Framework guide

ISO/IEC 42001, explained simply

ISO/IEC 42001 is the first management-system standard for artificial intelligence. It does not tell you which AI systems are allowed — it asks whether your organisation governs AI deliberately: policies, roles, risk assessment, and evidence that the system is actually run.

Standard
ISO/IEC 42001:2023 (AI management system)
Version
ISO/IEC 42001:2023
Jurisdiction
International (ISO/IEC)
Catalogue last verified
2026-07-16

Who it is for

Any organisation that develops, provides or uses AI systems, at any size. It is certifiable: an accredited body audits you and issues a certificate. Unlike the EU AI Act it is voluntary — but the two overlap heavily, and buyers increasingly ask for it as shorthand for "you govern your AI properly".

What is actually in it

Tawsik tracks every requirement in the published catalogue, grouped by its official numbering.

60requirements tracked

  • A. · 38
  • Cl. · 22

What evidence can prove — and what it can’t

We would rather tell you this up front than let a dashboard imply more certainty than it has.

9Provable from an inspectionChecked against your website or the repositories you select.
37Provable from a documentA policy, register or report you attach.
14Only you can answerYour own declaration, or a judgement that needs a human reviewer.

Where Tawsik fits

Tawsik is not a certification body. It measures your readiness against the standard from your own evidence, shows you exactly which clauses and Annex A controls are still open, and carries the overlap into your EU AI Act work so the same proof counts twice.

Tawsik is not a certification body or an auditor.

One set of evidence, every framework

Tawsik maps one canonical control to every framework that asks for it, so a proof you gather once counts everywhere it applies.

See where you stand

Start with the free EU AI Act check — no account, no email. Your workspace covers the rest.

Other frameworks

Tawsik guides you toward compliance. It isn’t legal advice.