| Control ID | Control Name | Required Evidence |
|---|---|---|
A.5.3 | AI System Impact Assessment | AI impact assessment documentation |
A.6.2.4 | AI System Testing & Validation | Organizational policy / process documentation |
A.6.2.6 | AI System Deployment Criteria | Organizational policy / process documentation |
A.7.2 | Data Quality for AI | Organizational policy / process documentation |
A.7.4 | Data Preparation | Organizational policy / process documentation |
A.8.4 | Reporting AI System Issues | Organizational policy / process documentation |
A.9.2 | AI System Use Procedures | Human-oversight and AI-use procedures |
A.9.3 | Human Oversight of AI | Human-oversight and AI-use procedures |
| Gap # | Control | Severity | Owner | Target Date | Status |
|---|---|---|---|---|---|
| 1 | A.7.3 | Medium | [ORG TO COMPLETE: Owner] | [ORG TO COMPLETE: Target date] | Open |
Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
Note: Code-level AI management controls only. ISO/IEC 42001 requires organizational policies, risk assessments, and process evidence that are beyond the scope of code scanning. This is a development aid for identifying code-level control gaps, not a certification tool — consult a qualified auditor for formal certification.