Compyl
Framework · ISO 42001AI management systems

ISO 42001, built on the ISMS you already run.

ISO/IEC 42001 is the first international standard for AI management systems, and the EU AI Act is making responsible AI a regulatory requirement rather than a talking point. Compyl runs your AI governance program on the same control library as the rest of your GRC, so most of the evidence you need already exists.

38 Annex A controls125+ integrationsISO 27001 head start
ISO 42001 · AIMS readinessStage 1 audit · in 6 weeks
82%ready
Annex A controls with live evidence31 / 38
Inherited from ISO 27001 ISMS19 / 38
Evidence Health90
A.2–A.3 GovernanceA.5 Impact · 1 assessment dueA.6 Life cycleA.7 DataA.10 Third parties
AI system impact assessment · churn modelBias and transparency evaluated · review due in 9 days
Due soon
A.6.2.4 · AI system verificationEvaluation results attached from the MLOps pipeline
Passing
ISMS overlap · 19 controls satisfied by existing ISO 27001 evidenceHead start
The problem

AI governance stopped being optional

The standard is new, the regulation is real, and buyers are already asking. Most teams have an AI policy; very few have a management system they could put in front of an auditor.

The EU AI Act is enforcing

The Act entered into force in August 2024, general-purpose AI obligations began in August 2025, and the 2026 Digital Omnibus on AI moved high-risk obligations to December 2027 (August 2028 for AI in regulated products). ISO 42001 is a strong, widely used way to evidence the governance the Act expects.

Your customers are asking

Security questionnaires now include AI sections. Enterprise buyers want evidence that your AI features are governed, and an ISO 42001 certificate answers the question before it is asked.

Boards want proof, not policy

AI risk has reached the board agenda. A certifiable management system turns responsible-AI intentions into controls, owners, evidence, and audit results.

How it works

One continuous loop, from connected systems to certification-ready

Compyl runs your AIMS as an always-on cycle, Annex A controls, impact assessments, and evidence stay in sync automatically.

01

Connect

Integrate cloud, identity, ML, data, and HR systems.

02

Collect evidence

Pull audit evidence automatically, in real time.

03

Map to Annex A

Link every artifact to its ISO 42001 control and clause.

04

Monitor

Watch controls continuously and flag drift early.

05

Stay certification-ready

Hand auditors a current evidence pack on demand.

Annex A

Nine control categories, one management system

ISO 42001 organizes its 38 Annex A controls into nine categories. Compyl maps live evidence to each, reusing your ISMS wherever the controls overlap.

Governance

Foundation
A.2 – A.3

AI policy, internal organization, roles, and the leadership accountability it starts with.

Policy · roles · reporting

Impact assessment

Assess
A.5

Assess the impact of each AI system on individuals, groups, and society before and during use.

Individuals · society · review

AI system life cycle

Build
A.6

Objectives, design, verification, deployment, and monitoring across the life of each AI system.

Design · verify · operate

Data & resources

Inputs
A.4 · A.7

Resources, data provenance, quality, and preparation for the systems that depend on them.

Provenance · quality · resources

Third parties

Outward
A.8 – A.10

Information for interested parties, responsible use, and supplier and customer relationships.

Users · suppliers · customers
Automated evidence

Stop assembling AIMS evidence by hand

ISO 42001 follows the same harmonized structure as ISO 27001, and the overlap is large. Compyl maps each control once, so your existing ISMS evidence counts toward your AIMS from day one, and pulls the AI-specific proof from your ML stack.

  • Reuse ISMS evidence for every Annex A control it already satisfies
  • Pull life-cycle evidence from your model registry, pipelines, and data platform
  • No more screenshots, spreadsheets, or last-minute requests
  • Export a complete, auditor-ready evidence pack on demand
AIMS evidence · collected automatically684 artifacts · live
ISO 27001 ISMS · shared controls312 artifacts inherited · mapped to A.2, A.3, A.7, A.10
Reused
MLflow · model registry, evaluations148 artifacts · mapped to A.6.2 life cycle · A.6.2.4 verification
Synced 4m
Snowflake · training data lineage96 artifacts · mapped to A.7.2 – A.7.6 data for AI systems
Synced 9m
Policy library · AI policy, roles28 artifacts · mapped to A.2.2, A.3.2, A.8
Synced 1h
Every artifact mapped to the Annex A control it supportsAuditor-ready pack
Evidence Health · New in 26.2

Know your evidence is audit-ready, automatically

Collecting evidence is only half the battle; stale or incomplete proof is where certification audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces weeks before the audit, not during it.

