AIAI Governance StackFree kit

ISO/IEC 42001

Certifiable standard

What ISO/IEC 42001 requires

ISO/IEC 42001:2023 is the first international standard specifying requirements for an AI Management System (AIMS). It follows the familiar ISO management-system pattern — context, leadership, planning, support, operation, performance evaluation, improvement — which means organisations already certified to ISO 27001 will recognise the structure and can often reuse much of the governance scaffolding. Its distinguishing value is that it is certifiable: an accredited body can audit and issue a certificate, which is increasingly what enterprise customers and procurement teams ask for as evidence of responsible AI practice.

Who it applies to

Organisations wanting third-party-auditable proof of an AI management system, often driven by customer or procurement demand.

35 tools that map to ISO/IEC 42001

Grouped by what the tool actually does, because a documentation platform and a runtime guardrail both claiming support are solving different halves of the problem.

Policy, Compliance & GRC (32)

Govern your AI and automate GRC for EU AI Act and ISO 42001 compliance

EU AI ActISO/IEC 42001NIST AI RMF

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

ISO/IEC 42001EU AI ActNIST AI RMF

Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001

NIST AI RMFISO/IEC 42001GDPR

European compliance automation platform with an ISO 42001 and EU AI Act AI management system

EU AI ActISO/IEC 42001GDPR

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

ISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

NIST AI RMFISO/IEC 42001EU AI Act

AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance

EU AI ActNIST AI RMFISO/IEC 42001

Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise agentic GRC platform running on structured live-systems data, ISO 42001 certified

NIST AI RMFISO/IEC 42001GDPR

Security compliance automation vendor with ISO 42001 and real-time AI agent governance

ISO/IEC 42001EU AI ActSOC 2

European AI Management System built on ISO/IEC 42001 for AI Act compliance

EU AI ActISO/IEC 42001NIST AI RMF

Enabling enterprise AI by quantifying its quality and risk

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise AI governance and enablement across global regulatory frameworks

EU AI ActNIST AI RMFISO/IEC 42001

Govern all your AI in one connected graph

EU AI ActNIST AI RMFISO/IEC 42001

End-to-end AI governance with registry, risk assessment and automated compliance

EU AI ActNIST AI RMFISO/IEC 42001

AI-powered GRC platform, rebranded from AuditBoard, with AI governance via the FairNow acquisition

SOC 2NIST AI RMFISO/IEC 42001

No-code GRC platform with AI governance agents that triage and assess AI use cases

EU AI ActNIST AI RMFISO/IEC 42001

AI inventory, assessment and monitoring built on OneTrust's privacy and trust platform

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise AI governance to operationalize oversight, risk and compliance

EU AI ActNIST AI RMFISO/IEC 42001

Board governance and GRC platform embedding AI risk and compliance into enterprise oversight

EU AI ActNIST AI RMFISO/IEC 42001

AI governance platform to discover, assess and manage AI risk at scale

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise AI governance and model lifecycle automation as a system of record

EU AI ActNIST AI RMFISO/IEC 42001

Automated AI governance and EU AI Act compliance workflow management

EU AI ActNIST AI RMFISO/IEC 42001

Model governance and ML assurance for highly regulated industries

NIST AI RMFEU AI ActISO/IEC 42001

AI governance embedded in an integrated risk management platform

EU AI ActNIST AI RMFISO/IEC 42001

AI governance, risk and compliance with rapid audits, now operating as Asenion

EU AI ActNIST AI RMFISO/IEC 42001

AI-first connected GRC platform with a built-in AI governance and trust framework

NIST AI RMFISO/IEC 42001SOC 2

AI governance platform for regulated enterprises to manage risk and compliance

EU AI ActNIST AI RMFISO/IEC 42001

AI-powered GRC platform unifying audit, risk and controls with connected reporting

SOC 2ISO/IEC 42001

Ethical AI governance and use-case risk assessment, now part of Asenion

EU AI ActNIST AI RMFISO/IEC 42001

AI governance, risk and compliance platform for tracking AI use cases, models and vendors

EU AI ActNIST AI RMFISO/IEC 42001

All-in-one enterprise AI governance for ethical, transparent and compliant AI

EU AI ActNIST AI RMFISO/IEC 42001

Observability & Monitoring (1)

AI quality, testing, and monitoring platform for evaluating and safeguarding models in production

ISO/IEC 42001GDPRHIPAAOpen-source

Red-Teaming & AI Security (1)

End-to-end AI security and governance platform to discover, monitor, red-team and prove enterprise AI

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise Incumbents (1)

Lifecycle governance, risk and compliance for models and agentic AI, built on IBM's GRC heritage

EU AI ActNIST AI RMFISO/IEC 42001

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.