Why now – Palantir alternatives for Europe: what 'sovereign' actually means, and how European public bodies are decidingRegister →
ISO/IEC 42001

AI governance you can certify because the runtime enforces it

ISO/IEC 42001 is the first international standard for managing AI responsibly. Scrydon turns its controls into runtime behaviour — guardrails, oversight, logging, supply-chain choice — and produces the evidence an AIMS audit expects, while certification of your programme remains yours.

Written for the security, risk and data protection teams who have to evidence this — not just describe it.

What it is

ISO/IEC 42001 (ISO 42001)

ISO/IEC 42001:2023 is the first international, certifiable standard for an artificial intelligence management system (AIMS). Published in December 2023, it follows the same harmonised structure as ISO 27001: an organisation sets AI policy and objectives, assesses AI-specific risks and the impacts of its AI systems across their lifecycle, and operates, monitors and continually improves its controls. Annex A supplies a reference set of controls covering AI policy, internal organisation, resources, impact assessment, the AI system lifecycle, data for AI, information for interested parties, use of AI systems and third-party relationships, with implementation guidance in Annex B. It is deliberately compatible with the EU AI Act's expectations on risk management, data governance, logging, human oversight and transparency, which is why many organisations use it as the management-system backbone of their conformity narrative — although it is not itself an AI Act harmonised standard and does not confer a presumption of conformity. Scrydon operates its own AIMS aligned with ISO/IEC 42001 and publishes its status on the compliance hub; this page is about how the platform supports the AIMS you run.
At a glance
Jurisdiction
International
Applies to
Any organisation that develops, provides or uses AI systems and wants a certifiable management system for doing so responsibly — providers and deployers preparing for the EU AI Act in particular.
Talk to us
How we help

How Scrydon helps you comply

Controls are built into the runtime, so compliance is something you can demonstrate with evidence drawn from the platform itself — not assembled after the fact.

Guardrails on AI system operation

The DLP guardrails engine scans model inputs and outputs for personal data and hallucination, with regex and JSON gates that block, redact or quarantine. This gives the operation and monitoring controls in Annex A's AI-system-lifecycle family something enforceable to point to: the behaviour of a model in production is constrained by policy, not just described in a procedure.

Human oversight through policy-as-code

A single policy-as-code decision point authorises actions across the application and data planes with fail-closed defaults, so approval gates, human-in-the-loop checkpoints and prohibited uses are enforced by the runtime. This supports Annex A's controls on responsible use of AI and on defining and enforcing the objectives of an AI system, and it produces a record every time oversight is exercised.

Lifecycle logging and traceability

Every actor, decision and agent action lands in an immutable, queryable audit log with redaction and retention controls. That log evidences the lifecycle controls an AIMS audit samples — verification, validation, deployment, operation and monitoring — and doubles as the event logging the EU AI Act asks of high-risk systems.

Data for AI: clearance and classification

Document clearance and classification decide which data may reach which model and context, and access is policy-governed and logged. This supports Annex A's data-for-AI controls on data provenance, quality and preparation and lets you show exactly what data an AI system was permitted to use.

Third-party relationships and framework evidence packs

External AI vendors are opt-in and you choose where models run, so third-party and supplier controls are decisions you take and can evidence rather than defaults you inherit. Evidence packs then map platform controls to ISO 42001 Annex A alongside ISO 27001 and the EU AI Act, giving your AIMS documentation a control-by-control starting point.

Key requirements

What ISO 42001 asks of you

  • Set an AI policy and objectives, with leadership accountability for responsible AI.
  • Assess AI-specific risks and the impacts of AI systems on individuals, groups and society.
  • Govern the AI system lifecycle: requirements, design, verification, deployment, operation, monitoring and retirement.
  • Manage data for AI — provenance, quality and preparation — and document AI systems for interested parties.
  • Provide resources, roles and competence, and control the use of AI systems and third-party suppliers.
  • Monitor, measure, internally audit and management-review the AIMS.
  • Continually improve, and where certification is sought, pass certification and surveillance audits.
Where the line sits

What we provide, and what stays yours

No vendor can be compliant on your behalf. We build the controls into the platform and produce the evidence; the assessment of your own deployment stays with you. Here is the split, stated plainly, so it does not surface late in a security review.

