AI Governance
Available nowISO/IEC 42001 · 2023
ISO/IEC 42001:2023 is the international standard for an AI Management System (AIMS). It covers the management-system clauses (4-10), including AI risk and impact assessment, plus the Annex A reference controls, the certifiable framework for organizations that build or deploy AI at scale.
65
requirements tracked
Premium
Access
Add-on from $39/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below, all 65 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 65 requirements
- In Keel’s scored scope
- 65 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs ISO/IEC 42001?
- Organizations that want a certifiable, audited AI governance program
- AI providers and deployers asked to prove responsible-AI practices
- Teams already running ISO 27001 who want the AI companion standard
What Keel does
How Keel helps with ISO/IEC 42001
- The management-system clauses plus the Annex A controls as a trackable framework
- Crosswalked to ISO 27001 and your other frameworks, so shared work counts once
- Readiness scoring across the whole standard so nothing slips before certification
Collect once, comply everywhere
ISO/IEC 42001 shares canonical controls with ISO 9001, ISO/IEC 27001 and NIST AI Risk Management Framework and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding ISO/IEC 42001 rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls no shared canonical controls
- PCI DSS no shared canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- FedRAMP Consolidated Rules shares canonical controls
- NIST SP 800-171 shares canonical controls
- HIPAA shares canonical controls
- GDPR no shared canonical controls
- COPPA shares canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- PIPEDA no shared canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials shares canonical controls
- NIST AI Risk Management Framework shares canonical controls
- EU AI Act shares canonical controls
- ESG Essentials shares canonical controls
- US Employment Law - Federal Baseline no shared canonical controls
A framework is lit when at least one canonical control satisfies both ISO/IEC 42001 and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 18 of 26 are lit here.
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks