Skip to main content
NOVACompliance

Frameworks

Available now

ISO/IEC 42001

The management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.

Overview

ISO/IEC 42001 specifies requirements for an artificial intelligence management system, addressing how an organisation governs the development, provision and use of AI systems.

It follows the same management system structure as ISO/IEC 27001, which allows organisations to extend an existing programme rather than start a new one. Its distinguishing content covers AI-specific impact assessment, lifecycle governance and the responsibilities attached to automated outputs.

It is increasingly relevant to organisations that embed AI features into products or rely on AI in decision workflows.

Who this is for

  • Organisations building or embedding AI capability into products
  • Teams that must evidence human oversight of automated outputs
  • Existing ISO/IEC 27001 holders extending governance to AI systems

Governance areas

AI policy and roles

Governance intent, accountability and the roles that approve AI use.

Impact assessment

Assessing effects of AI systems on individuals, groups and the organisation.

Lifecycle governance

Requirements across design, development, deployment, monitoring and retirement.

Data governance

Provenance, quality and appropriateness of the data used by AI systems.

Human oversight

Where a person must review, approve or override an automated output.

How NOVA supports this framework

  • Maintain AI system inventory entries with owner, purpose and lifecycle stage
  • Hold impact assessments as reviewed evidence against the relevant controls
  • Document where human approval is mandatory in each AI-assisted workflow
  • Reuse the ISO/IEC 27001 management system structure already in place

Controls and evidence focus

  • AI system inventory records with approval history
  • Impact assessment documents with reviewer and date
  • Records of human review or override on automated outputs
  • Data provenance and quality assessments

Cross-framework reuse

Shares the management system clauses with ISO/IEC 27001

Human oversight records support the responsible AI position published in the Trust Centre

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Structure

AI management system areas

ISO/IEC 42001 follows the familiar management system structure and adds requirements specific to the governance of AI systems across their lifecycle.

Policy

AI policy and roles

Governance intent, accountable roles and the approval path for putting an AI system into use.

Inventory

AI system inventory

Each AI system recorded with owner, purpose, lifecycle stage and approval history.

Impact

AI system impact assessment

Assessment of effects on individuals, groups and the organisation, reviewed and dated.

Data

Data governance

Provenance, quality and appropriateness of data used for training, tuning and operation.

Lifecycle

Lifecycle controls

Requirements applied at design, development, deployment, monitoring and retirement.

Oversight

Human oversight

Defined points where a person must review, approve or override an automated output.

Evidence

Typical evidence held in NOVA

Oversight is the distinguishing evidence class: the record must show where a person intervened, not only that a policy said they could.

ArtefactTypical sourceExpected cadence
AI system inventory entryNOVA AI registerOn change
Impact assessmentManual upload with reviewerPer system, on change
Human review or override recordNOVA workflow recordPer decision
Data provenance assessmentManual uploadPer dataset
Model or prompt change approvalSource control or ticketingPer change
Monitoring reviewNOVA control recordQuarterly

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

How it runs

Working through ISO/IEC 42001 in NOVA

  1. Step 1

    Inventory

    Identify every AI system in development or use, with an accountable owner for each.

  2. Step 2

    Assess impact

    Complete an impact assessment per system and have it reviewed before deployment.

  3. Step 3

    Set oversight points

    Document where human approval is mandatory in each AI-assisted workflow.

  4. Step 4

    Extend the ISMS

    Reuse the existing management system clauses instead of standing up a second programme.

  5. Step 5

    Monitor and review

    Keep monitoring, review and retirement records current as systems change.

Questions

ISO 42001 questions we are asked

Do we need ISO/IEC 27001 first?
It is not a prerequisite, but the shared clause structure means organisations already certified to ISO/IEC 27001 typically extend that management system rather than build a new one.
Does the NOVA assistant make compliance decisions?
No. The assistant drafts and summarises. NOVA supports the readiness decision. Final launch and risk decisions remain human decisions, and those approvals are recorded.
What counts as an AI system for the inventory?
Any system your organisation develops, provides or uses where automated output influences a decision or a product behaviour. The inventory records purpose and lifecycle stage for each.

Pricing

Plans that cover ISO 42001

Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.

Launch

AUD $99 /month

A first certification or attestation programme run properly from the start.

  • One activated framework
  • Control ownership and review cadence
  • Evidence mapping and reviewer validation
  • Policy versioning and approval
Compare plans

Growth

Most chosen

AUD $249 /month

Multiple frameworks on one shared control set, with reuse across requirements.

  • Multiple activated frameworks
  • Cross-framework control and evidence reuse
  • Risk register with treatment and acceptance
  • GitHub evidence connector
Compare plans

Professional

AUD $499 /month

Assurance-grade operation with external review workflows included.

  • Everything in Growth
  • Auditor Portal with scoped engagement access
  • Trust Centre publication
  • Asset register and classification
Compare plans

Enterprise

On request

Quoted per organisation against scope, users and assurance requirements.

  • Everything in Business
  • Scope defined per organisation
  • Commercial terms agreed with Eredox
  • Structured onboarding programme
Compare plans

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

Getting started

How to start with ISO 42001

Four steps from an empty workspace to a reviewable readiness position.

  1. Step 1

    Activate the framework

    Create the workspace and activate ISO 42001 so its requirements load into your control set.

  2. Step 2

    Assign control ownership

    Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.

  3. Step 3

    Map and validate evidence

    Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.

  4. Step 4

    Review readiness

    Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

Talk to us

Ask about ISO/IEC 42001

Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Forms are not connected yet. Please email compliance@eredox.com.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.