ISO 42001 and responsible AI

AI adoption usually moves faster than the governance around it. This cluster covers inventorying AI use, assessing impact, naming owners, keeping humans in the loop and evidencing oversight — inside the same management system as your other standards.

Start here

The product view lives on AI governance software and AI-assisted governance.

The standard

Regulation and frameworks

Operating AI safely day to day

Deciding how to run it

The other resource clusters

Answers buyers, procurement and auditors want

Do we need ISO 42001 if we only use third-party AI tools?+

Using someone else's model still creates obligations: knowing where AI is used, what data reaches it, who approved it, and what happens when the output is wrong. ISO/IEC 42001 gives that a structure whether or not you certify.

How does ISO 42001 relate to the EU AI Act?+

The Act is law with obligations by risk classification; ISO/IEC 42001 is a management system standard. Operating the standard produces much of the governance, documentation and oversight evidence the Act expects, but conformity with a standard is not the same as legal compliance.

Can AI governance reuse our ISO 27001 work?+

Substantially. Supplier assessment, access control, change management, logging, training and incident response already exist. AI adds inventory, purpose, impact assessment, human oversight and performance review on top.

See how your existing risks, controls and evidence could become one integrated management system

Bring what you already have — a part-finished risk register, a folder of policies, last year's audit findings — and see it mapped across the standards you need.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.