Scrutineer · Frameworks
ISO 42001 compliance software for AI management system certification
ISO 42001 is the first management system standard for artificial intelligence, and most teams already hold the evidence for a good part of it.
Scrutineer maps your existing ISO 27001 and SOC 2 controls onto the Annex A objectives, then shows you the gap that is genuinely new.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with ISO 42001
Your ISO 27001 evidence, reused not rebuilt
ISO 42001 shares the harmonized management system structure with ISO 27001, so clauses 4 through 10 are familiar ground. Scrutineer maps the controls you already evidence onto the Annex A objectives and marks the ones your existing programme genuinely does not answer, which is a much shorter list than most gap analyses imply.
The AI-specific gap, named
Impact assessment, data provenance and life cycle verification are where an ISO 27001 programme runs out. Those objectives ask for records nobody generates by accident, so Scrutineer treats them as their own workstream with owners and dates rather than burying them in a control list.
An inventory that survives the audit
An AI management system is only as credible as its system inventory. Scrutineer keeps each AI system, the data behind it, its impact assessment and its owner on one record, so the scope you certify is the scope you can still describe twelve months later.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps one control set to ISO 42001, ISO 27001, SOC 2 and your other frameworks at once
- Shows which Annex A objectives your existing evidence already answers, and which it does not
- Keeps an inventory of AI systems with owner, data sources, impact assessment and status
- Tracks impact assessments and life cycle verification records as dated, reviewable artifacts
- Carries supplier and customer responsibility allocation across into the A.10 objective
- Keeps the management review, internal audit and corrective action records the clauses require
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Annex A reference
The nine ISO 42001 Annex A objectives, and how much of each your ISO 27001 evidence already answers
Most ISO 42001 gap analyses present all nine objectives as new work. They are not. The last column is the one worth reading: it separates the objectives an existing information security programme largely covers from the three that generate records nobody produces by accident.
| Annex A objective | What it asks for | Evidence an auditor samples | Does your ISO 27001 evidence already cover it? |
|---|---|---|---|
| A.2 Policies related to AI | An AI policy that is approved, communicated and reviewed, and that sits consistently alongside your other policies. | The policy itself, the approval record, the review date and evidence it reached the people it applies to. | Partly. The policy machinery transfers directly from your ISMS. The content is new, and a policy copied from a template without an AI inventory behind it reads as exactly that. |
| A.3 Internal organization | Defined roles and responsibilities for AI, and a route for people to report concerns about an AI system. | A responsibility assignment, job descriptions or terms of reference, and the escalation path with evidence it works. | Mostly. The governance structure carries over. The addition is naming who can decide that an AI system is fit to deploy, which is often genuinely unassigned. |
| A.4 Resources for AI systems | An account of the resources AI depends on: data, tooling, compute, and human competence. | A resource inventory covering each AI system, plus competence records for the people governing it. | Partly. Asset inventory and competence records exist in an ISMS, but models, training data and compute are rarely classified as assets in one, so the inventory usually needs extending. |
| A.5 Assessing impacts of AI systems | An assessment of the consequences an AI system can have for individuals, groups and society, not just for your organization. | A completed impact assessment per system, dated, with the decision it supported. | No. This is the single largest genuinely new requirement. A security risk assessment asks what harm can come to the organization; this asks what harm the organization can cause. ISO/IEC 42005 gives guidance on performing it. |
| A.6 AI system life cycle | Responsible design, development, verification, deployment and operation, with objectives set before building. | Design records, verification and validation results, release approvals and post-deployment monitoring. | Partly. Secure development controls transfer. Model verification and validation do not, and this objective carries the most individual controls of the nine. |
| A.7 Data for AI systems | Control over the data used to develop and run AI systems, including provenance, quality and preparation. | Data provenance records, quality checks, preparation steps and the acquisition basis for training data. | Partly. Classification and handling transfer. Provenance and quality do not, and provenance for data acquired years ago is often the hardest record to reconstruct. |
| A.8 Information for interested parties | Documentation and disclosure so users and affected parties understand the system and its limits. | System documentation, user-facing disclosures, and the record of what was communicated to whom. | Largely new. An ISMS documents internally; this objective is about what you tell people outside the organization, including those subject to a decision rather than buying the product. |
| A.9 Use of AI systems | Responsible use of AI, including how your own workforce uses AI systems you did not build. | An acceptable use position for AI, and evidence that actual use is monitored against it. | Partly. Acceptable use policies exist. Covering third-party AI tools staff adopted on their own usually does not, and shadow AI is the common finding here. |
| A.10 Third-party and customer relationships | Responsibility allocated clearly across suppliers, partners and customers for the AI in the chain. | Supplier agreements, the allocation of responsibilities, and supplier assessment records. | Mostly. Supplier security controls transfer well. The addition is stating who is accountable when a supplier model produces a bad outcome, which contracts written before 2023 rarely address. |
| Running it once for all of it | One mapped control set covering ISO 42001, ISO 27001 and SOC 2, evidenced once and reviewed on one cadence. | The same artifacts answering every row above, with the AI-specific records tracked as their own workstream. | This is where Scrutineer sits. The point is not that ISO 42001 is easy; it is that three of the nine objectives are where the real work lives, and knowing which three is worth more than another control checklist. |
References are to ISO/IEC 42001:2023 Annex A, whose objectives run A.2 to A.10. Published counts of the individual controls under those objectives vary between 38 and 39 depending on how one AI life cycle sub-clause is split, so confirm the exact list against the copy of the standard you purchase. Assessments of ISO 27001 overlap in the final column are practitioner judgment about typical programmes, not a published crosswalk, and your own coverage will differ. Scrutineer prepares and maintains certification evidence; an accredited certification body performs the audit and issues any certificate.
Good questions
Questions about ISO 42001
Keep reading
Guides that go deeper on AI governance and the standards next to it
Choosing an AI governance framework
ISO 42001 against the NIST AI RMF and the US state AI laws as they actually stand in 2026, and how to tell which one your buyers are really asking for.
Read the guideAll 93 ISO 27001 Annex A controls
The control set that carries a large share of your ISO 42001 work, listed in full with the 2022 numbering.
Read the guideHow long ISO 27001 certification takes
The certification cycle ISO 42001 mirrors, stage by stage, with the parts teams consistently underestimate.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification