ISO 42001, without the spreadsheets.
Govern the AI systems you build and use, and get certified for it.
What is ISO 42001?
ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence. It follows the same structure as ISO 27001 and asks organisations to manage AI risks and impacts, set policies for responsible AI and control the AI system life cycle.
Who needs it
- Companies building AI features into their products
- Teams preparing for the EU AI Act who want a recognised governance framework
- Vendors whose customers ask how their AI is governed
What ISO 42001 looks at
AI policy and roles
A policy for responsible AI and clear accountability for AI systems.
AI risk and impact assessment
Assessing risks to the organisation and impacts on individuals and society.
AI system life cycle
Controls from design and data through verification, deployment and monitoring.
Third parties and data
Governing data quality and the suppliers of AI models and components.
How Beviso gets you there
- AI management controls alongside ISO 27001, with shared management-system evidence
- Risk register for AI-specific risks and impact assessments
- Vendor register for model and AI service providers
6 ISO 42001 controls, ready on day one
These controls are loaded when you enable ISO 42001, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
A.6.1
AI System Impact Assessment
The organization shall conduct an AI impact assessment prior to deploying AI systems.
Evidence from
- Jira
- Notion
- GitHub
A.6.2
AI Risk Assessment
Risks related to AI systems shall be identified, analysed, and evaluated.
Evidence from
- Snyk
- SonarCloud
- Wiz
A.7.1
AI Data Governance
The organization shall manage data used in AI systems to ensure quality, integrity, and appropriateness.
Evidence from
- Segment
- Notion
- Airtable
A.8.1
AI System Logging and Monitoring
The organization shall implement logging and monitoring for AI system operations.
Evidence from
- Datadog
- Splunk
- Grafana
- New Relic
A.9.1
Responsible AI Use Policy
Policies for responsible and ethical use of AI systems shall be defined and communicated.
Evidence from
- Notion
- Ironclad
A.10.1
AI Third-Party Governance
Third-party AI services and components shall be assessed and governed.
Evidence from
- Ironclad
- DocuSign
- Segment
ISO 42001 questions
- Do we need ISO 27001 before ISO 42001?
- No, but they share the same management system structure. Running both in Beviso lets clauses like internal audit and management review count for both.
Often run alongside ISO 42001
Start your ISO 42001 programme today.
Free while Beviso is in beta. No credit card required.
Get started free