// Information Security
ISO/IEC 42001 AI Management System Compliance Software
International standard for responsible development and use of AI systems.
Framework at a glance
Short name
ISO 42001
Version
—
Category
Information Security
Controls
69
What ISO 42001 covers
69 controls across 30 domains — every one tracked, owned and evidenced in Cyber Horizon.
Organisational Context
1 controls- 4.1 Understanding the organisation for AI
Stakeholders
1 controls- 4.2 Interested parties in AI
Scope
1 controls- 4.3 Scope of AI management system
Management System
1 controls- 4.4 AI management system
Governance
4 controls- 5.1 Leadership for AI
- 5.3 AI roles and responsibilities
- A.2.3 Internal AI use restrictions
- A.2.5 Responsibilities for AI systems
Policy
2 controls- 5.2 AI policy
- A.2.2 Policies for responsible AI
Risk Management
2 controls- 6.1 AI risk management
- A.3.2 AI risk assessment process
Impact Assessment
2 controls- 6.2 AI impact assessment
- 8.2 AI system impact assessment
Objectives
1 controls- 6.3 AI objectives
Resources
1 controls- 7.1 Resources for AI
Training
1 controls- 7.2 AI competence
Awareness
1 controls- 7.3 AI awareness
Communication
1 controls- 7.4 AI communication
Documentation
2 controls- 7.5 AI documentation
- 8.7 AI system documentation
Planning
1 controls- 8.1 Operational planning for AI
Data Governance
2 controls- 8.3 AI data management
- A.4.2 Resource documentation
Development
1 controls- 8.4 AI system development
Third-Party
2 controls- 8.5 AI third-party management
- A.2.6 Third-party AI systems
Operations
1 controls- 8.6 AI system operations
Monitoring
1 controls- 9.1 AI performance monitoring
Audit
1 controls- 9.2 AI internal audit
Management Review
1 controls- 9.3 AI management review
Corrective Action
1 controls- 10.1 AI nonconformity
Improvement
1 controls- 10.2 AI continual improvement
Data Management
1 controls- A.4.3 Data resources
Transparency
1 controls- A.5.2 Stakeholder communication on AI
Verification
1 controls- A.6.1 AI system verification
Validation
1 controls- A.6.2 AI system validation
Incident Management
1 controls- A.8.4 Incident management for AI
ISO 42001
31 controls- A.2.4 Review of the AI policy
- A.3.3 Reporting concerns about AI
- A.4.4 Tooling resources
- A.4.5 System & computing resources
- A.4.6 Human resources for AI
How Cyber Horizon automates ISO 42001
Every ISO 42001 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO/IEC 42001 AI Management System?
International standard for responsible development and use of AI systems.
How many controls does ISO/IEC 42001 AI Management System have?
ISO/IEC 42001 AI Management System has 69 controls in Cyber Horizon's catalogue, organised across 30 domains.
How does Cyber Horizon help with ISO/IEC 42001 AI Management System?
Cyber Horizon maps ISO/IEC 42001 AI Management System into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 42001 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Information Security frameworks
See ISO 42001 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 42001 in Cyber Horizon.