Pro · the guided path

The 15-Day Sprint

Not a folder of templates — a guided path. Fifteen focused days, each producing one real artefact, in the order an auditor expects. By the end you hold an audit-ready ISO 42001 document set and a defensible EU AI Act posture.

Honest scope. "15 days" is a pace, not a certificate. It gets you an audit-ready document set (Stage 1 preparation). The ISO 42001 certificate is issued only by an accredited body after an independent audit. Go faster or slower — the path is the same.
Phase 1 · Days 1–3

Scope & baseline — know where you stand

Day 1

Orient & classify

Map your AI systems, risk tiers and your provider/deployer role. See the whole terrain.

→ Output: AI system inventory + risk classification record
ISO A.2AI Act Art. 6 / 50
Day 2

Strict gap assessment

Score yourself against the evidence-only readiness rubric. Your baseline and your blocking gaps.

→ Output: readiness score + gap list
ISO all
Day 3

AIMS scope & context

Define the boundary of your management system and the interested parties.

→ Output: AIMS scope & context statement
ISO Clause 4
Phase 2 · Days 4–9

Core documents — the artefacts an auditor opens first

Day 4

AI policy

The top-management-approved policy that anchors everything.

→ Output: signed AI policy
ISO A.2 / C5
Day 5

Roles & RACI

One accountable owner per activity — for ISO and for AI Act deployer duties.

→ Output: RACI matrix
ISO A.3 / C5.3Art. 26
Day 6

Risk register

Score each AI risk (likelihood × impact), inherent vs residual, with treatment.

→ Output: scored risk register
ISO C6.1 / A.5Art. 9
Day 7

Impact assessment

Impacts on people and society; fundamental-rights impact where it applies.

→ Output: AI impact assessment
ISO A.5.2–5Art. 27
Day 8

Data governance

Quality, provenance and bias controls for your data.

→ Output: data governance procedure
ISO A.7Art. 10
Day 9

Statement of Applicability

All 38 Annex A controls, applicability and justification — the auditor's index.

→ Output: SoA
ISO Annex A
Phase 3 · Days 10–12

Operate & oversee — make it run, not just exist

Day 10

Lifecycle & development

How AI systems are built, changed and retired under control.

→ Output: lifecycle procedure
ISO A.6Art. 12
Day 11

Transparency

Chatbot disclosure, synthetic-content marking, deepfake labelling — the 2 Dec 2026 deadline.

→ Output: transparency procedure + user notices
ISO A.8Art. 50 · due 2 Dec 2026
Day 12

Human oversight & incidents

Oversight measures with real authority, plus an incident procedure.

→ Output: oversight + incident procedures
ISO A.9 / A.8Art. 14
Phase 4 · Days 13–15

Audit preparation — get ready to be checked

Day 13

Suppliers & objectives

Contractual AI obligations with vendors; measurable AI objectives.

→ Output: supplier clauses + objectives
ISO A.10 / C6.2Art. 25/28
Day 14

Internal audit & review

Run one internal audit and a management review — auditors check you check yourself.

→ Output: internal audit report + review minutes
ISO Clause 9
Day 15

Evidence pack

Assemble everything into one defensible evidence set. Re-score: you should be audit-ready.

→ Output: audit-ready evidence pack
ISO allAI Act posture