The world's first certifiable AI Management System
What is ISO 42001?
ISO/IEC 42001:2023, published in December 2023, is the world's first international management-system standard for artificial intelligence. It defines requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS) — modeled on the pattern used by ISO 27001 for information security and ISO 9001 for quality.
The standard contains a set of management-system clauses (4–10) covering context, leadership, planning, support, operation, performance evaluation, and improvement, plus a normative Annex A with 38 controls covering the AI lifecycle from policies through third-party providers.
Who needs ISO 42001
Any organization developing, providing, or using AI systems at material scale. The standard is rapidly becoming the de facto demonstration of mature AI governance for enterprise buyers, regulated industries (financial services, healthcare, public sector), and as a readiness signal for the EU AI Act, which references ISO 42001 as evidence of due diligence.
How episki helps
episki ships ISO 42001 alongside a dedicated AI Governance module: an agent and AI use-case registry with allowlists and safety floors, AI-specific risk treatments wired to controls and evidence, and confidence-scored registry upkeep. episki governs its own agents through the same module — every model call is attributed to a surface and an operation, so the AIMS covers the platform you are running it on. Crosswalks to ISO 27001 and the NIST AI RMF are derived through the SCF hub. Start a free trial or book a demo.
ISO 42001 outcomes with episki
Why teams choose episki for ISO 42001
- Inventory across vendors, internal builds, and shadow AI
- Risk tier per use case using ISO 42001 criteria
- Lifecycle stage from concept to retirement
- AI-specific risk taxonomy
- Acceptance, mitigation, transfer, avoid paths
- Tied to controls and ongoing monitoring
- Policies, leadership, resources, lifecycle controls
- Data quality, fairness, interpretability
- Third-party AI provider obligations
ISO 42001 readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ AI use-case inventory and risk tiering
- ✓ Annex A control selection per use case
- ✓ AI ethics and acceptable use policy
- ✓ AI risk register with treatment plans
- ✓ Third-party AI provider (sub-processor) assessment
- ✓ Ongoing AI performance and incident monitoring