Frameworks
Available nowISO/IEC 42001
The management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.
Overview
ISO/IEC 42001 specifies requirements for an artificial intelligence management system, addressing how an organisation governs the development, provision and use of AI systems.
It follows the same management system structure as ISO/IEC 27001, which allows organisations to extend an existing programme rather than start a new one. Its distinguishing content covers AI-specific impact assessment, lifecycle governance and the responsibilities attached to automated outputs.
It is increasingly relevant to organisations that embed AI features into products or rely on AI in decision workflows.
Who this is for
- Organisations building or embedding AI capability into products
- Teams that must evidence human oversight of automated outputs
- Existing ISO/IEC 27001 holders extending governance to AI systems
Governance areas
AI policy and roles
Governance intent, accountability and the roles that approve AI use.
Impact assessment
Assessing effects of AI systems on individuals, groups and the organisation.
Lifecycle governance
Requirements across design, development, deployment, monitoring and retirement.
Data governance
Provenance, quality and appropriateness of the data used by AI systems.
Human oversight
Where a person must review, approve or override an automated output.
How NOVA supports this framework
- Maintain AI system inventory entries with owner, purpose and lifecycle stage
- Hold impact assessments as reviewed evidence against the relevant controls
- Document where human approval is mandatory in each AI-assisted workflow
- Reuse the ISO/IEC 27001 management system structure already in place
Controls and evidence focus
- AI system inventory records with approval history
- Impact assessment documents with reviewer and date
- Records of human review or override on automated outputs
- Data provenance and quality assessments
Cross-framework reuse
Shares the management system clauses with ISO/IEC 27001
Human oversight records support the responsible AI position published in the Trust Centre
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
Structure
AI management system areas
ISO/IEC 42001 follows the familiar management system structure and adds requirements specific to the governance of AI systems across their lifecycle.
AI policy and roles
Governance intent, accountable roles and the approval path for putting an AI system into use.
AI system inventory
Each AI system recorded with owner, purpose, lifecycle stage and approval history.
AI system impact assessment
Assessment of effects on individuals, groups and the organisation, reviewed and dated.
Data governance
Provenance, quality and appropriateness of data used for training, tuning and operation.
Lifecycle controls
Requirements applied at design, development, deployment, monitoring and retirement.
Human oversight
Defined points where a person must review, approve or override an automated output.
Evidence
Typical evidence held in NOVA
Oversight is the distinguishing evidence class: the record must show where a person intervened, not only that a policy said they could.
| Artefact | Typical source | Expected cadence |
|---|---|---|
| AI system inventory entry | NOVA AI register | On change |
| Impact assessment | Manual upload with reviewer | Per system, on change |
| Human review or override record | NOVA workflow record | Per decision |
| Data provenance assessment | Manual upload | Per dataset |
| Model or prompt change approval | Source control or ticketing | Per change |
| Monitoring review | NOVA control record | Quarterly |
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
How it runs
Working through ISO/IEC 42001 in NOVA
- Step 1
Inventory
Identify every AI system in development or use, with an accountable owner for each.
- Step 2
Assess impact
Complete an impact assessment per system and have it reviewed before deployment.
- Step 3
Set oversight points
Document where human approval is mandatory in each AI-assisted workflow.
- Step 4
Extend the ISMS
Reuse the existing management system clauses instead of standing up a second programme.
- Step 5
Monitor and review
Keep monitoring, review and retirement records current as systems change.
Questions
ISO 42001 questions we are asked
- Do we need ISO/IEC 27001 first?
- It is not a prerequisite, but the shared clause structure means organisations already certified to ISO/IEC 27001 typically extend that management system rather than build a new one.
- Does the NOVA assistant make compliance decisions?
- No. The assistant drafts and summarises. NOVA supports the readiness decision. Final launch and risk decisions remain human decisions, and those approvals are recorded.
- What counts as an AI system for the inventory?
- Any system your organisation develops, provides or uses where automated output influences a decision or a product behaviour. The inventory records purpose and lifecycle stage for each.
Capabilities that support this framework
Pricing
Plans that cover ISO 42001
Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.
Launch
AUD $99 /month
A first certification or attestation programme run properly from the start.
- One activated framework
- Control ownership and review cadence
- Evidence mapping and reviewer validation
- Policy versioning and approval
Growth
Most chosenAUD $249 /month
Multiple frameworks on one shared control set, with reuse across requirements.
- Multiple activated frameworks
- Cross-framework control and evidence reuse
- Risk register with treatment and acceptance
- GitHub evidence connector
Professional
AUD $499 /month
Assurance-grade operation with external review workflows included.
- Everything in Growth
- Auditor Portal with scoped engagement access
- Trust Centre publication
- Asset register and classification
Enterprise
On request
Quoted per organisation against scope, users and assurance requirements.
- Everything in Business
- Scope defined per organisation
- Commercial terms agreed with Eredox
- Structured onboarding programme
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
Getting started
How to start with ISO 42001
Four steps from an empty workspace to a reviewable readiness position.
- Step 1
Activate the framework
Create the workspace and activate ISO 42001 so its requirements load into your control set.
- Step 2
Assign control ownership
Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.
- Step 3
Map and validate evidence
Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.
- Step 4
Review readiness
Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
Talk to us
Ask about ISO/IEC 42001
Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.