ISO/IEC 42001 (October 2026)
TL;DR: ISO/IEC 42001:2023 is the international standard for an AI management system: a certifiable set of requirements (clauses 4 to 10) and 38 Annex A controls for running AI responsibly. This page explains it and shows where a platform can help you collect evidence. It is not a claim that anyone is certified.
What the standard asks for
Clauses 4 to 10 are the management-system requirements, wrapped in a plan, do, check, act cycle. They follow the same structure as ISO/IEC 27001, so teams that already run an information security management system will recognize it. The right-hand column shows the kind of evidence each clause tends to need.
| Clause | What it requires | Typical evidence |
|---|---|---|
| 4. Context | Identify the internal and external issues that bear on AI, the interested parties, and the scope of the AI management system, including which AI systems are in it. | An inventory of AI systems, models and agents in scope, and who owns each. |
| 5. Leadership | Top management owns the AI policy, assigns roles and accountability, and commits resources. | Policy documents, role assignments and management decisions. These are organizational records, not platform output. |
| 6. Planning | AI risk assessment, AI risk treatment and AI system impact assessment, with objectives for the system. | Risk and impact assessments per system, and the controls chosen to treat them. |
| 7. Support | Resources, competence, awareness, communication and documented information. | Training records and controlled documents. Mostly organizational. |
| 8. Operation | Run the processes: carry out risk treatment and impact assessments, and manage each AI system through its life cycle in production. | Operating records for each system: which model and data it used, what it did, which policy applied, who approved what. |
| 9. Performance evaluation | Monitor and measure the system, run internal audits and hold management reviews. | Monitoring output, usage and cost reports, audit results and review minutes. |
| 10. Improvement | Handle nonconformities with corrective action and improve the system over time. | Incident records, corrective actions and the changes that followed. |
Annex A: 38 controls, nine objectives
Annex A groups its controls under nine objectives. You do not implement all 38 by default: you choose the controls that apply through a Statement of Applicability, driven by your own risk and impact assessments, and justify any you leave out.
- Policies related to AI
- Internal organization
- Resources for AI systems
- Assessing impacts of AI systems
- AI system life cycle
- Data for AI systems
- Information for interested parties
- Use of AI systems
- Third-party and customer relationships
How the platform supports evidence collection
Swfte provides technical controls, governance mechanisms and records that an organization can use as evidence in its own AI management system. The exact posture depends on your use case, jurisdiction, deployment and configuration. Policy, roles, impact assessments and internal audit remain your organization’s work, and a platform cannot make a system certified or compliant on its own.
An inventory you do not have to build by hand
Nexus is designed to surface the agents, model providers and non-human identities in use, including ones no one registered. That gives clause 4 and the asset side of Annex A something concrete to start from.
Swfte NexusOperating records for clause 8
Nexus records agent activity: sessions, tool actions, file changes, dependency installs and token usage, and logs the reason when a policy blocks an action. Those records are the raw material for showing how a system was operated.
AI agent governanceModel access and spend you can attribute
Connect puts model calls behind one endpoint with cost tracking, so use of third-party models and its cost can be shown per team or key rather than reconstructed from invoices.
Swfte ConnectPolicy that changes behavior
Policy-as-code in Nexus is evaluated before an agent action runs, so a documented control and the control in operation can be shown to match.
AI governanceFrequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). ISO and IEC published it in December 2023. It uses the same harmonized structure as ISO/IEC 27001 and ISO 9001, with clauses 4 to 10 as the requirements and an Annex A of controls.
Is ISO/IEC 42001 the same as ISO 27001?
No. ISO/IEC 27001 is for information security management. ISO/IEC 42001 is for managing AI systems responsibly: policy, risk and impact assessment, life cycle, data and third-party relationships. They share a management-system structure, so organizations that already run ISO 27001 can reuse much of the scaffolding.
Is ISO/IEC 42001 mandatory?
No. It is a voluntary, certifiable standard. Customers, procurement teams and regulators may ask for it or for equivalent evidence, and it is often used to structure an organization’s approach to other rules such as the EU AI Act. It does not by itself make a system compliant with any law.
How many controls are in Annex A?
Annex A lists 38 controls grouped under nine objectives. An organization selects the controls that apply to it through a Statement of Applicability, based on its own risk and impact assessments, and justifies the ones it leaves out.
Does Swfte hold an ISO/IEC 42001 certificate?
This page does not claim that Swfte is certified to ISO/IEC 42001. It explains the standard and how the platform can help a customer collect evidence for its own AI management system. Certification is held by an organization for its own management system, not by a tool.
How does Swfte help with ISO/IEC 42001 evidence?
Swfte provides technical controls and records that an organization can use as evidence: an inventory of agents and model providers, activity records, policy decisions and cost attribution. The exact posture depends on your use case, jurisdiction, deployment and configuration, and the management-system work (policy, roles, impact assessment, internal audit) stays with your organization.
How does it relate to the NIST AI RMF and the EU AI Act?
The NIST AI RMF is a voluntary US framework organized around Govern, Map, Measure and Manage. The EU AI Act is binding regulation with risk-tiered obligations. ISO/IEC 42001 is a management-system standard that can be used to organize the work for either. See our pages on the NIST AI RMF and the EU AI Act.
See what AI is running in your organization
Start with an inventory. The free AI usage risk audit looks at metadata only, under NDA, and shows what you would need to evidence.
Metadata only · NDA first · Design-partner terms on request