New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Other frameworks

ISO 42001: AI management systems

ISO/IEC 42001 is the first international management-system standard written specifically for AI: a framework for governing AI responsibly across its lifecycle, the same certifiable shape as ISO 27001 but built around AI-specific risks. EuroCompliant covers the full standard: the Clause 4-10 management-system requirements and all 38 real Annex A controls.

Transcript

ISO 42001 is the AI-specific counterpart to ISO 27001: a certifiable management system built around AI governance. It turns abstract AI risk into documented, auditable practice.

Open Settings and find the Compliance Frameworks screen. This is where every regulation you work under is switched on and off, and where the obligations engine decides what lands on your list.

Toggle ISO 42001 on. Enabling it adds all 51 of its obligations to your list at once: the policy, risk assessment, AI system lifecycle, and continual improvement requirements.

Head to My Obligations to see the new items. Each carries its own action guidance, not just a clause title. A subset, like impact assessments and documented system changes, can be marked in progress and completed as you work them.

Not everything starts complete. These are the items that need real work: policies to publish, risk criteria to set, and management reviews to schedule. The status column shows exactly where each one sits.

What already works well: your registered AI systems carry the purpose, data, and deployment details ISO 42001 asks about, so the inventory feeds straight into the management system instead of being re-entered.

From System Inventory, open a system's checklist to see ISO 42001 obligations mapped against it, alongside the AI Act and GDPR. One system, every framework it must satisfy.

Why this is required

Clause 5.2 requires an AI management policy setting out your organisation's commitments. Clause 6.1.2 requires an AI-specific risk assessment. Clause 6.2 requires control objectives. Clause 7.2 requires demonstrating the competence of people involved in AI development and use, and Clause 9.2 requires internal audits of the management system itself. Annex A adds 38 further controls across nine themes, from AI policy and roles (A.2-A.3) through impact assessment (A.5), the AI system lifecycle (A.6), data (A.7), and supplier/customer relationships (A.10).

Where ISO 42001 earns its keep alongside the EU AI Act is scope: the Act only regulates AI systems above a risk threshold, while an ISO 42001 ISMS-equivalent covers your organisation's AI governance as a whole, minimal-risk systems included. Several of the platform's Annex A entries also cite the specific EU AI Act article each control maps to, drawn from a published crosswalk.

What EuroCompliant does

Enabling ISO 42001 adds all 51 obligations (13 clauses plus 38 Annex A controls) to your Obligations page, each with its own action guidance rather than a bare clause title. A subset, roles and responsibilities (A.3.2), impact assessment (A.5.2-A.5.4, backed by your risk assessments and Fundamental Rights Impact Assessments), system monitoring (A.6.2.6), technical documentation (A.6.2.7), event logging (A.6.2.8), incident communication (A.8.4), user documentation (A.8.2), and supplier risk (A.10.3), are automatically evidenced from your platform data; the rest are honest manual checklist items with a specific action to complete, not a vague restatement of the clause.

ISO/IEC 42001 itself is a paywalled standard with no free official text. The Clause 4-10 requirements and Annex A control summaries in the platform are written from secondary sources (cross-checked across multiple independent implementer guides), not the purchased standard. Treat the platform's descriptions as a reliable paraphrase, not verbatim ISO wording, if you need to quote the standard precisely.

Four document types exist in the platform's document engine for this framework: an AI Management Policy, an AI Risk Assessment built from your system inventory, a Control Objectives register, and a Statement of Applicability against the full Annex A control set.

Walking through it

1

Enable ISO 42001

Adds the framework's Clause 4-10 obligations to your Obligations page.

Open /settings/profile?tab=frameworks →
2

Make sure your AI systems are registered first

The risk-assessment and policy documents this framework produces are only as complete as your system inventory.

Open /systems →
3

Work through the Clause and Annex A items

Competence (7.2), internal audit (9.2), and the Annex A items are each specific, actionable checklist entries: record who's been trained, when your last review happened, and complete each Annex A control in turn.

Open /obligations →

The law

Frequently asked

Is ISO 42001 a replacement for EU AI Act compliance?

No, and they're not mutually exclusive either. The AI Act is binding law with statutory penalties; ISO 42001 is a voluntary, certifiable management standard. Many organisations pursue both, since ISO 42001 certification is increasingly used as evidence of AI Act Article 9 risk-management maturity.

Does the platform cover Annex A, or just the Clause 4-10 management-system requirements?

Both. All 38 real Annex A controls are in the platform, each with its own action guidance, alongside the 13 Clause 4-10 requirements.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial