ISO/IEC 42001
ISO/IEC 42001: Operational Records for Your AI Management System
ISO/IEC 42001 is the certifiable standard for managing AI across an organization to cover your management system. Lumenova AI holds the operational records beneath it for AI agents: the inventory, the controls in force, and evaluation results.
What Is the ISO 42001 Standard?
ISO/IEC 42001:2023, usually called ISO 42001, is the international standard for an AI management system (AIMS): how an organization establishes, runs, maintains, and improves the way it manages AI. Published in December 2023, it follows the same clause structure as ISO/IEC 27001 and adds Annex A, a set of reference controls for AI. Accredited certification bodies audit organizations against it.
Lumenova AI is an agentic AI governance platform that keeps the operational records the management system relies on: the agent inventory, controls enforced before each action, evaluation and red-team results, and decision records. It doesn’t certify you or replace the policy, objectives, and management review the standard asks for.
Annex A has 38 controls under nine objectives, covering AI policy, internal organization, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems, and third-party relationships.
CORE CHECKS
What the ISO 42001 Standard Asks
The first certifiable AI management system standard, so an external auditor can confirm you meet it.
Context and Scope
Defines which AI systems and teams are in scope, the organization’s role for each, and the issues and stakeholders that shape the system.
Leadership and AI Policy
Requires top management to commit to the AI management system, set an AI policy, and assign clear roles and responsibilities.
Risk and Impact Assessment
Calls for an AI risk assessment, a treatment plan with a Statement of Applicability, and an assessment of impacts on people and society.
Operation
Puts those controls into practice, repeating risk and impact assessments at planned intervals or whenever something significant changes.
Evaluation and Improvement
Tracks performance through monitoring, internal audit, and management review, with corrective action when something doesn’t conform.
How Lumenova AI Supports Your AI Management System
The Inventory the System Needs
Agents, MCP servers, skills, and prompts in one registry, with an owner, approver, and risk tier on each use case, for your scope and Annex A records
Controls that Run Before the Action
Each agent’s limits are written as policy and enforced before the action, with version history that shows when each control changed.
Evaluations Checked Against Your Reviewers
Measure how closely automated evaluation scores match your own reviewers before you use them as Clause 9 evidence.
Red-Team Findings with Their Evidence
Black-box probes keep the request and response behind each finding, and replays confirm each fix for your corrective action records.
Lifecycle States for Every Asset
Move agents, MCP servers, skills, and prompts through active, deprecated, blocked, and deleted states, and see what breaks before retiring any.
Records for Your Audits
Decision records and findings are exported as CSV or JSON for internal audits and certification audits.
How to Get Ready
- Set the scope: which AI systems, agents included, and which teams;
- Register the systems in scope and name their owners;
- Write the limits as policy and test them before they bind;
- Choose the evaluations for each system and check them against your reviewers;
- Route red-team findings into your corrective action process;
- Decide which records your auditor will sample, and check they export cleanly.
Frequently Asked Questions
No. Only an accredited certification body can certify your AI management system. Lumenova AI keeps operational records your auditor may sample: the agent inventory, the controls in force and their history, evaluation and red-team results, and decision records.
Both follow the same management system structure, so an organization certified to ISO/IEC 27001 can reuse much of its approach, such as document control, internal audit, and management review. ISO/IEC 42001 adds AI-specific requirements, including the AI system impact assessment and the Annex A controls for AI.
If agents are part of the AI systems your organization develops, provides, or uses within the scope you set, they belong in the management system: inventoried, risk-assessed, controlled, and monitored like any other AI system. Record their tools and dependencies too, since an agent’s risk depends on what it can reach.
Clause 6.1.4 asks organizations to assess the potential consequences of an AI system for individuals, groups, and society, and to document the results. ISO/IEC 42005 gives guidance on running these assessments. Lumenova AI’s inventory, risk tiers, and evaluation results supply the facts the assessment starts from.
ISO/IEC 42001 is a voluntary, certifiable standard for managing AI across an organization. The EU AI Act is law, with obligations set by each system’s risk level and your role. Certification to 42001 doesn’t by itself satisfy the Act, but the management system can organize much of the evidence the Act asks for.