SanRa
ISO/IEC 42001 · AI management system

Compliance,
made workable.

A practical framework for ISO/IEC 42001 readiness — map the clauses, track evidence gaps, and prioritise what to build next. Educational only; not a certification audit.

Open the framework
Your readiness signal 0% complete

Work through the clause checklist. Progress stays in this browser only.

Why this exists

An AIMS is a system of judgement, not a pile of policies.

ISO/IEC 42001 asks organisations to establish, implement, maintain and continually improve an AI management system. This portal turns that into a usable map: context, leadership, planning, support, operation, evaluation and improvement — with human factors kept in view.

Clause framework

Seven domains. Work them in order.

Mark each item as you build evidence. Use this as a readiness conversation tool with leadership — not as a certificate.

Discuss gaps with SanRa

This framework is educational. It is not legal advice, an audit, or a determination of ISO/IEC 42001 conformity or certification readiness.

Annex A lens

Control themes that usually matter first

01 · AI system lifecycle

Inventory, intended purpose, design objectives, verification, validation, deployment and retirement.

02 · Data & provenance

Data quality, lineage, retention, lawful use, and what leaves the organisation via prompts, fine-tunes or vendors.

03 · Risk & impact

Risk assessment across security, privacy, safety, misuse, fairness and third-party dependency — with residual risk accepted by name.

04 · Human oversight

Who can challenge outputs, when automation must stop, and how competence is maintained under time pressure.

05 · Transparency & reporting

What users, customers and leadership are told about AI use, limitations and incidents.

06 · Suppliers & tools

Due diligence on model providers, agents, plugins and subprocessors — including training-use and retention terms.

Briefings & related

FIDO

Passkeys that
survive phishing.

Strong identity underpins trustworthy AI operations — roll out FIDO2 and passkeys with recovery that holds.

Open FIDO framework

ISO/IEC 42001

AI management,
made ready.

A concise introduction to the decisions, evidence and operating disciplines behind an AI management system.

Download readiness guide

ISO/IEC 27001

An ISMS people
can actually run.

Pair your AIMS with a workable information security management system — same structure, security focus.

Open ISO 27001 framework

WP-01

The Neuron Doctrine
of Security.

SanRa thought leadership on human factors and security in the age of AI-augmented systems.

Download whitepaper
Start a readiness conversation

Build an AIMS that people
can actually run.

ibrahim.mukherjee@icloud.com

Read our privacy notice.