DIAGNOSE
Establish your ISO 42001 position before you commit to a programme.
A fixed-scope diagnostic covering your AI estate, your governance gaps, and your EU AI Act exposure. For organisations facing investor diligence, enterprise procurement questions on AI, or an internal decision about whether ISO 42001 is warranted.
From £2,500 + VAT
THE ENGAGEMENT
A documented position, before any implementation decision.
Most organisations approach ISO 42001 without a documented AI inventory and without a view on which of their systems fall into which EU AI Act risk tier. Decisions then get made on impression rather than evidence, and scope is set either far too wide or far too narrow. The assessment establishes both positions before anyone commits budget to a programme.
The work is conducted by a senior practitioner across a short, structured engagement. We map where AI is used across the product and the operation, classify each in-scope system against the EU AI Act risk tiers, and test your current governance against the ISO 42001 Annex A controls. Findings are rated by severity, so the board can see what is material and what is housekeeping.
The output is a decision document, not a sales document. Where certification is not warranted, the report says so and sets out the lighter alternative. Where it is warranted, the fee credits in full against a subsequent ISO 42001 Sprint.
DELIVERABLES
What you receive.
AI system inventory across the organisation, documented and categorised
EU AI Act risk tier classification for each in-scope system
Gap analysis against ISO 42001 Annex A controls
Board-ready report with findings and severity ratings
Prioritised remediation roadmap with indicative effort
A recommendation on whether certification is warranted and on what timeline
FIT
Who this is for.
- You have AI in production or in active development, whether built in-house or bought in.
- AI governance has been raised by an investor, your board, or an enterprise buyer, and you need a documented answer.
- You are weighing ISO 42001 against lighter alternatives and want the comparison evidenced rather than argued.
This is not for organisations with no AI in the product or the operation. The inventory would come back empty and you would be paying for a document that says so.
WHAT COMES NEXT
Where organisations go from here.
Most organisations move from the assessment into implementation once the inventory and the risk classification are settled. The roadmap produced here becomes the scope document for the Sprint, and the assessment fee credits in full against it.
IMPLEMENTATION
ISO 42001 Sprint
ISO 42001 AI Management System implementation across the four AIMS lifecycle phases. Fixed scope, timeline agreed at scoping.
Explore the ISO 42001 SprintDIAGNOSE
ISO 27001 Readiness Assessment
Where the information security management system is the gate rather than AI governance, the equivalent diagnostic against ISO 27001:2022.
Explore the ISO 27001 assessmentASSURE
AI Trust Evidence Pack
Where an enterprise AI questionnaire has already arrived, ten completed governance artefacts built to answer it.
Explore the AI Trust Evidence PackQUESTIONS
Common questions.
Establish the position.
A 45 minute scoping call establishes the size of your AI estate, the right scope for the assessment, and the price. No sales pitch. If the assessment is not the right instrument for you, we will say so and tell you what is.
Prefer email? Write to info@goldlineconsultancy.co.uk.
