Skip to content
User guide · part 3

Close the gaps

65 controls, and no, you do not do them in an afternoon. This is the part that runs for months — so the guide is about how to work it sustainably rather than how to click the buttons.

What the catalogue holds

27 controls from clauses 4 to 10 — the management-system requirements: context, leadership, planning, support, operation, performance evaluation, improvement. Then 38 from Annex A, the AI-specific controls: policies, internal organisation, resources, impact assessment, life cycle, data, information for interested parties, use of AI systems, and third parties.

Titles are paraphrased for working use. The app deliberately does not reproduce the standard's text — that is licensed content, and reproducing it would put both you and us on the wrong side of the licence. Each control cites its clause number so you can read the standard alongside, which you will need to do anyway to be certified against it.

The four statuses, and what they mean

  • Not started. The default, and the honest state for most controls on day one. A control with no stored state reads as not started, so a fresh install shows 0% across the whole catalogue rather than an empty page.
  • In progress. Counts as half in the readiness figure. Use it when work is genuinely underway, not as a way of feeling better about not started.
  • Implemented. The thing exists, is being done, and you could show somebody. If you cannot attach evidence, it is probably in progress.
  • Not applicable. Excluded from the denominator, not scored as zero. This is how a Statement of Applicability works, and it is the status people are most reluctant to use — but a control that genuinely does not apply to you should say so, with a note explaining why.
Not applicable needs a justification

Put it in the notes. The generated Statement of Applicability prints your note in the justification column, verbatim, and "N/A" with nothing beside it is the first thing an auditor asks about.

The gap tracker with a filter set to all controls, showing status, evidence count, owner and updated date for ten controls.
Illustration The tracker, filtered to everything. The filter is the tool you will use most — 'not started' is the working list, and 'Annex A only' is the Statement of Applicability preview.

A workable order

  1. Do a first pass with no evidence

    Go through all 65 and set a status from what you already know. Do not attach anything, do not write long notes. Two hours with the right person in the room. You now have a real readiness figure instead of a blank one, and — more useful — a list of what is genuinely not started.

  2. Name owners for everything not implemented

    An unowned control does not move. This is a fifteen-minute pass and it is the single highest-leverage thing on the page.

  3. Attach evidence to what you claim is implemented

    Filter to implemented and work down it. Every one should have at least one evidence record. The ones that do not are the ones you will be embarrassed by, and finding them now is the whole point.

  4. Then work the gaps, in clause order

    Clauses 4 and 5 first — context, scope, policy, roles. They are quick, they are prerequisites for the rest, and they move the number visibly, which matters when you are asking people for time.

Recording evidence

Evidence is a record of what proves a control, not the thing itself. Give it a title somebody would recognise, a link to where it actually lives, an owner, and the date it was last confirmed still true — a new record starts on today’s date.

One evidence record can cover several controls, and it usually should. An AI policy covers Clause 5.2, Annex A.2.2 and A.2.4 at once — record it once and tick all three. The form groups the controls by clause and Annex A section: open Clause 5 — Leadership and Annex A.2 — Policies to find them, or use Select all when one record covers a whole section.

The review date is the field people ignore and later wish they had not. A policy approved two years ago and never revisited is not evidence of a working management system; it is evidence of one that stopped. The date is how you find those before an auditor does.

The evidence register listing six records with the controls each covers, the owner and the last reviewed date.
Illustration Six evidence records covering fifteen controls between them. The 'Covers' column is the fastest way to spot a control claiming to be implemented on nothing.
Control 6.1.2 open, showing status, notes, owner, attached evidence and three history entries.
Illustration Every change to a control is recorded — who, what, and when. Nobody can edit or delete that history, including a Jira administrator.
Why the history cannot be edited

Because an owner who can delete a line can erase the status change made the week before an audit. The trail is the artefact that makes the rest of it credible, so the app has no update and no delete for it — not for contributors, not for administrators, not for us.