Your governance committee needs to know where the AI governance risks are — not read a report to find out. The Gap Severity Matrix puts all nine gaps, their CQC mapping, severity ratings, and EU AI Act cross-references on a single, high-resolution reference sheet.
Designed for governance committee agendas, internal audit dashboards, and inspection preparation. Pin it. Project it. Print it. The complete ISO 42001 × CQC Well-Led picture in one place, in the format governance professionals actually use.
One-time purchase · No subscription · Instant download · Print-ready PDF + high-res PNG
The first three rows are shown in full below. Rows 4–9 are available on purchase. Each row contains the gap, its ISO 42001 clause, the CQC Well-Led KLoE mapping, severity rating, EU AI Act article reference, and ITIL 4 practice.
A single-page reference document engineered for governance use — not reading. Designed to be printed at A3, projected in a committee meeting, or used as a dashboard anchor for your AI governance review.
Every gap in the ISO 42001 Nine-Gap Audit framework is mapped. Including the three not covered in the free lead magnet — Internal Organisation (G2), AI System Register (G3), and AI Lifecycle Management (G5). The free guide shows you where your biggest risks are. The matrix shows you the complete picture.
Each gap is mapped to the CQC Well-Led (and where applicable, Safe, Effective, Responsive) Key Line of Enquiry it intersects. The exact CQC question wording is reproduced — not paraphrased — so you can show inspectors the direct linkage between your ISO governance evidence and the CQC criterion it satisfies.
Severity is calibrated to CQC inspection risk, not abstract compliance score. A Critical gap is one where absence of governance evidence is most likely to contribute to an "Inadequate" or "Requires Improvement" Well-Led rating. Use severity to prioritise your remediation roadmap and governance committee agenda.
The EU AI Act creates obligations that parallel ISO 42001 requirements. For healthcare providers using or procuring AI systems, these obligations may apply directly. Each gap includes the relevant EU AI Act article — so your governance committee can see where ISO 42001 compliance also closes EU AI Act exposure.
Each gap is mapped to its primary ITIL 4 practice — the service management framework that governs how the gap should be addressed operationally. This allows you to assign remediation ownership to the correct practice owner rather than treating AI governance as a standalone compliance exercise.
Delivered as a high-resolution PDF at A3 landscape — the format governance committees and quality teams use for reference documents. Print and laminate for your governance office. Project from a laptop in a committee meeting. Use as a standing agenda item backdrop. The design is engineered for these use cases, not general reading.
The matrix is a working document, not a reading document. It's for the people who need a complete picture of AI governance risk at a glance — and who need to produce that picture for others quickly.
Single-page high-res reference PDF. Instant download. One-time purchase.
Processed by ClickBank · Secure checkout · 60-day money-back guarantee · Instant download after purchase
The matrix is delivered as a high-resolution PDF file formatted at A3 landscape (420 × 297 mm / 16.5 × 11.7 inches). It is print-colour-adjusted to reproduce correctly on both colour and mono printers. A high-resolution PNG is also included in the download package for digital use — presentations, intranets, and screen projection.
The free guide covers five gaps (G1, G4, G6, G8, G9) in long-form — with inspection scenarios, clause analysis, and evidence checklists. It is designed for reading and self-assessment. The matrix covers all nine gaps in a single-page reference format — designed for governance committee use, internal audit scope documentation, and inspection preparation. They serve different purposes and different audiences. The matrix is the logical second step after the free guide: you know what the gaps are, now you need the complete picture in committee-ready format.
Severity ratings are calibrated against CQC inspection methodology and published Well-Led evidence requirements — specifically the CQC's Key Lines of Enquiry, the Well-Led Inspection Framework, and publicly available inspection reports. They reflect the CQC inspection risk — the likelihood that absence of governance evidence for a given gap will contribute to an "Inadequate" or "Requires Improvement" Well-Led rating. They are governance judgements, not statistical measures based on enforcement data.
EU AI Act references are current to Regulation (EU) 2024/1689 as enacted. The matrix includes article references and brief descriptions. For full EU AI Act compliance assessment, the matrix is a cross-reference tool, not a compliance programme. Healthcare providers with EU AI Act obligations should take qualified legal advice on the extraterritorial application of the regulation to their specific circumstances.
Yes. The purchase licence permits internal organisational use — printing, projection, sharing with governance committee members, quality teams, and clinical leads within the purchasing organisation. It does not permit resale, redistribution to third parties, or use as a deliverable in consulting engagements. Multi-organisation licences and consultant licences are available — contact support@unuslondon.com.
Nine gaps. Five KLoEs. Severity ratings. EU AI Act references. ITIL 4 practice ownership. One reference document. £19.
One-time · Instant download · A3 high-res PDF · 60-day guarantee