Lesson 5 of 11 · Frameworks · 3 min read

ISO 42001 software: what an AI management system tool should cover

In brief

ISO/IEC 42001:2023 is the international standard for an AI management system, and organizations can be certified against it. Software helps keep the records the standard asks for: scope, risk and impact assessments, controls, monitoring and improvement.

By The Charter Desk, Agentic Governance Compare · Published 2026-09-08 · Updated 2026-09-10 · Vendor pages read 8 September 2026 · Editorial assessment

What is ISO/IEC 42001?

ISO/IEC 42001, published in December 2023, specifies requirements for establishing, implementing, maintaining and continually improving an artificial intelligence management system (AIMS). Like ISO/IEC 27001 for information security, it is a management system standard: it asks how the organization governs AI, not whether one model is good. Accredited certification bodies can certify an organization against it.

How is the standard organized?

The requirements follow the common structure of ISO management system standards:

  • Clause 4, Context: the organization, interested parties and the scope of the AIMS.
  • Clause 5, Leadership: commitment, an AI policy and assigned roles.
  • Clause 6, Planning: AI risk assessment, risk treatment, AI system impact assessment and objectives.
  • Clause 7, Support: resources, competence, awareness, communication and documented information.
  • Clause 8, Operation: running the planned processes and assessments.
  • Clause 9, Performance evaluation: monitoring, internal audit and management review.
  • Clause 10, Improvement: nonconformities, corrective action and continual improvement.

Annex A lists reference control objectives and controls, Annex B gives implementation guidance for them, and organizations record which controls apply in a statement of applicability.

Where does software help?

An AIMS produces records: the scope, the risk register, impact assessments, the controls chosen, evidence that they operate, audit findings and corrective actions. Governance platforms help by keeping those records linked. Inventory-first tools help most with clauses 4 and 6 (scope, risk and impact). Enforcement-first tools help most with clauses 8 and 9 (operating controls and monitoring them).

Alice, Holistic AI, Pillar Security and Lasso name ISO 42001 on the pages we read, and Credo AI names ISO. Pillar says it generates audit-ready reports for ISO 42001; Lasso describes an audit trail for it; Alice maps WonderFence guardrails to it.

What should you ask a vendor?

  • Which Annex A controls does your product provide evidence for, and in what form?
  • Can I export the evidence for an internal audit and a certification audit?
  • How do impact assessments link to the systems in the register and to their controls?
  • How are nonconformities found by testing tracked to corrective action?

How does ISO/IEC 42001 relate to the EU AI Act?

They do different jobs. ISO/IEC 42001 is a voluntary management system standard that any organization can adopt and be certified against. The EU AI Act is law, with obligations that depend on each system's risk level and the organization's role. An AI management system can organize the records the Act asks for, such as risk management, logging and post-market monitoring, but certification against ISO/IEC 42001 is not the same as meeting the Act's obligations. Many programs run one control library for both, as lesson 7 describes.