Software and AI vendors
Anyone whose customers send a security questionnaire — an ISMS is the answer most of them expect, and a certificate ends the questionnaire.
Nobody is required to. These are the organisations for which the standard answers a question someone is already asking.
Anyone whose customers send a security questionnaire — an ISMS is the answer most of them expect, and a certificate ends the questionnaire.
Art. 28 and Art. 32 ask a processor to show appropriate technical and organisational measures; an ISMS is the usual evidence.
EU AI Act Art. 15 asks for accuracy, robustness and cybersecurity across the lifecycle; the technological controls of Annex A are where that work is organised.
Certified by an accredited certification body — never by Veritome (ISO/IEC 17021-1 §5.2.5 keeps the consultant and the certifier apart).
| Date | Event | What it means |
|---|---|---|
| 25.10.2022 | 2022 edition published | ISO/IEC 27001:2022 replaced the 2013 edition; Annex A was restructured into four themes. |
| 31.10.2025 | Transition ended | Certificates to the 2013 edition ceased to be valid; every current certificate is to the 2022 edition. |
| 18.12.2023 | ISO/IEC 42001 published | The AI management system standard shares the Annex SL clause structure, which is why Veritome runs the two as one system. |
Clauses 4 to 10 set out the management system — context, leadership, planning, support, operation, evaluation, improvement — and Annex A lists the 93 controls in four themes: organisational, people, physical and technological. A control is applied through the Statement of Applicability, so the standard asks you to decide, justify and evidence, not to switch everything on. Veritome's catalogue names each control; the standard's own text is licensed and is never reproduced.
6 phases: Establish · Plan · Support · Operate · Evaluate & improve · Certification audit, gate-locked in that order. 14 of the 25 steps are the same record as the ISO/IEC 42001 programme — one form, both programmes, and approving it re-plans the sibling. The Operate phase groups the 93 controls into organisational, people, physical and technological themes plus continuity and incident management, so a control is evidenced where the work happens rather than in 93 separate forms. The Statement of Applicability is generated from those records.
The 14 records shared with ISO/IEC 42001 are credited in both programmes — the owner's verified matrix checked the clauses against both standards. Links from the security programme to the EU AI Act, the GDPR or the NIST AI RMF are related links: supporting reading beside a step, never coverage. GDPR Art. 32 and EU AI Act Art. 15 are the two the matrix relates most often.
| With | Records credited in both | Related only — shown, never credited | Page |
|---|---|---|---|
| EU AI Act | 0 | 17 | EU AI Act → |
| GDPR | 0 | 11 | GDPR → |
| ISO 42001 | 14 | 18 | ISO 42001 → |
| NIST AI RMF | 0 | 7 | NIST AI RMF → |
10 of the 25 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.
The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.
The international standard for an information security management system (ISMS), published by ISO and IEC. The current edition is 2022. It specifies how an organisation scopes, risk-assesses, controls and continually improves its information security, and it is certifiable by an accredited body.
Because its customers ask, and because three regimes point at the same work: GDPR Art. 32 asks for security appropriate to the risk, EU AI Act Art. 15 asks providers of high-risk systems for cybersecurity across the lifecycle, and ISO/IEC 42001 assumes the security clauses are already answered. One ISMS is the evidence for all three.
93 Annex A controls in four themes — organisational, people, physical and technological — beside 25 clause requirements in clauses 4 to 10. Veritome's catalogue carries all 118.
Annex A went from 114 controls in fourteen domains to 93 in four themes, with eleven new controls covering threat intelligence, cloud services, ICT readiness for continuity, physical monitoring, configuration, information deletion, data masking, data-leakage prevention, monitoring, web filtering and secure coding. The clauses 4 to 10 changed little. Certificates to the 2013 edition ceased to be valid on 31.10.2025.
Yes. Both follow the Annex SL clause structure, so context, leadership, support and evaluation are one set of records. Veritome runs them as one management system with two scopes: 14 of the 25 steps here are shared with the ISO/IEC 42001 programme.
No. An accredited certification body audits and certifies; ISO/IEC 17021-1 keeps the party that helped build the ISMS apart from the party that certifies it. Veritome runs the programme, generates the Statement of Applicability and holds the evidence the auditor asks for.