RepoScope Compliance intelligence for your codebase

Gap & Remediation Plan — ISO/IEC 42001:2023

Company: Acme Corp
Generated: June 27, 2026
Audit Period: 2026-01-01 to 2026-12-31

Summary

Open Items

Gap 1: A.7.3 — Data Provenance

Controls Outside Scope

Control IDControl NameRequired Evidence
A.5.3AI System Impact AssessmentAI impact assessment documentation
A.6.2.4AI System Testing & ValidationOrganizational policy / process documentation
A.6.2.6AI System Deployment CriteriaOrganizational policy / process documentation
A.7.2Data Quality for AIOrganizational policy / process documentation
A.7.4Data PreparationOrganizational policy / process documentation
A.8.4Reporting AI System IssuesOrganizational policy / process documentation
A.9.2AI System Use ProceduresHuman-oversight and AI-use procedures
A.9.3Human Oversight of AIHuman-oversight and AI-use procedures

Tracking

Gap #ControlSeverityOwnerTarget DateStatus
1A.7.3Medium[ORG TO COMPLETE: Owner][ORG TO COMPLETE: Target date]Open

Previously Remediated (Game Plan archive)

Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.

Note: Code-level AI management controls only. ISO/IEC 42001 requires organizational policies, risk assessments, and process evidence that are beyond the scope of code scanning. This is a development aid for identifying code-level control gaps, not a certification tool — consult a qualified auditor for formal certification.