Other frameworks
ISO 42001: AI management systems
ISO/IEC 42001 is the first international management-system standard written specifically for AI: a framework for governing AI responsibly across its lifecycle, the same certifiable shape as ISO 27001 but built around AI-specific risks. EuroCompliant covers the full standard: the Clause 4-10 management-system requirements and all 38 real Annex A controls.
Transcript
ISO 42001 is the AI-specific counterpart to ISO 27001: a certifiable management system built around AI governance. It turns abstract AI risk into documented, auditable practice.
Open Settings and find the Compliance Frameworks screen. This is where every regulation you work under is switched on and off, and where the obligations engine decides what lands on your list.
Toggle ISO 42001 on. Enabling it adds all 51 of its obligations to your list at once: the policy, risk assessment, AI system lifecycle, and continual improvement requirements.
Head to My Obligations to see the new items. Each carries its own action guidance, not just a clause title. A subset, like impact assessments and documented system changes, can be marked in progress and completed as you work them.
Not everything starts complete. These are the items that need real work: policies to publish, risk criteria to set, and management reviews to schedule. The status column shows exactly where each one sits.
What already works well: your registered AI systems carry the purpose, data, and deployment details ISO 42001 asks about, so the inventory feeds straight into the management system instead of being re-entered.
From System Inventory, open a system's checklist to see ISO 42001 obligations mapped against it, alongside the AI Act and GDPR. One system, every framework it must satisfy.
Why this is required
Clause 5.2 requires an AI management policy setting out your organisation's commitments. Clause 6.1.2 requires an AI-specific risk assessment. Clause 6.2 requires control objectives. Clause 7.2 requires demonstrating the competence of people involved in AI development and use, and Clause 9.2 requires internal audits of the management system itself. Annex A adds 38 further controls across nine themes, from AI policy and roles (A.2-A.3) through impact assessment (A.5), the AI system lifecycle (A.6), data (A.7), and supplier/customer relationships (A.10).
Where ISO 42001 earns its keep alongside the EU AI Act is scope: the Act only regulates AI systems above a risk threshold, while an ISO 42001 ISMS-equivalent covers your organisation's AI governance as a whole, minimal-risk systems included. Several of the platform's Annex A entries also cite the specific EU AI Act article each control maps to, drawn from a published crosswalk.
What EuroCompliant does
Enabling ISO 42001 adds all 51 obligations (13 clauses plus 38 Annex A controls) to your Obligations page, each with its own action guidance rather than a bare clause title. A subset, roles and responsibilities (A.3.2), impact assessment (A.5.2-A.5.4, backed by your risk assessments and Fundamental Rights Impact Assessments), system monitoring (A.6.2.6), technical documentation (A.6.2.7), event logging (A.6.2.8), incident communication (A.8.4), user documentation (A.8.2), and supplier risk (A.10.3), are automatically evidenced from your platform data; the rest are honest manual checklist items with a specific action to complete, not a vague restatement of the clause.
ISO/IEC 42001 itself is a paywalled standard with no free official text. The Clause 4-10 requirements and Annex A control summaries in the platform are written from secondary sources (cross-checked across multiple independent implementer guides), not the purchased standard. Treat the platform's descriptions as a reliable paraphrase, not verbatim ISO wording, if you need to quote the standard precisely.
Four document types exist in the platform's document engine for this framework: an AI Management Policy, an AI Risk Assessment built from your system inventory, a Control Objectives register, and a Statement of Applicability against the full Annex A control set.
Walking through it
Enable ISO 42001
Adds the framework's Clause 4-10 obligations to your Obligations page.
Open /settings/profile?tab=frameworks →Make sure your AI systems are registered first
The risk-assessment and policy documents this framework produces are only as complete as your system inventory.
Open /systems →Work through the Clause and Annex A items
Competence (7.2), internal audit (9.2), and the Annex A items are each specific, actionable checklist entries: record who's been trained, when your last review happened, and complete each Annex A control in turn.
Open /obligations →The law
AI policy
Top management must establish an AI policy setting out the organisation's commitments.
AI risk assessment
A documented process for assessing risks specific to AI systems across their lifecycle.
Competence
The organisation must determine and demonstrate the competence of persons doing work affecting AI system performance.
Internal audit
Internal audits at planned intervals to check the AI management system conforms to the standard.
Assessing AI system impact on individuals
Assess and document how the AI system affects individual users or groups of individuals, backed by a Fundamental Rights Impact Assessment where one exists.
Frequently asked
Is ISO 42001 a replacement for EU AI Act compliance?
No, and they're not mutually exclusive either. The AI Act is binding law with statutory penalties; ISO 42001 is a voluntary, certifiable management standard. Many organisations pursue both, since ISO 42001 certification is increasingly used as evidence of AI Act Article 9 risk-management maturity.
Does the platform cover Annex A, or just the Clause 4-10 management-system requirements?
Both. All 38 real Annex A controls are in the platform, each with its own action guidance, alongside the 13 Clause 4-10 requirements.
Related guides
ISO 27001: information security management
The international standard for an information security management system, and how EuroCompliant tracks your Annex A controls.
Risk classification
The Article 6 assessment that decides which obligations a system carries, and why the reasoning matters as much as the result.
AI literacy
Article 4 applies to nearly everyone deploying AI, it has been in force since February 2025, and it is the obligation most organisations discover last.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial