How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment
    Compliance Guide

    ISO 42001 Compliance Guide

    ISO/IEC 42001:2023 specifies requirements for an Artificial Intelligence Management System (AIMS). This guide maps those requirements to risk assessment, runtime controls, auditability, and conformity evidence for enterprise AI governance.

    ISO/IEC 42001:2023 specifies requirements for an Artificial Intelligence Management System (AIMS). Enterprises establish conformity by defining AIMS scope and inventory, assigning leadership and policy, running AI risk and impact assessments, operating life-cycle and third-party controls, measuring performance through audit and management review, and retaining evidence against applicable Annex A controls.

    What ISO/IEC 42001 requires

    ISO/IEC 42001 is a management system standard for artificial intelligence. It does not replace product-specific safety standards or sector regulation. Instead, it defines how an organization structures policy, roles, risk processes, operational controls, performance evaluation, and continual improvement around AI systems in scope.

    Conformity work typically spans context and interested parties, leadership commitment and AI policy, planning for risks and objectives, support (resources, competence, awareness, communication, documented information), operation across the AI life cycle, performance evaluation (monitoring, internal audit, management review), and improvement actions when nonconformities or control gaps appear.

    Annex A provides a reference set of controls. Organizations select and justify applicable controls, implement them, and retain evidence that they operate as intended. The AIMS stays auditable when inventory, assessments, decisions, exceptions, and monitoring outputs can be traced to the systems and clauses they support.

    AIMS building blocks under ISO/IEC 42001

    A practical AIMS groups work into four connected building blocks. Each block produces artifacts that later support internal audit and external conformity assessment.

    Context and scope

    Internal and external issues, interested parties, and a bounded AI system inventory.

    Leadership and policy

    Top management commitment, AI policy, roles, and authorities.

    Risk and impact

    AI risk assessment, system impact assessment, objectives, and treatment plans.

    Operation and evaluation

    Life-cycle controls, monitoring, internal audit, and continual improvement.

    Mapping ISO 42001 to AI agent governance and runtime control

    Agentic systems amplify several AIMS concerns: dynamic tool use, delegated authority, third-party models and APIs, and actions that change state outside a single model call. Mapping ISO 42001 effectively means treating agents as AI systems in inventory, with clear ownership, approved purposes, data boundaries, and residual-risk acceptance before autonomy or tool access expands.

    Operational clauses are easier to demonstrate when policy is executable at runtime. Permissions, approved tools, human oversight thresholds, and logging expectations should bind to the running agent, not only to static documents. Change history on prompts, tools, models, and deployment configuration should feed risk reassessment when material changes occur.

    Third parties (hosted models, plugins, data providers, and orchestration platforms) fall under the same seriousness as internal components: assessment, contractual controls, approval, and ongoing monitoring under the AIMS. Without that supply-chain link, Annex A control selection and operational planning leave a visible gap for auditors and for internal risk owners.

    Evidence artifacts auditors expect

    Auditors look for a coherent story from scope to control operation. Common evidence sets include the AIMS scope statement; an authoritative AI and agent inventory (with system cards or equivalent descriptions); AI policy and role definitions; risk and impact assessment records with treatment plans and residual-risk acceptance; records of life-cycle and change controls; third-party assessment and monitoring outputs; internal audit plans and findings; management review inputs and decisions; and samples of logs, exceptions, and corrective actions tied to systems in scope.

    For agent workloads, expect extra scrutiny on tool and permission matrices, human oversight records where required, segregation of duties across builders, deployers, approvers, and auditors, and proof that unlisted or shadow agents are detected and brought under inventory rather than left outside the control plane.

    Evaluation criteria for tools and processes supporting ISO 42001

    When selecting tools or defining processes that support the AIMS, evaluate them against operational and audit needs, not marketing labels alone:

    • Explicit mapping to ISO/IEC 42001 clauses and selected Annex A controls, with auditor-facing evidence artifacts the product or process produces
    • Maintained AI and agent inventory, system cards, and change history linked to risk and impact assessments
    • Demonstrable runtime policy enforcement, least-privilege permissions, human oversight workflows, and immutable logs for agent actions and tool use
    • Third-party model, tool, and data-provider assessment, approval, and continuous monitoring under the AIMS
    • Metrics, internal-audit support, and management-review inputs suitable for Clause 9 and continual improvement
    • Segregation of duties across builders, deployers, approvers, and auditors with workflow evidence

    Governance practices that keep the AIMS auditable

    The following practices help keep conformity sustainable as AI programs scale:

    • Keep inventory as the control plane: Treat the AI system inventory as authoritative for scope. Unlisted agents and tools are out-of-control assets for risk assessment and audit.
    • Assess before scale: Complete AI risk and impact assessments, treatment plans, and residual-risk acceptance before expanding agent autonomy or tool access.
    • Make policy executable: Bind approved uses, data boundaries, and tool permissions to runtime controls so operational clauses are enforced, not only documented.
    • Integrate the supply chain: Bring vendors, hosted models, APIs, and data providers under contracts, assessments, and monitoring with the same seriousness as internal systems.
    • Close the performance loop: Feed incidents, metrics, audit findings, and exception trends into scheduled management review and tracked improvement actions.
    • Separate conformity from legal compliance: Use ISO/IEC 42001 as the management backbone while mapping organization-specific legal and sector obligations separately; the standard alone does not guarantee legal compliance.

    Organizations that treat ISO/IEC 42001 as living management practice (inventory, risk, runtime control, evidence, and review) are better positioned for internal assurance and for external conformity assessment than those that only assemble static policy packs at audit time.

    Align runtime agent controls with your AIMS

    Trussed AI focuses on runtime governance, policy enforcement, agent permissions, and audit logging that can support operational control and evidence practices under an ISO/IEC 42001 management system.

    Request a Demo