ISO/IEC 42001 follows the same harmonised structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement (clauses 4–10), plus an Annex A of controls selected through a Statement of Applicability. Certification bodies accredited under ISO/IEC 42006 test whether the system runs — whether AI systems are inventoried and classified, whether impact assessments exist, whether use is monitored and whether non-conformities are corrected. Every one of those is easier when the evidence is generated by the controls themselves rather than assembled before the audit.
A documented AI policy aligned to business objectives, with defined roles, responsibilities and reporting of concerns.
Know the data, tooling, systems and people behind each AI system; assess impacts on individuals, groups and society (§6.1.4, §8.4).
Objectives, requirements, design, verification, deployment, operation and monitoring — documented and controlled for each system.
Data acquisition, quality, provenance and preparation under control — including what employees feed into third-party models.
Tell users and affected parties what the system does; define and enforce intended use, human oversight and acceptable-use objectives.
Allocate responsibilities across the supply chain — model providers, tool vendors, MCP servers, agent frameworks — and monitor them.
General information about the public text of the framework, not legal advice. Mappings describe how AccuroAI controls support each obligation; scope and conformity decisions remain with your legal, compliance and certification partners.
No, but they share the harmonised structure and many organisations integrate the two. AccuroAI evidence maps to both — ISO 27001 Annex A data-protection controls and ISO 42001 Annex A AI controls draw on the same inventory, policy and logging records.
Primarily A.4 (resources), A.6 (lifecycle, operationally), A.7 (data), A.9 (responsible use) and A.10 (third parties), plus the monitoring and measurement evidence for clause 9. Policy authorship (A.2), organisational roles (A.3) and impact assessment judgement (A.5) remain yours; we supply the data they rely on.
Each mapped control produces a named artefact — asset register, policy decision log, redaction records, AI bill of materials — that you can cite against the Annex A control in the SoA and show live to the auditor.
Yes. The standard applies to organisations that use AI systems, not only those that build them. Responsible-use objectives (A.9), data controls (A.7) and third-party controls (A.10) all apply to sanctioned and unsanctioned assistant use — which is why discovery comes first.
No. This page summarises the public structure of ISO/IEC 42001:2023 and describes how AccuroAI controls support it. Your certification body determines conformity.