The 15-Day Sprint
Not a folder of templates — a guided path. Fifteen focused days, each producing one real artefact, in the order an auditor expects. By the end you hold an audit-ready ISO 42001 document set and a defensible EU AI Act posture.
Scope & baseline — know where you stand
Orient & classify
Map your AI systems, risk tiers and your provider/deployer role. See the whole terrain.
Strict gap assessment
Score yourself against the evidence-only readiness rubric. Your baseline and your blocking gaps.
AIMS scope & context
Define the boundary of your management system and the interested parties.
Core documents — the artefacts an auditor opens first
AI policy
The top-management-approved policy that anchors everything.
Roles & RACI
One accountable owner per activity — for ISO and for AI Act deployer duties.
Risk register
Score each AI risk (likelihood × impact), inherent vs residual, with treatment.
Impact assessment
Impacts on people and society; fundamental-rights impact where it applies.
Data governance
Quality, provenance and bias controls for your data.
Statement of Applicability
All 38 Annex A controls, applicability and justification — the auditor's index.
Operate & oversee — make it run, not just exist
Lifecycle & development
How AI systems are built, changed and retired under control.
Transparency
Chatbot disclosure, synthetic-content marking, deepfake labelling — the 2 Dec 2026 deadline.
Human oversight & incidents
Oversight measures with real authority, plus an incident procedure.
Audit preparation — get ready to be checked
Suppliers & objectives
Contractual AI obligations with vendors; measurable AI objectives.
Internal audit & review
Run one internal audit and a management review — auditors check you check yourself.
Evidence pack
Assemble everything into one defensible evidence set. Re-score: you should be audit-ready.
Track it all in your readiness cockpit · not sure yet? Run the free assessment →