  • Every artifact scored on relevance, freshness, and completeness
  • An AI summary spells out exactly what’s missing and why
  • Re-scores automatically whenever the underlying evidence changes
  • Gaps surface with time to fix, not in front of the auditor
Evidence HealthNew in 26.2 · re-scores on change
ArtifactAI impact assessment · A.5.4
Score52 / 100
RelevanceHigh
FreshnessStale · 11 months
AI summary · what’s missingThe assessment predates the switch to a third-party foundation model and the expansion to EU users. Neither the new provider nor the high-risk classification under the EU AI Act is assessed. Re-run the impact assessment before the Stage 1 audit.
Create taskOpen assessment
Weak evidence surfaces before the certification audit, not during itScored continuously
Continuous monitoring

Catch drift before the auditor does

Models ship faster than policies update. Compyl monitors every Annex A control continuously, scores your posture in real time, and turns the moment something slips into a tracked task.

  • Live posture across all 38 Annex A controls
  • Automatic alerts the moment a control drifts out of compliance
  • Remediation tasks auto-assigned with owners and deadlines
  • A defensible, time-stamped trail across every AI system in scope
Continuous monitoring38 Annex A controls · checked hourly
Detected09:14 · model deployed without evaluation record
AlertedOwner: ML platform
Task openAI-214 · due in 2 days
Verifiedauto re-check
A.6.2.4 · AI system verificationDrifted 09:14 · evaluation record missing for v3.2
Drifting
A.7.4 · Quality of data for AI systemsLineage and quality checks current · last check 08:00
Passing
A defensible, time-stamped trail across every AI system in scopeAudit trail
Collect once, reuse everywhere

Your ISO 27001 work becomes a head start on ISO 42001

ISO 42001 reuses the harmonized management-system structure: context, leadership, planning, support, operation, evaluation, improvement. Compyl cross-maps each control so a large share of your AIMS is satisfied by evidence you already collect.

  • One control mapped to its equivalent across 70+ frameworks
  • Collect evidence once and reuse it across every report
  • See instantly how your ISMS translates to an AIMS
  • Add ISO 42001 without starting the program over
One ISO 42001 controlA.7.5 · Data provenanceOrigin, lineage, and processing history recorded for every training dataset · evidence from Snowflake and the data catalog1 piece of evidence
Also satisfies
ISO 27001A.5.12 Classification · A.8.10 Information deletion
Satisfied
SOC 2CC6.1 · PI1.1 Data integrity and access
Satisfied
GDPRArt 30 Records of processing · Art 5 Principles
Satisfied
NIST AI RMFMAP 2.3 · MEASURE 2.1 Data documentation
Satisfied
+ 70 more frameworks cross-mapped automatically
Why now

One standard, two reasons to act

The regulatory clock and the certification cycle run on different timelines. Compyl keeps you ready for both.

The EU AI Act

Obligations landing in phases

The Act is law across the EU, with obligations phased in by risk class. ISO 42001 is voluntary and gives no legal presumption of conformity, but it is a strong, widely used way to show the governance the Act expects.

August 2025
General-purpose AI obligations
December 2027
High-risk system obligations (Annex III)
With Compyl
Controls and evidence mapped to both
Certification 3-year cycle

Certifiable, like ISO 27001

An accredited body audits your AIMS in two stages, then returns for surveillance audits each year of the three-year cycle.

Stage 1 and 2
Documentation review, then implementation audit
Surveillance
Annual audits through the cycle
With Compyl
A living AIMS, not a pre-audit scramble
Why Compyl for ISO 42001

Not a checkbox tool, a continuous compliance engine

Plenty of tools store an AI policy. Compyl runs the whole AIMS, impact assessments, life-cycle evidence, vendor AI oversight, and a posture you can publish.

01

Continuous, not point-in-time

Annex A controls, assessments, and evidence stay live year-round, so audits never catch you out.

02

One connected system

Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.

03

125+ integrations

Pulls live data from the stack you already run, so posture reflects reality, not snapshots.

04

Agentic AI

AI maps controls, drafts remediations, and offloads busywork, your team stays in control.

05

Multi-framework by design

ISO 42001 evidence carries over from ISO 27001, SOC 2, and GDPR without redoing the work.

Beyond ISO 42001

Govern AI once, alongside every framework you already hold

Compyl cross-maps controls so ISO 42001 builds on the ISMS you have, and carries into the next framework on your roadmap.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
38
Annex A controls mapped to live evidence
125+
Native integrations feeding evidence automatically
Real-time
Evidence collection, no manual screenshots
Year-round
Certification readiness instead of a pre-audit scramble

“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”

JSJon SeniorCTO · via G2

What is ISO 42001, and how does Compyl help?

ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems (AIMS), published in December 2023. It defines how an organization governs the development and use of AI responsibly: leadership accountability, AI risk and impact assessments, life-cycle controls, data governance, and continuous improvement, with Annex A controls organized into nine categories. Like ISO 27001, it is certifiable: an accredited body audits your AIMS, and certification runs on a three-year cycle with surveillance audits. Compyl runs your AIMS on the same cross-mapped control library as ISO 27001, so existing ISMS evidence counts from day one, and adds AI risk and impact assessments, life-cycle evidence from your ML stack, policy management, and vendor AI oversight on one platform.

ISO 42001 vs ISO 27001

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 governs information security; ISO 42001 governs artificial intelligence. They share the same management-system skeleton, which is why they pair so well.

ISO 27001ISO 42001With Compyl
ScopeInformation security management system (ISMS)AI management system (AIMS)Both on one cross-mapped control library
Annex A93 controls in 4 themes38 controls in 9 categoriesShared controls satisfied once
Core assessmentInformation security risk assessmentAI risk and AI system impact assessmentsRun in the same risk module
CertificationAccredited audit, 3-year cycleAccredited audit, 3-year cycleOne living evidence pack for both
Adding it later—Reuses the harmonized structure of your ISMSA fraction of the effort of starting from scratch
FAQ

ISO 42001 questions, answered

What is ISO 42001 in simple terms?

ISO 42001 is the international standard that tells an organization how to govern its use of artificial intelligence responsibly. It works like ISO 27001 but for AI: you build a management system (an AIMS) with policies, risk assessments, controls, and evidence, and an accredited auditor certifies it.

Who needs ISO 42001?

Any organization that develops AI products, embeds AI features, or uses AI in ways that affect customers. Software companies with AI features, regulated industries deploying AI, and vendors selling into enterprises that ask about AI governance are the earliest adopters.

Is ISO 42001 mandatory under the EU AI Act?

No, ISO 42001 is voluntary. The EU AI Act is the law, and ISO 42001 is not a harmonized standard, so certification gives no presumption of conformity. It is still a strong way to evidence the governance, risk management, and documentation practices the Act expects. Many organizations pursue both together because the work overlaps heavily.

How long does ISO 42001 certification take?

It depends on your starting point. Organizations with an existing ISO 27001 ISMS typically move fastest because the management-system structure and much of the evidence already exist. On a platform with cross-mapped controls, readiness is usually a matter of months rather than a year.

How much does ISO 42001 certification cost?

Total cost includes your readiness work, the platform you run your AIMS on, and the certification body’s audit fees. The biggest cost driver is duplicated effort, which is why running ISO 42001 on the same control library as ISO 27001 matters: evidence collected once satisfies both. Compyl includes all 70+ frameworks, so adding ISO 42001 is not a new line item.

What is the difference between ISO 42001 and ISO 27001?

ISO 27001 governs information security; ISO 42001 governs artificial intelligence. They share the same management-system skeleton, which is why they pair so well: ISO 27001 protects the data, ISO 42001 governs what your AI does with it.

Does Compyl support ISO 42001?

Yes. ISO 42001 is one of the 70+ frameworks in Compyl’s cross-mapped control library, with evidence blueprints, AI risk assessment workflows, policy management, and vendor AI oversight on the same platform as the rest of your GRC program.

When do EU AI Act high-risk obligations apply now?

After the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on July 27, 2026, obligations for Annex III high-risk systems apply from December 2, 2027. Annex I systems embedded in regulated products follow from August 2, 2028. The original date was August 2, 2026.

Does ISO 42001 certification prove EU AI Act compliance?

No. ISO/IEC 42001 is not a harmonized standard under the AI Act, so certification gives no legal presumption of conformity. It helps evidence the governance, risk and documentation practices the Act expects, but compliance still has to be shown requirement by requirement.

What is ISO/IEC 42006?

ISO/IEC 42006:2025, published in July 2025, sets requirements for the certification bodies that audit ISO/IEC 42001 AI management systems, including auditor competence and audit time. Choosing an accredited body that works to 42006 makes your certificate more credible.

How do you do an AI impact assessment for ISO 42001?

ISO 42001 Annex A calls for AI system impact assessments. ISO/IEC 42005:2025 is the companion guidance for assessing effects on individuals, groups and society across the AI lifecycle, from design to post-deployment monitoring.

GRC your way

Govern AI on the platform you already trust

One control library. Your ISMS evidence, working toward your AIMS. See how Compyl gets you to ISO 42001 without starting over.

Last reviewed September 2026 by the Compyl GRC team
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies