you see precisely what exists and what is missing.

🔍

Current-State vs ISO 42001

A clear read on where your AI Management System (AIMS) already meets the standard and where the gaps sit — scoped to your actual models, agents, and data, not a generic checklist.

🛣️

Prioritised Remediation Roadmap

Each gap ranked by risk and effort, with the specific policies, processes, and technical controls needed to close it — sequenced so your team can start in the next sprint.

⚖️

Risk, Context & Leadership Review

Clauses 4–6 and 9 (context, leadership, planning, governance) reviewed so the management commitment an auditor expects is evidenced, not assumed.

Mapped to the governance frameworks your buyers already cite

Every gap assessment cross-references ISO/IEC 42001 Annex A controls to the EU AI Act and the NIST AI Risk Management Framework, so legal, security, and product share one source of truth.

ISO/IEC 42001:2023
AI Management System (AIMS) standard
Annex A
EU AI Act
Regulation (EU) 2024/1689
Mapped
NIST AI RMF
AI Risk Management Framework 1.0
Mapped
NIST AI-Agent Guidance
Red-teaming guidance, Mar 2026
Referenced

A report your security team and your board will both read

Every gap assessment ships with these artifacts. No slideware — every finding ties to a clause and a fix.

📊

Executive Summary

Board-ready language, an overall readiness verdict, and a one-page summary of gaps by severity and clause.

🗂️

Annex A Gap Matrix

Your current controls mapped to each Annex A control, marked met / partial / gap, with the clause cited.

🔎

Current-State Assessment

What already conforms to ISO 42001 today, and the evidence an auditor would accept for each.

🛠️

Remediation Roadmap

Gaps ranked by risk and effort, with the specific policies, processes, and controls to close each one.

⚖️

Risk & Context Findings

Clauses 4–6 and 9 gaps (context, leadership, planning, governance) laid out with owner-ready actions.

📞

60-Min Debrief Call

Walkthrough of the findings and the path to a certification-ready AIMS, live with your leadership team.

One fixed fee. No scoping calls to survive.

The governance entry point into GaleOps. The full fee is credited when you expand into a full audit.

How the gap assessment leads into the $5,000 full audit

The gap assessment is your governance baseline. The full AI Security Audit builds on it — adding adversarial technical testing and deeper compliance evidence — and your $3,500 is credited in full.

Capability Gap Assessment · $3,500 Full Audit · $5,000
Annex A control mapping Included Included
Current-state vs ISO 42001 Included Included
Prioritised remediation roadmap Included Included
Technical AI security testing Not included Prompt injection, jailbreaks, tool misuse
Red-team & proof-of-concept Not included Included
EU AI Act + NIST AI RMF mapping Governance scope Full technical + governance
Certification-ready evidence pack Not included Included
Fixed fee $3,500 (credited) $5,000
Discuss the Full $5,000 Audit →

Common questions

What is an ISO 42001 gap assessment?
An ISO 42001 gap assessment compares your current AI governance, policies, and technical controls against the ISO/IEC 42001:2023 standard. You receive an Annex A control-mapping matrix, a current-state vs ISO 42001 read, and a prioritised remediation roadmap that shows exactly what to fix before a certification audit.
How does the gap assessment differ from a full AI security audit?
The gap assessment is a governance baseline: it maps your AI Management System to ISO/IEC 42001 and to EU AI Act / NIST AI RMF expectations. The full AI Security Audit adds adversarial technical testing — prompt injection, jailbreaks, agent tool misuse, and data-exposure paths — on top of the governance work. The $3,500 gap assessment fee is credited toward the $5,000 full audit.
Do you provide ISO 42001 certification?
No. GaleOps is an independent advisory, not a certification body. We prepare your organisation with the evidence, controls, and remediation roadmap a certification auditor will expect — then you engage an accredited certification body for the formal audit.
How long does the gap assessment take?
The ISO 42001 Gap Assessment is delivered within 5 business days of receiving access to your current AI policies, model inventory, and governance documentation. A 60-minute leadership debrief is included.
Does this cover EU AI Act and NIST AI RMF?
Yes. The Annex A mapping is cross-referenced to EU AI Act obligations (Regulation EU 2024/1689) and the NIST AI Risk Management Framework, so your governance, legal, and security teams work from one document.

Know your AI governance gaps before an auditor or a regulator does.

Book a short fit call for the ISO 42001 Gap Assessment. We will confirm your scope, your model inventory, and whether the fixed-fee assessment is the right starting point.

Book a 15-Min Fit Call → $3,500 fixed fee · delivered within 5 business days · 100% credited toward a full audit