Certification · International

ISO 42001, without the spreadsheets.

Govern the AI systems you build and use, and get certified for it.

What is ISO 42001?

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. It follows the same structure as ISO 27001 and asks organisations to manage AI risks and impacts, set policies for responsible AI and control the AI system life cycle.

Who needs it

  • Companies building AI features into their products
  • Teams preparing for the EU AI Act who want a recognised governance framework
  • Vendors whose customers ask how their AI is governed

What ISO 42001 looks at

AI policy and roles

A policy for responsible AI and clear accountability for AI systems.

AI risk and impact assessment

Assessing risks to the organisation and impacts on individuals and society.

AI system life cycle

Controls from design and data through verification, deployment and monitoring.

Third parties and data

Governing data quality and the suppliers of AI models and components.

How Beviso gets you there

  • AI management controls alongside ISO 27001, with shared management-system evidence
  • Risk register for AI-specific risks and impact assessments
  • Vendor register for model and AI service providers

6 ISO 42001 controls, ready on day one

These controls are loaded when you enable ISO 42001, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

A.6.1

AI System Impact Assessment

The organization shall conduct an AI impact assessment prior to deploying AI systems.

Evidence from

  • Jira
  • Notion
  • GitHub

A.6.2

AI Risk Assessment

Risks related to AI systems shall be identified, analysed, and evaluated.

Evidence from

  • Snyk
  • SonarCloud
  • Wiz

A.7.1

AI Data Governance

The organization shall manage data used in AI systems to ensure quality, integrity, and appropriateness.

Evidence from

  • Segment
  • Notion
  • Airtable

A.8.1

AI System Logging and Monitoring

The organization shall implement logging and monitoring for AI system operations.

Evidence from

  • Datadog
  • Splunk
  • Grafana
  • New Relic

A.9.1

Responsible AI Use Policy

Policies for responsible and ethical use of AI systems shall be defined and communicated.

Evidence from

  • Notion
  • Ironclad

A.10.1

AI Third-Party Governance

Third-party AI services and components shall be assessed and governed.

Evidence from

  • Ironclad
  • DocuSign
  • Segment

ISO 42001 questions

Do we need ISO 27001 before ISO 42001?
No, but they share the same management system structure. Running both in Beviso lets clauses like internal audit and management review count for both.

Start your ISO 42001 programme today.

Free while Beviso is in beta. No credit card required.

Get started free