UprootSecurity
Book a demo

ISO/IEC 42001:2023 · AI Management System · Certification

FRAMEWORK

Govern your AI likeyou govern your infra.

ISO 42001 is the first management-system standard for AI. Uproot runs it against your real model lifecycle impact assessments, data provenance, and eval gates proven, not just claimed.

Start ISO 42001Talk to a governance lead

The first certifiable AI standard

·

Builds on your ISO 27001 management system

app.uproot.security · /framework/iso-42001
42001AIMS

acme-ai · ISO 42001:2023

AIMS · 6 AI systems in scope

79%

cert-ready

28 in place8 in progress2 open

Annex A · control objectives

38 controls

A.2

AI policy

A.2.1–A.2.4

100%

A.5

Impact assessment

A.5.1–A.5.5

82%

A.6

AI system life cycle

A.6.1–A.6.2

74%

A.7

Data for AI systems

A.7.1–A.7.6

71%

A.10

Third-party & suppliers · models

A.10.1–A.10.4

68%

AI systems

6 registered

Cert body

Schellman

Open impacts

2

Impact assessment triggered

A new model hit the registry. A.5.2 impact assessment was opened and routed to its owner.

Annex A controls

38

Across nine control objectives covering AI policy, lifecycle, data, transparency, and third parties.

Control objectives

9

From AI policy and internal organization through impact, lifecycle, data, and the use of AI systems.

Published

2023

The world's first certifiable AI management system standard net-new, not a profile of something older.

Certification cycle

3years

Stage 1 + Stage 2, annual surveillance, recertification at year three like ISO 27001.

Builds on

27001

Same management-system backbone. If you run an ISMS, the AIMS slots straight on top.

Annex A · 2023

Responsible AI, expressed as controls you can actually operate.

ISO 42001 turns "responsible AI" from a values statement into a management system: policy, impact assessment, a governed lifecycle, data provenance, and third-party model oversight. Uproot proves each against your real ML stack.

A.2
A.2

AI policy

A documented AI policy aligned to your objectives and risk appetite the foundation the AIMS hangs from.

A.2.2 AI policy · A.2.3 Alignment · A.2.4 Review
ControlsA.2.1–A.2.4
A.5

Impact assessment

Assess each AI system's impact on individuals and society fairness, safety, consequences before and during deployment.

A.5.2 Impact assessment · A.5.4 Individuals · A.5.5 Society
ControlsA.5.1–A.5.5
A.6

AI system life cycle

Objectives, design, validation, deployment, and monitoring where the model registry and CI gates earn their keep.

A.6.1.2 Objectives · A.6.2.4 V&V · A.6.2.6 Operation
ControlsA.6.1–A.6.2
A.7

Data for AI systems

Provenance, quality, and governance of training data knowing where it came from and whether it fits.

A.7.2 Provenance · A.7.4 Quality · A.7.5 Preparation
ControlsA.7.1–A.7.6
A.10

Third-party & suppliers

Governing foundation models, APIs, and suppliers across your AI supply chain.

A.10.2 Suppliers · A.10.3 Customers · A.10.4 Responsibilities
ControlsA.10.1–A.10.4
One control, end to end

"We test our models" is a claim. A.6.2.4 is the proof.

Verification and validation is where responsible-AI intentions meet the pipeline. Here's how Uproot turns your eval gates into continuous, certifiable evidence.

A.6.2.4 AI system verification & validation

AI systems must be verified and validated against their requirements before and during use including performance, robustness, and bias testing with results documented. The control that separates a governed model from a hopeful one.

"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."

— Yogesh Narayan, CTO

A.6.2.4 · VERIFICATION & VALIDATION

AI systems are verified & validated

Last evidenced 09:14:02 UTC · 6 AI systems · sha256 verified

In place
01

The control

What Annex A.6.2.4 asks for

“The organization shall define and document verification and validation measures for the AI system and specify the criteria… against the requirements throughout the AI system life cycle.”
02

Your ML stack

What we read from your systems

Uproot points at the systems that actually gate models the registry, the eval jobs, the deploy pipeline.

mlflow ·model.registrygithub ·eval.workfloww&b ·eval.runsargo ·deploy.gate
03

Evidence collected

Eval results, gates, and lineage

Eval coverage, pass thresholds, and the link between a deployed model version and its passing run are pulled from source, hashed, and stored.

eval suites ·6 / 6 modelsbias tests ·enforceddeploy gate ·blocking0 ungated releases
04

For the auditor

Read-only portal, mapped to the SoA

The certification body opens A.6.2.4 and sees every in-scope model, its eval history, and proof that the deploy gate is blocking already linked to your Statement of Applicability.

