ISO 42001 AI governance, with human oversight you can prove.
ISO/IEC 42001 is the first certifiable international standard for an AI Management System (AIMS) — governing how an organisation develops, deploys, and monitors AI systems responsibly. grComply seeds the full clause structure (Context through Improvement) plus Annex A AI controls, and can bundle it with ISO 27001 and the NIST AI Risk Management Framework in one mapping-set profile — the same discipline grComply applies to its own BYOK AI assistant, which drafts narratives but never auto-completes a control without a human decision.
What is ISO/IEC 42001? ISO/IEC 42001:2023 is the first international, certifiable standard for an AI Management System (AIMS) — requiring organisations to govern AI development and use through documented risk assessment, impact assessment, human oversight, and continual improvement, structured the same way ISO 27001 structures information security.
How grComply benefits your ISO 42001 programme
A dedicated AIMS clause structure, not ISO 27001 repurposed
Context, Leadership, Planning, Support, Operation, Evaluation, Improvement, plus Annex A AI controls, seeded as its own tree.
AI risk assessment feeds the same risk register
An AI-specific risk entry sits in the identical configurable register used for every other risk in the platform.
Impact assessments become versioned documentation
An AI system impact assessment is evidence-tracked and versioned like any other control artefact, not a one-off Word doc.
Human oversight is provable, not asserted
A RACI attestation requirement makes "a human is accountable" a checked fact, not a claim in a policy.
Mapping-set ready: AIMS + ISMS + NIST AI RMF in one profile
grComply's own illustrative example bundles ISO 42001, ISO 27001, and NIST AI RMF into one activated mapping set.
grComply's own AI assistant is governed the way this standard expects
BYOK, labelled AI output, confirm-before-complete is the transparency and human-oversight pattern 42001 asks organisations to run internally.
Eight clause themes, seeded with the real AIMS structure
Follows the ISO management-system pattern — Context through Improvement — plus a sample Annex A AI-control set covering development, transparency, and oversight.
Context of the organization
Understanding the organisation and its AI context, and identifying interested parties and AI system scope — the foundation an AIMS is scoped from.
Leadership
AI policy and leadership commitment, and clearly assigned roles, responsibilities, and authorities for AI governance.
Planning
AI risk assessment and treatment, and AI system impact assessment — both versioned, evidence-tracked artefacts rather than static documents.
Support & Operation
Competence, awareness, and documented information; AI system life cycle processes; data governance for AI systems; and third-party/supplier AI relationships.
Performance evaluation & Improvement
Monitoring, measurement, and internal audit of the AIMS, plus nonconformity, corrective action, and continual improvement.
Annex A — AI control objectives
AI system development controls, transparency and explainability, and human oversight — evidenced with a RACI attestation, not a policy statement alone.
Evidence grComply already models for ISO 42001
Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.
| Control | Evidence type | Example |
|---|---|---|
| LDR-1 — AI policy | Policy document | Approved AI / AIMS policy |
| PLN-1 — AI risk assessment | Risk register export | AI risk register excerpt |
| PLN-2 — AI impact assessment | Policy document | AI system impact assessment, versioned |
| ANX-2 — Transparency | Narrative document | Transparency statement for in-scope AI systems |
| ANX-3 — Human oversight | Attestation | Human oversight RACI attestation |
Why this matters: grComply's own AI assistant follows 42001's own logic before the standard even applies to it: BYOK, clearly labelled AI-generated output, and a human decision required before anything counts as complete — the platform practices the governance pattern it helps you certify.
ISO 42001, in the live workspace
The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to ISO 42001.






ISO 42001 in grComply
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first certifiable international standard for an AI Management System (AIMS), requiring documented AI risk assessment, impact assessment, human oversight, and continual improvement — structured the same way ISO 27001 structures information security.
Does grComply support the full AIMS clause structure?
Yes — Context, Leadership, Planning, Support, Operation, Performance evaluation, and Improvement are seeded, plus a sample of Annex A AI control objectives.
How is an AI risk assessment different from a normal risk register entry?
Structurally it isn't — an AI-specific risk uses the identical configurable risk register (likelihood, impact, treatment, owner) every other risk in grComply uses, just scoped to an AI system.
What does grComply mean by 'human oversight, provable'?
Annex A's human-oversight control carries a RACI attestation requirement, so accountability for a given AI system is a checked, evidenced fact rather than a sentence in a policy document.
Can ISO 42001 run alongside ISO 27001 and NIST AI RMF?
Yes — grComply's own illustrative mapping-set example bundles ISO/IEC 42001 (AI management), ISO/IEC 27001 (information assets), and the NIST AI Risk Management Framework into one activated profile.
Does grComply's own AI assistant follow ISO 42001 principles?
Yes — the platform's BYOK Claude assistant drafts narratives and suggestions labelled as AI-generated, and a human always confirms before anything counts as complete, matching the transparency and oversight this standard expects internally.
Who needs ISO 42001 certification?
Organisations that develop, deploy, or heavily rely on AI systems and want to formally demonstrate responsible AI governance to customers, regulators, or partners increasingly asking for it.
Can we import the full official 42001 control text?
Yes — the seeded clause and Annex A structure expands to the complete official text via the same versioned import path used for any framework. See the full catalog on the Compliance Frameworks page.
See ISO 42001 mapped into your control library
Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →
Talk to us about ISO 42001
Tell us where your ISO 42001 programme stands today, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to bring ISO 42001 into one control library?
We respond within one working day — or reach us instantly on WhatsApp.