Frameworks

ISO/IEC 42001, alongside your ISMS.

If you already run ISO 27001, much of an AI management system will feel familiar. TruOps reuses what you have and shows what is new.

ISO/IEC 42001 · readinessevidence current
ISO/IEC 42001 · coverage by clause and control area
Clauses 4–10 · AIMSpartial · 62%
AI policysatisfied · 92%
AI system impact assessmentpartial · 58%
AI system lifecyclepartial · 74%
Data for AI systemsopen · 14%
Third-party relationshipssatisfied · 98%
The same work also counts toward
NIST AI RMF44% · partials shown
ISO 2700171% · partials shown
SOC 240% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

ISO/IEC 42001, published in December 2023, is the first international management-system standard for artificial intelligence. It specifies requirements for establishing, implementing, maintaining, and improving an AI management system (AIMS), follows the same high-level structure as ISO/IEC 27001, and includes an annex of reference controls. Organizations can be certified by accredited bodies.

This page is for you if
  • You want a certifiable AIMS and already have an ISMS
  • Buyers have started asking for 42001 or equivalent
  • AI impact assessments are Word docs outside the control system
Published by
ISO and IEC
Published
December 2023
Type
Certifiable management-system standard
Structure
Same harmonized structure as ISO 27001

What it requires

Like ISO 27001, ISO 42001 has management-system clauses (context, leadership, planning, support, operation, performance evaluation, improvement) and an annex of reference controls, here focused on AI policies, AI system impact assessment, the AI system lifecycle, data for AI systems, and third-party relationships.

The actual challenge

42001 looks like 27001 on purpose. The waste is standing up a second management system instead of reusing leadership, competence, audit, and supplier clauses you already evidence.

  • The annex controls for data, lifecycle, and third parties are new; the management-system clauses are not.
  • Each AI system needs to be in scope, not just "AI" as a theme.
  • Certification bodies will ask for the same dated evidence ISO 27001 already taught you to keep.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts ISO/IEC 42001 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

How TruOps helps with ISO/IEC 42001

Pick ISO/IEC 42001 as your anchor, or map it to the framework you already run. TruOps keeps ISO/IEC 42001's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your ISO/IEC 42001 assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

Because 42001 shares ISO 27001's structure, clauses such as leadership, competence, and internal audit can reuse evidence. TruOps marks each overlap as full or partial.

If this is your situation

Bring your ISO 27001 SoA. TruOps marks which 42001 clauses reuse that evidence and which are still open.

How TruOps helps

Anchor or map
Run ISO 42001 as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your ISO 42001 assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

Is ISO 42001 certifiable?

Yes. Organizations can be certified by accredited certification bodies.

Do I need ISO 27001 before ISO 42001?

No, but they share a structure, and organizations with an ISMS can reuse much of it.

How does ISO 42001 relate to the EU AI Act?

ISO 42001 is voluntary; the EU AI Act is law. A 42001 management system can support, but does not by itself demonstrate, AI Act compliance.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.