ISO 42001 AI management system readiness — inventory, assess, evidence, certify

Your customers have started asking what AI you run and how you govern it. ISO/IEC 42001 is the certifiable answer, and the EU AI Act is the deadline. This workspace stands up an AI management system in days: AI system inventory, AI risk register, all 39 Annex A controls, impact assessments and AI Act tiering — reusing the same register, control catalogue and evidence base as your ISO 27001 programme.

Where AI governance stalls

Nobody can answer 'what AI are we running, and who owns the risk?' in under a week.

  • Every team signed up a different model or vendor; there is no single inventory and no owner.
  • The AI Act asks for tiering, technical documentation and impact assessments — your evidence is a Notion page and a policy someone drafted with ChatGPT.
  • ISO 42001 needs a management system, not a policy: objectives, roles, lifecycle controls, monitoring, review.
  • Doing it separately from ISO 27001 means documenting access control, supplier review and incident response twice.
Product walkthrough

Watch the AIMS come together

Onboard an AI system, classify it against the AI Act, score its AI-specific risks, treat them with ISO 42001 Annex A controls, and produce the impact assessment and Statement of Applicability.

  1. 1
    AI system inventory

    Register every model, use case and supplier with owner, data sources, lifecycle stage and risk tier.

  2. 2
    EU AI Act tiering

    Classify prohibited / high-risk / limited / minimal; the tier unlocks the duties that actually apply.

  3. 3
    AI risk register

    AI-specific taxonomy — bias, drift, prompt injection, training-data leakage, hallucination — scored and owned.

  4. 4
    ISO 42001 Annex A controls

    All 39 controls pre-loaded; mark in or out of scope with justification and the AIMS SoA assembles itself.

  5. 5
    AI impact assessment

    Structured AIIA covering fundamental rights, bias, transparency and human oversight, tailored to the tier.

  6. 6
    Crosswalk to ISO 27001 & NIST AI RMF

    Reuse existing evidence across standards instead of documenting the same control three times.

Spreadsheets vs ISO-STANDARD.app

The jobSpreadsheets & shared driveISO-STANDARD.app
AI system inventoryA tab someone updated once, already missing three tools procurement approved.Live register with owners, tiers, data flows and lifecycle stage.
AI Act classificationDebated over email; no record of the reasoning.Recorded tier with rationale and the duties that follow from it.
Impact assessmentsA Word template completed differently by every team.Structured AIIA generated from the system data you already captured.
Evidence reuseCopy-paste from the ISO 27001 folder, then drift.One evidence base mapped to both 27001 and 42001 controls.
Certification prepReassembled from scratch before the audit.AIMS SoA, objectives, monitoring and review records exported on demand.
Free readiness assessment

Free ISO 42001 readiness assessment

Inventory your AI systems, tier them against the EU AI Act, and load the 39 Annex A controls. You get a gap score across the AIMS clauses and controls without a sales call.

  • Annex A (39 control) coverage score
  • AI Act tier per system and the duties triggered
  • Missing AIMS clause 4–10 documentation
  • Overlap you can reuse from an existing ISO 27001 ISMS

Instant download, no sales call. We reply within one business day.

What it costs

Same published pricing as the rest of the platform — the AIMS is not an upsell tier.

Starter
£79/mo

AI inventory, AI risk register, controls and policies.

Growth
£199/mo

Impact assessments, SoA, crosswalk, audits and AI ‘Fix this’ remediation.

Business
£399/mo

Microsoft 365 evidence automation, Jira and service-desk integrations, SSO.

Full feature-by-feature breakdown on the pricing page. No sales call required to start.

MM
Built by Michael McCarroll
25+ years · IT governance · Information security · AI

I've spent 25 years in IT governance and the last few helping organisations adopt AI without pretending the risk isn't new. ISO 42001 rewards teams that can show a working management system — inventory, tiering, assessment, monitoring — not teams with the longest AI policy.

Read the founder story

Where to go next

See the wider AI governance platform, read the ISO 42001 certification readiness guide or the AI impact assessment guide.

Answers buyers, procurement and auditors want

Can we run ISO 42001 alongside ISO 27001?+

Yes — that's the point of the shared model. One risk register, one control catalogue and one evidence base serve both, with crosswalk mapping so a single access-review record evidences controls in each standard.

Does this make us EU AI Act compliant?+

It gives you the inventory, tiering, impact assessments and technical records the Act expects, and maps obligations to controls. Legal interpretation for your specific systems remains yours — but you'll have the evidence to support it.

How long does ISO 42001 readiness take?+

Teams with an existing ISMS typically reach readiness in 30–60 days because most clause 4–10 machinery is reused. Starting from scratch, plan for 90 days.

Is the readiness assessment free?+

Yes. Inventory your systems and score your Annex A coverage before you pay anything.

Stand up your AI management system this week

Inventory your AI, classify it against the AI Act, and produce the ISO 42001 evidence reviewers and certification bodies expect.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.