Scrydon provides

  • Controls enforced in the runtime by default, rather than left to configuration.
  • An immutable, queryable record of what ran, on whose authority, and against which data.
  • Evidence packs mapped to the obligations set out on this page.
  • Documented architecture and data flows your assessors can read.
  • Deployment inside your own perimeter — up to fully disconnected.

You remain responsible for

  • Classifying your own systems and data under the framework.
  • Your risk assessment, data protection impact assessment and conformity assessment.
  • Who you grant access to, and on what basis.
  • Your incident response and reporting obligations.
  • The operational security of the environment you run it in.
FAQ

Frequently asked questions

Is Scrydon ISO 42001 certified?+
Not yet. Scrydon operates an AI management system aligned with ISO/IEC 42001, alongside its ISO 27001-aligned ISMS, and publishes the programme's status on the compliance hub — internal audit first, external certification audits next. A certification claim will appear there only once external audits are complete. Note that ISO 42001 certifies an organisation's AIMS and its declared scope; it never certifies a product, so your own certificate covers your AIMS, and Scrydon's role is to make the controls inside it enforceable and demonstrable.
How does ISO 42001 relate to the EU AI Act?+
They are complementary. The AI Act is law and sets binding, risk-tiered obligations; ISO 42001 is a voluntary management-system standard that organises how you meet obligations like risk management, data governance, logging, human oversight and transparency. Many providers and deployers use an ISO 42001 AIMS as the backbone of their AI Act conformity narrative, but the standard is not an AI Act harmonised standard and does not confer a presumption of conformity. Scrydon's evidence packs map the same controls to both, so the work is done once.
Which Annex A control families does the platform support?+
Chiefly the AI-system-lifecycle, data-for-AI, use-of-AI-systems and third-party families: guardrails and policy-as-code for operation, monitoring and responsible use; the immutable audit log for verification, deployment and operational records; document clearance and classification for data provenance and quality; and opt-in vendors and model placement for supplier relationships. Policy, roles, competence and impact-assessment controls are organisational and remain yours, though the platform supplies the evidence they draw on.
How does Scrydon help with AI impact assessment?+
An impact assessment needs to know what data an AI system may use, what it is allowed to do, who can trigger it and what it actually did. Classification and clearance answer the first, policy-as-code the second and third, and the audit log the last, with agent actions recorded alongside human ones. The assessment itself — and the judgement about impacts on individuals, groups and society — remains your responsibility, but it can be grounded in the system's real behaviour rather than a description of it.
Can we run ISO 42001 and ISO 27001 as one management system?+
Yes, and most organisations do. ISO 42001 uses the same harmonised structure as ISO 27001, so scope, risk process, internal audit and management review can be shared, with the AI-specific controls layered on. Scrydon's evidence packs treat the two together, so a control such as the audit log or key custody is mapped once and referenced by both.
Does ISO 42001 cover agentic AI, and does the platform?+
The standard applies to AI systems generally, and its lifecycle, use and monitoring controls apply just as much when the system acts autonomously. On Scrydon, agent actions pass through the same policy-as-code decision point and land in the same audit log as human ones, with guardrails on their inputs and outputs, so agentic workloads inherit the same governance and produce the same evidence.
What evidence does an AIMS audit expect, and what does Scrydon provide?+
Auditors look for a documented AIMS, an AI inventory and impact assessments, lifecycle records, and proof that controls operate. Scrydon contributes the last two: time-bounded, queryable audit records of decisions, guardrail actions and oversight events, inspectable policy and classification configuration, and evidence packs mapping those to Annex A. Policy documents, roles and the impact assessments themselves are yours to author.

Or write to us

Tell us what you are working on and who should reply. A person reads it and replies within one business day.

We only use these details to reply to you. Privacy policy

Prefer to write? Email hello [at] scrydon.com and we will get back to you.