Compliance
ISO/IEC 42001
The auditable AI management system standard. Operational evidence for the clauses an internal auditor asks to see.
At a glance
Who this covers, and who enforces it
Organizations that establish, implement, maintain, and improve an AI management system (AIMS) — certifiable by an accredited body.
- Instrument
- ISO/IEC 42001:2023 — certifiable standard
- Issued by
- ISO/IEC JTC 1/SC 42
- Published
- December 2023
- Certification
- Accredited bodies; three-year cycle with surveillance audits
- Scope
- AI management systems (AIMS)
Requirements
What it asks for
- 1Documented AIMS scope, policy, and objectives
- 2AI-specific risk assessment and treatment plan
- 3Operational controls and staff competence
- 4Internal audit and management review
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Documented policy & scope
- Projects & Team defines ownership and scope per workspace.
- Risk assessment
- Model Inventory and Synthetic Scenarios document tested risk scenarios per system.
- Operational controls
- Guardrails enforce policy on live traffic with a full event log.
- Internal audit
- Export & Audit hands an internal auditor the full evidence trail instead of a log-mining exercise.
Primary source
Read the actual text
Everything on this page is drawn from ISO — ISO/IEC 42001:2023. The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes ISO/IEC 42001’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. ISO/IEC 42001 compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
- All frameworksThe full evidence-layer overview and all twelve frameworks.
- SR 11-7 model riskModel risk management discipline applied to AI and LLMs. Monitoring, validation, and change history in one place.
- NY DFS Part 500Cybersecurity oversight extended to AI systems, with incident evidence and access records examiners expect.
Ask us about your framework
Tell us how ISO/IEC 42001 applies to your systems and we'll show you the evidence path.