ISO/IEC 42001 — an AI management system that runs itself.
ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence. It asks who owns each AI system, what it is allowed to do, how it is monitored, and what evidence proves it. Lojycal keeps that register live instead of frozen in a document.
What ISO/IEC 42001 actually demands
Certification auditors look for a working AI management system (AIMS) — not a policy PDF. Four things must hold on any given day.
A complete AI system inventory
Every model, assistant, copilot, and embedded AI feature in use — including the ones a department bought without telling IT.
Impact assessment per system
Annex B requires documented assessment of the impact on individuals and society, proportionate to the risk of each system.
Defined roles and accountability
Named owners for each AI system, an accountable management representative, and evidence of management review.
Continual monitoring and improvement
Performance, incidents, and corrective actions logged over time — an AIMS is judged on its operating record, not its design.
The Lojycal AI governance engine
AI usage is discovered from the same connectors that run the rest of your estate, then held to the standard's clauses.
AI system register
Discovered AI tools and internal models with owner, purpose, data categories, and lifecycle state. Shadow AI surfaces automatically from SaaS and browser telemetry.
Shadow IT Lab + Application Library
Impact assessments
Templated assessments per system, versioned and re-triggered when the system's purpose, data, or vendor changes.
Policy Lab → ISO 42001
Operational monitoring
Usage, access grants, and incidents tracked continuously so the AIMS has a real operating record to show an auditor.
Audit Log + Access Reviews
Certification evidence pack
Signed exports mapping each clause and Annex A control to the artefact that satisfies it, verifiable independently of Lojycal.
Trust Center → Evidence Pack
ISO 42001 clauses → Lojycal controls
Lojycal produces evidence for the majority of the standard's operational clauses. A sampled view:
| Clause / Annex A | Example obligation | Lojycal source |
|---|---|---|
| 4 — Context of the organisation | Scope of the AIMS and AI systems in use | AI system register |
| 5 — Leadership | AI policy approved by management | Policy Lab |
| 6 — Planning | AI risk assessment and treatment plan | Trust Center → Risk |
| 7 — Support | Competence, awareness, documented information | HR Automation |
| 8 — Operation | AI impact assessment per system | Policy Lab → ISO 42001 |
| 9 — Performance evaluation | Monitoring, internal audit, management review | Audit Log + Access Reviews |
| 10 — Improvement | Nonconformity and corrective action | Incident Reports |
| A.6 — AI system lifecycle | Responsible design and deployment records | Application Library |
Lojycal automates the evidence. Certification remains the job of an accredited certification body — we make the audit short, not optional.
Evidence that survives an audit
Every artefact is signed, timestamped, and independently verifiable.
The AIMS evidence pack bundles the AI system register, impact assessments, management-review minutes, and the monitoring record into one signed archive with a detached signature. Auditors verify the signature without trusting Lojycal — the same mechanism used for ISO 27001 and NIS2 packs.
Your path to a working AIMS
Most organisations reach audit-readiness in a single quarter.
- Week 1–2
Discover
Connect identity, SaaS, and browser telemetry. The AI system register populates itself, including shadow AI.
- Week 3–6
Assess
Run impact assessments on the systems that matter, assign owners, and close the obvious gaps.
- Week 7–10
Operate
Monitoring, incidents, and reviews accumulate a genuine operating record.
- Week 11+
Certify
Export the signed evidence pack and walk your certification body through it.
ISO/IEC 42001 questions
Is ISO/IEC 42001 mandatory?
No. It is a voluntary, certifiable management-system standard. It is increasingly demanded contractually — enterprise buyers and public-sector tenders use it the same way they use ISO 27001, as a precondition rather than a nice-to-have.
How does it relate to the EU AI Act?
They overlap heavily but are not the same. The AI Act is binding law with risk classes and obligations; ISO 42001 is a management system that helps you demonstrate you are meeting them. In Lojycal the underlying evidence is shared, and the mapping between the two is bidirectional.
We only use third-party AI tools. Does it still apply?
Yes. The standard covers AI systems you use, not just AI you build. Procured copilots and assistants need an owner, a purpose, a data assessment, and monitoring — which is precisely what the discovery-driven register gives you.
How many controls does Lojycal map?
The framework advertises 38 controls across the clauses and Annex A. Lojycal ships a mapped subset covering the operational controls it can evidence directly, and the export states clearly how many of the 38 are mapped so nobody is misled about coverage.
Where do I switch it on?
Policy Lab → Available frameworks (off) → Enable on the ISO/IEC 42001 card. It then appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.
Run your AI management system as a live system.
Every model. Every owner. Every assessment. One signed source of truth your certification body can verify.
