ISO/IEC 42001 AI Management

ISO/IEC 42001 — an AI management system that runs itself.

ISO/IEC 42001 is the first certifiable management-system standard for artificial intelligence. It asks who owns each AI system, what it is allowed to do, how it is monitored, and what evidence proves it. Lojycal keeps that register live instead of frozen in a document.

What ISO/IEC 42001 actually demands

Certification auditors look for a working AI management system (AIMS) — not a policy PDF. Four things must hold on any given day.

  • A complete AI system inventory

    Every model, assistant, copilot, and embedded AI feature in use — including the ones a department bought without telling IT.

  • Impact assessment per system

    Annex B requires documented assessment of the impact on individuals and society, proportionate to the risk of each system.

  • Defined roles and accountability

    Named owners for each AI system, an accountable management representative, and evidence of management review.

  • Continual monitoring and improvement

    Performance, incidents, and corrective actions logged over time — an AIMS is judged on its operating record, not its design.

The Lojycal AI governance engine

AI usage is discovered from the same connectors that run the rest of your estate, then held to the standard's clauses.

AI system register

Discovered AI tools and internal models with owner, purpose, data categories, and lifecycle state. Shadow AI surfaces automatically from SaaS and browser telemetry.

Shadow IT Lab + Application Library

Impact assessments

Templated assessments per system, versioned and re-triggered when the system's purpose, data, or vendor changes.

Policy Lab → ISO 42001

Operational monitoring

Usage, access grants, and incidents tracked continuously so the AIMS has a real operating record to show an auditor.

Audit Log + Access Reviews

Certification evidence pack

Signed exports mapping each clause and Annex A control to the artefact that satisfies it, verifiable independently of Lojycal.

Trust Center → Evidence Pack

ISO 42001 clauses → Lojycal controls

Lojycal produces evidence for the majority of the standard's operational clauses. A sampled view:

Clause / Annex AExample obligationLojycal source
4 — Context of the organisationScope of the AIMS and AI systems in useAI system register
5 — LeadershipAI policy approved by managementPolicy Lab
6 — PlanningAI risk assessment and treatment planTrust Center → Risk
7 — SupportCompetence, awareness, documented informationHR Automation
8 — OperationAI impact assessment per systemPolicy Lab → ISO 42001
9 — Performance evaluationMonitoring, internal audit, management reviewAudit Log + Access Reviews
10 — ImprovementNonconformity and corrective actionIncident Reports
A.6 — AI system lifecycleResponsible design and deployment recordsApplication Library

Lojycal automates the evidence. Certification remains the job of an accredited certification body — we make the audit short, not optional.

Evidence that survives an audit

Every artefact is signed, timestamped, and independently verifiable.

The AIMS evidence pack bundles the AI system register, impact assessments, management-review minutes, and the monitoring record into one signed archive with a detached signature. Auditors verify the signature without trusting Lojycal — the same mechanism used for ISO 27001 and NIS2 packs.

Your path to a working AIMS

Most organisations reach audit-readiness in a single quarter.

  1. Week 1–2

    Discover

    Connect identity, SaaS, and browser telemetry. The AI system register populates itself, including shadow AI.

  2. Week 3–6

    Assess

    Run impact assessments on the systems that matter, assign owners, and close the obvious gaps.

  3. Week 7–10

    Operate

    Monitoring, incidents, and reviews accumulate a genuine operating record.

  4. Week 11+

    Certify

    Export the signed evidence pack and walk your certification body through it.

ISO/IEC 42001 questions

Is ISO/IEC 42001 mandatory?

No. It is a voluntary, certifiable management-system standard. It is increasingly demanded contractually — enterprise buyers and public-sector tenders use it the same way they use ISO 27001, as a precondition rather than a nice-to-have.

How does it relate to the EU AI Act?

They overlap heavily but are not the same. The AI Act is binding law with risk classes and obligations; ISO 42001 is a management system that helps you demonstrate you are meeting them. In Lojycal the underlying evidence is shared, and the mapping between the two is bidirectional.

We only use third-party AI tools. Does it still apply?

Yes. The standard covers AI systems you use, not just AI you build. Procured copilots and assistants need an owner, a purpose, a data assessment, and monitoring — which is precisely what the discovery-driven register gives you.

How many controls does Lojycal map?

The framework advertises 38 controls across the clauses and Annex A. Lojycal ships a mapped subset covering the operational controls it can evidence directly, and the export states clearly how many of the 38 are mapped so nobody is misled about coverage.

Where do I switch it on?

Policy Lab → Available frameworks (off) → Enable on the ISO/IEC 42001 card. It then appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.

Run your AI management system as a live system.

Every model. Every owner. Every assessment. One signed source of truth your certification body can verify.