Frameworks · Global standards
ISO 42001 compliance, run as a living system
ISO/IEC 42001 specifies requirements for an artificial intelligence management system, covering AI policy, risk and impact assessment, lifecycle controls and human oversight.
Who it applies to
Organisations building, deploying or procuring AI systems that must show governed, accountable use of the technology.
What it demands
AI governance
AI policy, roles, objectives and management review.
Impact assessment
Assessment of AI system impacts on individuals and society, with mitigation.
Lifecycle controls
Data governance, model documentation, testing, monitoring and human oversight.
How Compli-Once runs it
- 1
AI systems maintained as an inventory with owners, risk rating and linked controls.
- 2
Impact assessments run as structured assessments with evidence and review dates.
- 3
Model changes raise review tasks, so oversight is evidenced rather than assumed.
What you already satisfy
ISO 42001 overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
Who needs ISO 42001?
Organisations that build or deploy AI and are asked, by customers or regulators, to show it is governed.
Does it overlap with ISO 27001?
Substantially on governance and operational controls, and the crosswalk quantifies that coverage before you plan work.
