Providers and developers of AI
Organisations that build models or AI products and want a certifiable governance system their customers can rely on — the Annex A controls cover the AI lifecycle, data and third parties.
Nobody is required to. These are the organisations for which the standard answers a question someone is already asking.
Organisations that build models or AI products and want a certifiable governance system their customers can rely on — the Annex A controls cover the AI lifecycle, data and third parties.
Companies using several AI systems across functions, where an inventory, an impact-assessment method and a review cycle need an owner.
The two standards share the Annex SL clause structure, so an ISMS already answers the context, leadership, support and evaluation clauses — one management system, two scopes.
Certified by an accredited certification body — never by Veritome (ISO/IEC 17021-1 §5.2.5 keeps the consultant and the certifier apart).
| Date | Event | What it means |
|---|---|---|
| 18.12.2023 | Published | First edition of ISO/IEC 42001, the first certifiable AI management system standard. |
| 01.08.2024 | EU AI Act in force | Regulation (EU) 2024/1689 entered into force; harmonised standards for it are drafted separately by CEN-CENELEC and none is cited in the Official Journal yet. |
| 02.12.2027 | EU AI Act Annex III | The date most Annex III high-risk duties apply from. An AI management system organises the work; it gives no presumption of conformity today. |
The standard follows the Annex SL structure every modern ISO management system uses — context, leadership, planning, support, operation, performance evaluation, improvement — and adds AI-specific requirements: an AI risk assessment, an AI system impact assessment, and an Annex A of controls on policy, roles, resources, lifecycle, data, information for interested parties, responsible use and third parties. Veritome's catalogue paraphrases every clause and control; the standard's own text is licensed and is never reproduced.
6 phases: Establish · Plan · Support · Operate · Evaluate & improve · Certification audit. Each phase opens when the one before it is complete, the same gate rule the EU AI Act journey uses. 14 of the 27 steps are one record shared with the ISO/IEC 27001 programme — context, interested parties, roles, risk method, objectives, change, competence, awareness, documented information, operational control, monitoring, internal audit, management review and corrective action — written once, credited in both. The Statement of Applicability is a view over the programme, not a second form: exclusions need a written justification. The certification phase is optional and records the arrangements with your certification body.
The 14 shared records are the only place two frameworks credit the same evidence in Veritome — the owner's verified matrix checked those clauses against both standards. Everything else that connects ISO/IEC 42001 to the EU AI Act, the GDPR or the NIST AI RMF is a related link: shown beside the step as supporting reading, never counted as coverage.
| With | Records credited in both | Related only — shown, never credited | Page |
|---|---|---|---|
| EU AI Act | 0 | 34 | EU AI Act → |
| GDPR | 0 | 16 | GDPR → |
| ISO 27001 | 14 | 18 | ISO 27001 → |
| NIST AI RMF | 0 | 23 | NIST AI RMF → |
13 of the 27 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.
The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.
The first international standard for an AI management system, published by ISO and IEC in December 2023. It specifies how an organisation establishes, runs and improves the governance of the AI it develops or uses — policy, roles, risk and impact assessment, lifecycle controls, review — and it can be certified by an accredited body.
No. It is voluntary, and it is not a harmonised standard under the Act. The European harmonised standards are being drafted by CEN-CENELEC's JTC 21 and none has been cited in the Official Journal, so no standard gives a presumption of conformity today. ISO/IEC 42001 organises the management-system half of the work; it does not discharge an Art. 9 or Art. 17 obligation on its own.
38 Annex A controls, alongside 27 clause requirements in clauses 4 to 10 — 65 requirements in Veritome's catalogue. The controls are applied through the Statement of Applicability: each is included or excluded with a justification.
Yes — both follow the Annex SL clause structure, so the context, leadership, support and evaluation clauses are answered once. Veritome shares 14 records between the two programmes: one record, both programmes, credit in both.
The document that lists every Annex A control and says whether it is included, and why any is excluded. In Veritome it is a view over the programme — the SoA steps open pre-filled from the records already written, and an exclusion needs a justification sentence before it saves.
No. Certification is issued by an accredited certification body after its own audit, and ISO/IEC 17021-1 keeps the party that helped build the system apart from the party that certifies it. Veritome runs the programme and produces the records; the certification phase records the arrangements with the body you choose.