Skip to content
Cyber Horizon
All frameworks

// Information Security

ISO/IEC 42001 AI Management System Compliance Software

International standard for responsible development and use of AI systems.

Framework at a glance

Short name

ISO 42001

Version

Category

Information Security

Controls

69

What ISO 42001 covers

69 controls across 30 domains — every one tracked, owned and evidenced in Cyber Horizon.

Organisational Context

1 controls
  • 4.1 Understanding the organisation for AI

Stakeholders

1 controls
  • 4.2 Interested parties in AI

Scope

1 controls
  • 4.3 Scope of AI management system

Management System

1 controls
  • 4.4 AI management system

Governance

4 controls
  • 5.1 Leadership for AI
  • 5.3 AI roles and responsibilities
  • A.2.3 Internal AI use restrictions
  • A.2.5 Responsibilities for AI systems

Policy

2 controls
  • 5.2 AI policy
  • A.2.2 Policies for responsible AI

Risk Management

2 controls
  • 6.1 AI risk management
  • A.3.2 AI risk assessment process

Impact Assessment

2 controls
  • 6.2 AI impact assessment
  • 8.2 AI system impact assessment

Objectives

1 controls
  • 6.3 AI objectives

Resources

1 controls
  • 7.1 Resources for AI

Training

1 controls
  • 7.2 AI competence

Awareness

1 controls
  • 7.3 AI awareness

Communication

1 controls
  • 7.4 AI communication

Documentation

2 controls
  • 7.5 AI documentation
  • 8.7 AI system documentation

Planning

1 controls
  • 8.1 Operational planning for AI

Data Governance

2 controls
  • 8.3 AI data management
  • A.4.2 Resource documentation

Development

1 controls
  • 8.4 AI system development

Third-Party

2 controls
  • 8.5 AI third-party management
  • A.2.6 Third-party AI systems

Operations

1 controls
  • 8.6 AI system operations

Monitoring

1 controls
  • 9.1 AI performance monitoring

Audit

1 controls
  • 9.2 AI internal audit

Management Review

1 controls
  • 9.3 AI management review

Corrective Action

1 controls
  • 10.1 AI nonconformity

Improvement

1 controls
  • 10.2 AI continual improvement

Data Management

1 controls
  • A.4.3 Data resources

Transparency

1 controls
  • A.5.2 Stakeholder communication on AI

Verification

1 controls
  • A.6.1 AI system verification

Validation

1 controls
  • A.6.2 AI system validation

Incident Management

1 controls
  • A.8.4 Incident management for AI

ISO 42001

31 controls
  • A.2.4 Review of the AI policy
  • A.3.3 Reporting concerns about AI
  • A.4.4 Tooling resources
  • A.4.5 System & computing resources
  • A.4.6 Human resources for AI

How Cyber Horizon automates ISO 42001

Every ISO 42001 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO/IEC 42001 AI Management System?

International standard for responsible development and use of AI systems.

How many controls does ISO/IEC 42001 AI Management System have?

ISO/IEC 42001 AI Management System has 69 controls in Cyber Horizon's catalogue, organised across 30 domains.

How does Cyber Horizon help with ISO/IEC 42001 AI Management System?

Cyber Horizon maps ISO/IEC 42001 AI Management System into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 42001 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 42001 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 42001 in Cyber Horizon.