Close the gaps
65 controls, and no, you do not do them in an afternoon. This is the part that runs for months — so the guide is about how to work it sustainably rather than how to click the buttons.
What the catalogue holds
27 controls from clauses 4 to 10 — the management-system requirements: context, leadership, planning, support, operation, performance evaluation, improvement. Then 38 from Annex A, the AI-specific controls: policies, internal organisation, resources, impact assessment, life cycle, data, information for interested parties, use of AI systems, and third parties.
Titles are paraphrased for working use. The app deliberately does not reproduce the standard's text — that is licensed content, and reproducing it would put both you and us on the wrong side of the licence. Each control cites its clause number so you can read the standard alongside, which you will need to do anyway to be certified against it.
The four statuses, and what they mean
- Not started. The default, and the honest state for most controls on day one. A control with no stored state reads as not started, so a fresh install shows 0% across the whole catalogue rather than an empty page.
- In progress. Counts as half in the readiness figure. Use it when work is genuinely underway, not as a way of feeling better about not started.
- Implemented. The thing exists, is being done, and you could show somebody. If you cannot attach evidence, it is probably in progress.
- Not applicable. Excluded from the denominator, not scored as zero. This is how a Statement of Applicability works, and it is the status people are most reluctant to use — but a control that genuinely does not apply to you should say so, with a note explaining why.
Put it in the notes. The generated Statement of Applicability prints your note in the justification column, verbatim, and "N/A" with nothing beside it is the first thing an auditor asks about.
A workable order
-
Do a first pass with no evidence
Go through all 65 and set a status from what you already know. Do not attach anything, do not write long notes. Two hours with the right person in the room. You now have a real readiness figure instead of a blank one, and — more useful — a list of what is genuinely not started.
-
Name owners for everything not implemented
An unowned control does not move. This is a fifteen-minute pass and it is the single highest-leverage thing on the page.
-
Attach evidence to what you claim is implemented
Filter to implemented and work down it. Every one should have at least one evidence record. The ones that do not are the ones you will be embarrassed by, and finding them now is the whole point.
-
Then work the gaps, in clause order
Clauses 4 and 5 first — context, scope, policy, roles. They are quick, they are prerequisites for the rest, and they move the number visibly, which matters when you are asking people for time.
Recording evidence
Evidence is a record of what proves a control, not the thing itself. Give it a title somebody would recognise, a link to where it actually lives, an owner, and the date it was last confirmed still true — a new record starts on today’s date.
One evidence record can cover several controls, and it usually should. An AI policy covers Clause 5.2, Annex A.2.2 and A.2.4 at once — record it once and tick all three. The form groups the controls by clause and Annex A section: open Clause 5 — Leadership and Annex A.2 — Policies to find them, or use Select all when one record covers a whole section.
The review date is the field people ignore and later wish they had not. A policy approved two years ago and never revisited is not evidence of a working management system; it is evidence of one that stopped. The date is how you find those before an auditor does.
Because an owner who can delete a line can erase the status change made the week before an audit. The trail is the artefact that makes the rest of it credible, so the app has no update and no delete for it — not for contributors, not for administrators, not for us.