AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
ISO/IEC 42001:2023 · AI Management System

ISO 42001 certification runs on evidence. Generate it continuously.

ISO/IEC 42001 asks you to run an AI management system — policies, risk and impact assessment, lifecycle controls, monitoring and improvement. AccuroAI supplies the operational controls and the Annex A evidence auditors look for, without a spreadsheet in sight.
Dec 2023
Standard published — first certifiable AI management system
A.2 – A.10
Nine Annex A control objectives, 38 controls
§9 · §10
Monitoring, audit and continual improvement
ConsoleCompliance · ISO/IEC 42001Evidence live
Requirement · referenceEvidence
Inventory and classify every AI systemA.4.2 · A.6.2 · AI asset register with owner, purpose, risk tier and lifecycle stateGenerated
Enforce the AI policy in practiceA.2.2 · A.9.3 · Policy versions, decisions and exceptions, time-stampedGenerated
Control data going into AI systemsA.7.2 – A.7.6 · Redaction and block records by data class and systemGenerated
Human oversight and intended useA.9.2 · A.9.4 · Oversight events and acknowledgement logsGenerated
Govern third parties and componentsA.10.2 – A.10.4 · AI bill of materials per agent with verification statusGenerated
Monitor, measure and improve§9.1 · §9.2 · §10.2 · Audit-ready evidence pack regenerated continuously, 11× faster audit prepGenerated
6 requirements mapped · evidence refreshed continuously8 frameworks
Why it matters

A management system, not a checklist.

ISO/IEC 42001 follows the same harmonised structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement (clauses 4–10), plus an Annex A of controls selected through a Statement of Applicability. Certification bodies accredited under ISO/IEC 42006 test whether the system runs — whether AI systems are inventoried and classified, whether impact assessments exist, whether use is monitored and whether non-conformities are corrected. Every one of those is easier when the evidence is generated by the controls themselves rather than assembled before the audit.

What ISO/IEC 42001 asks for

The obligations that touch security and IT.

01A.2 · A.3

AI policy and internal organisation

A documented AI policy aligned to business objectives, with defined roles, responsibilities and reporting of concerns.

02A.4 · A.5

Resources and impact assessment

Know the data, tooling, systems and people behind each AI system; assess impacts on individuals, groups and society (§6.1.4, §8.4).

03A.6

AI system life cycle

Objectives, requirements, design, verification, deployment, operation and monitoring — documented and controlled for each system.

04A.7

Data for AI systems

Data acquisition, quality, provenance and preparation under control — including what employees feed into third-party models.

05A.8 · A.9

Information for interested parties & responsible use

Tell users and affected parties what the system does; define and enforce intended use, human oversight and acceptable-use objectives.

06A.10

Third-party and customer relationships

Allocate responsibilities across the supply chain — model providers, tool vendors, MCP servers, agent frameworks — and monitor them.

How AccuroAI maps

Each requirement, one control, one piece of evidence.

RequirementReferenceAccuroAI controlEvidence produced
Inventory and classify every AI systemA.4.2 · A.6.2Shadow AI discovery across browser, desktop, IDE and agents; risk scoring per system from the 1,400+ catalogAI asset register with owner, purpose, risk tier and lifecycle state
Enforce the AI policy in practiceA.2.2 · A.9.3Policy engine: allow, redact, warn or block per tool, data class, team and agent actionPolicy versions, decisions and exceptions, time-stamped
Control data going into AI systemsA.7.2 – A.7.6Inline inspection with 40+ classifiers and 60+ secret types before data leaves the device, at <38ms p99Redaction and block records by data class and system
Human oversight and intended useA.9.2 · A.9.4Approval gates and kill switch for agents; per-group acceptable-use rules; usage noticesOversight events and acknowledgement logs
Govern third parties and componentsA.10.2 – A.10.4AI supply-chain vetting: models, MCP servers, skills and packages checked for provenance and capability driftAI bill of materials per agent with verification status
Monitor, measure and improve§9.1 · §9.2 · §10.2Executive reporting with trend metrics; evidence mapped to 8 frameworks including ISO 27001 and SOC 2Audit-ready evidence pack regenerated continuously, 11× faster audit prep

General information about the public text of the framework, not legal advice. Mappings describe how AccuroAI controls support each obligation; scope and conformity decisions remain with your legal, compliance and certification partners.

Where it runs

The products behind the evidence.

Further reading
FAQ

What teams ask about ISO/IEC 42001.

Do we need ISO 27001 before ISO 42001?

No, but they share the harmonised structure and many organisations integrate the two. AccuroAI evidence maps to both — ISO 27001 Annex A data-protection controls and ISO 42001 Annex A AI controls draw on the same inventory, policy and logging records.

Which Annex A controls does AccuroAI cover?

Primarily A.4 (resources), A.6 (lifecycle, operationally), A.7 (data), A.9 (responsible use) and A.10 (third parties), plus the monitoring and measurement evidence for clause 9. Policy authorship (A.2), organisational roles (A.3) and impact assessment judgement (A.5) remain yours; we supply the data they rely on.

How does this help the Statement of Applicability?

Each mapped control produces a named artefact — asset register, policy decision log, redaction records, AI bill of materials — that you can cite against the Annex A control in the SoA and show live to the auditor.

Does ISO 42001 cover employee use of ChatGPT?

Yes. The standard applies to organisations that use AI systems, not only those that build them. Responsible-use objectives (A.9), data controls (A.7) and third-party controls (A.10) all apply to sanctioned and unsanctioned assistant use — which is why discovery comes first.

Is this legal or certification advice?

No. This page summarises the public structure of ISO/IEC 42001:2023 and describes how AccuroAI controls support it. Your certification body determines conformity.

See your ISO/IEC 42001 evidence, live.

Book a 30-minute demo and we'll show the inventory, the logs and the oversight controls behind every mapping on this page — on your own AI estate within 72 hours.

Book a demoTalk to security