⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · AI governance standard

ISO 42001 AI governance, with human oversight you can prove.

ISO/IEC 42001 is the first certifiable international standard for an AI Management System (AIMS) — governing how an organisation develops, deploys, and monitors AI systems responsibly. grComply seeds the full clause structure (Context through Improvement) plus Annex A AI controls, and can bundle it with ISO 27001 and the NIST AI Risk Management Framework in one mapping-set profile — the same discipline grComply applies to its own BYOK AI assistant, which drafts narratives but never auto-completes a control without a human decision.

8 clause themes — AI risk, impact assessment, and human oversight, each a trackable control.
Back to all frameworks WhatsApp us
8Clause themes
2023ISO revision seeded
AIMSCertifiable AI management system
StructuralSeed depth

What is ISO/IEC 42001? ISO/IEC 42001:2023 is the first international, certifiable standard for an AI Management System (AIMS) — requiring organisations to govern AI development and use through documented risk assessment, impact assessment, human oversight, and continual improvement, structured the same way ISO 27001 structures information security.

Why it's different

How grComply benefits your ISO 42001 programme

A dedicated AIMS clause structure, not ISO 27001 repurposed

Context, Leadership, Planning, Support, Operation, Evaluation, Improvement, plus Annex A AI controls, seeded as its own tree.

AI risk assessment feeds the same risk register

An AI-specific risk entry sits in the identical configurable register used for every other risk in the platform.

Impact assessments become versioned documentation

An AI system impact assessment is evidence-tracked and versioned like any other control artefact, not a one-off Word doc.

Human oversight is provable, not asserted

A RACI attestation requirement makes "a human is accountable" a checked fact, not a claim in a policy.

Mapping-set ready: AIMS + ISMS + NIST AI RMF in one profile

grComply's own illustrative example bundles ISO 42001, ISO 27001, and NIST AI RMF into one activated mapping set.

grComply's own AI assistant is governed the way this standard expects

BYOK, labelled AI output, confirm-before-complete is the transparency and human-oversight pattern 42001 asks organisations to run internally.

Structure

Eight clause themes, seeded with the real AIMS structure

Follows the ISO management-system pattern — Context through Improvement — plus a sample Annex A AI-control set covering development, transparency, and oversight.

Context of the organization

Understanding the organisation and its AI context, and identifying interested parties and AI system scope — the foundation an AIMS is scoped from.

Leadership

AI policy and leadership commitment, and clearly assigned roles, responsibilities, and authorities for AI governance.

Planning

AI risk assessment and treatment, and AI system impact assessment — both versioned, evidence-tracked artefacts rather than static documents.

Support & Operation

Competence, awareness, and documented information; AI system life cycle processes; data governance for AI systems; and third-party/supplier AI relationships.

Performance evaluation & Improvement

Monitoring, measurement, and internal audit of the AIMS, plus nonconformity, corrective action, and continual improvement.

Annex A — AI control objectives

AI system development controls, transparency and explainability, and human oversight — evidenced with a RACI attestation, not a policy statement alone.

Evidence, mapped

Evidence grComply already models for ISO 42001

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
LDR-1 — AI policyPolicy documentApproved AI / AIMS policy
PLN-1 — AI risk assessmentRisk register exportAI risk register excerpt
PLN-2 — AI impact assessmentPolicy documentAI system impact assessment, versioned
ANX-2 — TransparencyNarrative documentTransparency statement for in-scope AI systems
ANX-3 — Human oversightAttestationHuman oversight RACI attestation

Why this matters: grComply's own AI assistant follows 42001's own logic before the standard even applies to it: BYOK, clearly labelled AI-generated output, and a human decision required before anything counts as complete — the platform practices the governance pattern it helps you certify.

Product screens

ISO 42001, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to ISO 42001.

FAQ

ISO 42001 in grComply

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the first certifiable international standard for an AI Management System (AIMS), requiring documented AI risk assessment, impact assessment, human oversight, and continual improvement — structured the same way ISO 27001 structures information security.

Does grComply support the full AIMS clause structure?

Yes — Context, Leadership, Planning, Support, Operation, Performance evaluation, and Improvement are seeded, plus a sample of Annex A AI control objectives.

How is an AI risk assessment different from a normal risk register entry?

Structurally it isn't — an AI-specific risk uses the identical configurable risk register (likelihood, impact, treatment, owner) every other risk in grComply uses, just scoped to an AI system.

What does grComply mean by 'human oversight, provable'?

Annex A's human-oversight control carries a RACI attestation requirement, so accountability for a given AI system is a checked, evidenced fact rather than a sentence in a policy document.

Can ISO 42001 run alongside ISO 27001 and NIST AI RMF?

Yes — grComply's own illustrative mapping-set example bundles ISO/IEC 42001 (AI management), ISO/IEC 27001 (information assets), and the NIST AI Risk Management Framework into one activated profile.

Does grComply's own AI assistant follow ISO 42001 principles?

Yes — the platform's BYOK Claude assistant drafts narratives and suggestions labelled as AI-generated, and a human always confirms before anything counts as complete, matching the transparency and oversight this standard expects internally.

Who needs ISO 42001 certification?

Organisations that develop, deploy, or heavily rely on AI systems and want to formally demonstrate responsible AI governance to customers, regulators, or partners increasingly asking for it.

Can we import the full official 42001 control text?

Yes — the seeded clause and Annex A structure expands to the complete official text via the same versioned import path used for any framework. See the full catalog on the Compliance Frameworks page.

See ISO 42001 mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about ISO 42001

Tell us where your ISO 42001 programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring ISO 42001 into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us