Frameworks

ISO/IEC 42001 — AI Management Systems

The world's first certifiable standard for AI governance. Compriska was built for it.

Book a demo

ISO/IEC 42001 does for artificial intelligence what ISO 27001 did for information security: it defines a certifiable management system. If your company builds AI, buys AI, or sells to enterprises that do, this standard is about to shape your next two years.

What ISO 42001 actually requires

At its core, ISO 42001 asks you to run AI deliberately. That means a documented AI management system (AIMS): an inventory of every AI system you operate, risk assessments for each one, defined roles and accountability, policies your people actually acknowledge, impact assessments for systems that affect individuals, and a cycle of monitoring and improvement. None of it is exotic — but almost nobody has it written down.

Who needs it, and when

Three groups are moving first: companies selling AI products to enterprise buyers (certification is becoming a procurement checkbox), regulated firms in finance and healthcare that need defensible AI oversight, and organizations preparing for the EU AI Act, which shares much of its DNA. If a security questionnaire has already asked you about AI governance — and lately they all do — you're in the market for this standard whether you planned to be or not.

The path to certification

The journey looks like ISO 27001's: gap assessment, scoping, building the AIMS (inventory, risk methodology, policies, controls from Annex A), operating it long enough to generate evidence, an internal audit, then a two-stage certification audit with an accredited body. Teams that already hold ISO 27001 typically move faster because the management-system muscle is already there.

How Compriska helps

Compriska's AI Governance module is a working AIMS out of the box: a living AI inventory, risk assessments aligned to the standard, model approval workflows, AI policy generation and acknowledgment tracking, and continuous monitoring — all mapped to ISO 42001's clauses in the Compliance module, so readiness is measured, not guessed.

Frequently asked questions

Is ISO 42001 certification mandatory?

No law requires it today, but enterprise procurement increasingly does. It also builds much of the operational muscle the EU AI Act expects, which is why many teams pursue both together.

How long does ISO 42001 certification take?

Most organizations need six to twelve months from gap assessment to certification, depending on how much AI they run and whether they already operate another ISO management system.

Do we need ISO 42001 if we only use third-party AI like OpenAI or Anthropic?

Using AI — not just building it — puts you in scope. Your AIMS covers how you select, assess, and monitor third-party AI, which is exactly what enterprise customers ask about.

Other frameworks

Automate ISO 42001 with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo