The AI Diagnostic reads your organisation on six pillars, built on ISO/IEC 42001 (the AI management system), the AI Act and the NIST AI RMF. Each requirement: is it written down, and is it applied?
1Strategy
What AI should serve
Your objectives, the uses that matter, who decides where AI goes.
ISO/IEC 42001: 4.1, 4.2, 6.2
2Governance
The framework and its owners
AI policy, roles, committee, management review.
ISO/IEC 42001: 5, 9, 10, A.2, A.3
3People
Teams in control
Skills, awareness, AI literacy for every person concerned (AI Act, Article 4).
ISO/IEC 42001: 7.2, 7.3 · AI Act Art. 4
4Process
Risks, impacts, suppliers
AI risk assessment, impact assessment, human validation, supplier clauses, transparency (AI Act, Article 50).
ISO/IEC 42001: 6.1, 8, A.5, A.10 · AI Act Art. 50
5Data
What you feed AI
Quality, provenance, preparation and rights on the data used.
ISO/IEC 42001: A.7
6Technology
The tools actually running
Inventory of AI systems, life cycle, documentation, incidents.
ISO/IEC 42001: A.4, A.6, A.8
Your role under the AI Act, deployer or provider, sets the obligations on top. Each pillar comes out with its level, the gap to target and the order of work.