ISO/IEC 42001
ISO/IEC 42001:2023 defines requirements for an AI Management System (AIMS) — an organizational, policy-driven framework rather than a set of technical controls. Gadriel Code renders the standard as a structured review workbook.
Related: Compliance overview · NIST AI RMF · EU AI Act.
At a glance
| Property | Value |
|---|---|
| Slug | iso-42001 |
| Aliases | iso42001, iso-42001-ams |
| Controls | 19 |
| Manual-only | 19 (fully manual) |
| Machine-assessable | 0 |
| Direct mapping key | iso_42001 (present, but not verdict-driving in v1) |
All-manual in v1. Existing iso_42001 data in the GVL corpus is largely
mislabeled ISO 27001 content and is deliberately not used to drive
verdicts. Every control renders as NOT ASSESSABLE with its narrative.
Generating the report
bashgadriel code report --compliance iso-42001
Outputs: .security/compliance/iso-42001.{md,typ,pdf}.
Using the report
ISO/IEC 42001 is best served by:
- Pairing this workbook with the NIST AI RMF and EU AI Act reports for technical evidence.
- Attaching policy artifacts (AI policy, roles & responsibilities, lifecycle procedures) as external evidence during your management-system audit.
A future release will wire predicated evidence in behind selected controls; until then, treat the ISO 42001 file as a governance workbook, not a technical verdict.
