International Standard

ISO 42001 Certification Readiness. Delivered.

ISO/IEC 42001: Artificial Intelligence Management System (AIMS)

ISO 42001 is the international standard for AI management systems. Norivo implements the full management system structure, cross-mapped to VALID controls and EU AI Act requirements. One engagement covers multiple frameworks.

Published in December 2023, ISO/IEC 42001 establishes requirements for organisations to manage AI responsibly. It provides the management system structure that complements the EU AI Act's prescriptive requirements. Our team delivers both in a single engagement. You sign off on the deliverables; we maintain them for 12 months.

10Capability Areas
40-50%VALID Overlap
FullModule Coverage
2023Published

10 Capability Areas

ISO 42001 covers the full scope of AI management. Our team implements each area and cross-maps it to VALID controls and EU AI Act requirements.

01

AI Management System (AIMS)

Establish a systematic approach to managing AI risks and opportunities within your organisation's context.

02

AI Policy & Objectives

Define organisational AI policies, objectives, and the commitment to responsible AI development and deployment.

03

Roles & Responsibilities

Assign clear accountability for AI governance, from board-level oversight to operational AI system owners.

04

AI Risk Assessment

Identify, analyse, and evaluate AI-specific risks including bias, safety, transparency, and fundamental rights impacts.

05

AI Impact Assessment

Conduct impact assessments for AI systems, considering effects on individuals, groups, and society.

06

Performance Evaluation

Monitor, measure, and evaluate AI system performance against defined objectives and ethical requirements.

07

AI System Lifecycle

Govern the full AI lifecycle: design, development, deployment, operation, monitoring, and decommissioning.

08

Data Governance for AI

Manage data quality, provenance, bias testing, and privacy throughout the AI data pipeline.

09

Continual Improvement

Systematic process for improving AI governance practices based on monitoring results and incident learnings.

10

Third-Party AI Management

Govern AI systems and components sourced from third parties, including vendor assessments and contractual requirements.

VALID Framework Cross-Mapping

40-50% of ISO 42001 requirements map directly to VALID controls. One assessment contributes to both frameworks.

ISO 42001RequirementVALID ControlVALID NameOverlap
A.6.2.2AI InventoryV-01AI System InventoryDirect
A.6.2.3Risk CriteriaV-02Risk ClassificationDirect
A.6.2.4Risk AssessmentA-01Risk AssessmentDirect
A.6.2.5Impact AssessmentA-02Impact AssessmentDirect
A.7.3AI AwarenessA-04Transparency AssessmentPartial
A.7.5Documented InformationL-04Cross-Framework EvidenceDirect
A.8.2Legal RequirementsL-01Regulatory MappingDirect
A.9.1Monitoring & MeasurementI-02Monitoring & AlertingDirect
A.10.2AI ControlsD-01Authority BoundariesExtended
A.10.3AI SafeguardsD-02Circuit BreakersExtended

How We Deliver ISO 42001 Readiness

Four phases. One engagement. Cross-mapped evidence that satisfies multiple frameworks at once.

1

Gap Analysis

Our team runs the gap analysis using Nora AI, measuring your current AI governance posture against ISO 42001 requirements. You receive a prioritised remediation plan, not a list of homework.

2

Control Implementation

We implement every ISO 42001 control on your behalf, cross-mapping to VALID controls so the same evidence satisfies both frameworks. Your team approves; we deliver.

3

Evidence Collection

We collect and organise evidence against every ISO 42001 clause, cross-mapped across VALID and EU AI Act. One upload, multiple frameworks covered.

4

Audit Package

We generate the Statement of Applicability, gap closure report, and full evidence set. You hand it to your certification body, and we walk you through every artefact in a handoff meeting.

Book a Scoping Call

ISO 42001 readiness delivered as a managed service, cross-mapped to VALID and the EU AI Act so one engagement covers multiple frameworks.