Skip to content

AI · Governance · Assess

ISO 42001 / EU AI Act Readiness

A gap assessment against ISO/IEC 42001 and the EU AI Act for your in-scope AI systems, with a risk register and remediation plan.

Quote-based · EU pricing on request

What you get

  • Gap assessment for up to 5 AI systems
  • EU AI Act risk categorisation
  • Risk register
  • Remediation plan and documentation templates

Scope

Included

  • Gap assessment against ISO/IEC 42001 controls and EU AI Act risk categories for up to 5 AI systems
  • Risk register
  • Remediation plan
  • Documentation templates

Not included

  • Certification audit
  • Acting as auditor
  • Legal advice
  • Remediation work

Always outside a fixed-scope package

  • Software licences, credits, add-ons, apps, connectors, and vendor support.
  • Custom code (Apex, LWC, Visualforce, HubSpot custom modules or apps, serverless functions, API services).
  • Data cleansing, deduplication, enrichment or transformation beyond the record counts and rules listed; data is loaded as the client provides it.
  • Integrations not named in the package, and any work inside third-party systems.
  • Content: copywriting, design, imagery, email or page templates beyond the numbers listed.
  • Training beyond the sessions listed, training for staff hired after go-live, and in-person training.
  • Legal, compliance or regulatory approval; we configure controls, the client's compliance team approves them.
  • Administration after the 30-day hypercare (sold as Support).
  • Additional UAT cycles caused by changes to approved requirements.
  • Work outside business hours (US Central or EET by client region), on-site work and travel.
  • Performance or load testing, penetration testing, and accessibility audits.
  • Licence negotiation, vendor contract changes, and vendor-side configuration we cannot access.

What you provide

  • A project owner with decision authority, available 2 to 4 hours a week.
  • Licences in place, admin access, and a sandbox or test environment by kickoff.
  • Subject-matter experts for each process in scope, available for workshops.
  • Source data exported in the agreed format by the date in the project plan.
  • Answers, design approvals and UAT sign-off within 3 business days of each request.
  • Their own users' availability for training sessions.
  • Compliance and legal review of any client-facing content, messaging or AI output.

Assumptions

AI engagement terms

  • AI output is probabilistic; we test against agreed cases and do not guarantee answers.
  • The client's compliance team approves controls, prompts and supervision rules before go-live.
  • Client data is not used to train models; enterprise or zero-retention data terms are configured where the vendor offers them.
  • Vendor model changes and retired features after go-live are handled under Support.
  • Usage costs are the client's and are estimated, not guaranteed.

Done means

Acceptance: Assessment, register and plan delivered.

Price and change control

  • This package is quoted after a short scoping call because the effort depends on your systems and data. The scope above is what the quote covers; you receive a written fixed price before work starts.
  • Anything not listed as included is a change. Changes are written up, priced and approved by you before we do them.
  • Software licences, subscriptions and third-party fees are bought by you from the vendor and are never included.
  • EU and UK clients: euro pricing on request; VAT is added where applicable.

Package VP-AI-ISO · scope last reviewed October 2, 2026 by the Vantage Point team. All AI packages → Print this scope