SoA · included  ·  Owner· ML Platform  ·  Nonconformities · 0

NIST AI RMF MEASUREEU AI Act Art. 15
Path to certification

From AI inventory to a certified management system.

A path for a team that already runs ISO 27001 with Uproot. Net-new management systems take a little longer to stand up the clauses.

Week 0

Inventory AI systems

Register every model and AI feature in scope. Uproot discovers them from your model registry and deployment pipeline.

Week 1–2

Set AI policy & scope

AI policy, roles, and AIMS scope defined. The Annex A Statement of Applicability is generated.

Week 3–6

Impact & risk

Impact assessments run per system; AI risks assessed and treated. Data provenance and eval gates wired to evidence.

Week 7–9

Stage 1 audit

The body reviews your AIMS documentation through the read-only portal. Findings closed before Stage 2.

5

Week 12–13

Stage 2 audit

The body tests that controls operate across the AI lifecycle. Evidence is continuous nothing to assemble.

6

Year 1–3

Certified + surveillance

Certificate issued. Surveillance audits read the same live evidence. Recert at year three is routine.

The slideware way
  • ×

    An “AI principles” page on the website with nothing operational behind it

  • ×

    Impact assessments done once, in a doc, never revisited when the model changes

  • ×

    No record of which model version is in production or whether it passed its evals

  • ×

    Foundation-model suppliers used with no governance or allocated responsibility

With Uproot
  • An AI policy tied to operating controls across the real model lifecycle

  • Impact assessments triggered automatically when a model enters or changes scope

  • Every deployed model linked to its passing eval run, gates proven blocking

  • Third-party models inventoried and governed, responsibilities documented

Evidence map

Where AI governance actually lives. Uproot reads it there.

A partial map of the AIMS evidence Uproot pulls from your ML and data stack registries, pipelines, datasets, and suppliers.

A.6

Lifecycle & evals

  • MLflow · model registry

    6

  • GitHub · eval workflow

    gated

  • W&B · eval runs

    live

  • Argo · deploy gate

    blocking

A.7

Data for AI

  • Dataset registry

    provenance

  • Snowflake · lineage

    tracked

  • Data quality checks

    CI

  • Consent / licensing

    recorded

A.5

Impact & risk

  • Impact assessments

    6

  • AI risk register

    live

  • Bias / fairness tests

    enforced

  • Human-oversight log

    on file

A.10

Suppliers

  • Foundation models

    3

  • API supplier DPAs

    signed

  • Model cards on file

    linked

  • Responsibility matrix

    live

Certification bodies

Among the first bodies accredited for AI management systems.

ISO 42001 is new, and the accredited body pool is growing fast. Uproot is body-agnostic and gives yours a read-only portal scoped to your AIMS the same handoff that works for ISO 27001.

BSI

ukas

Schellman

anab

TÜV SÜD

dakks

DNV

accredia

A-LIGN

anab

Bureau Veritas

ukas

SGS

ukas

Coalfire

anab

A-LIGN AI

anab

Mastermind

anab

NQA

ukas

+ growing

on request

ISO 42001, plainly

Questions we get every week. Answered the way an engineer would.

What is ISO 42001?+

It's the first certifiable management-system standard for artificial intelligence an "AIMS." It governs how you develop, deploy, and oversee AI systems responsibly, the way ISO 27001 governs information security.

Who needs it?+

Any organization building or meaningfully using AI systems, especially those selling to enterprises or operating in regulated markets. It's quickly becoming the artifact procurement teams ask for alongside SOC 2.

How does it relate to the EU AI Act?+

They're complementary. The EU AI Act is law with risk-tiered obligations; ISO 42001 is a voluntary management system that demonstrates many of those practices. Running the AIMS makes Act readiness far easier to evidence.

Do I need ISO 27001 first?+

No, but it helps. ISO 42001 shares the same management-system clauses (4–10). If you already run an ISMS with Uproot, the AIMS reuses that backbone and a lot of the evidence.

What's an AI impact assessment?+

An assessment (Annex A.5) of how an AI system affects individuals and society fairness, safety, and consequences. Uproot triggers one whenever a model enters or materially changes scope, and tracks it to closure.

How many controls are there?+

Annex A defines 38 controls across nine control objectives. As with ISO 27001, you justify applicability in a Statement of Applicability which Uproot generates from your real AI inventory.

Make responsible AI provable.

Register your AI systems, generate impact assessments, and prove your eval gates and data provenance continuously. Invite your certification body when Stage 2 is a formality.

Start ISO 42001Talk to a governance lead
$uproot init --framework iso42001
discovering AI systems6
building Annex A SoA · 38 controlsok
28 in place · impact assessments queued79%
AIMS scaffolded in 4m 06slive