Insights

Five-step AI risk assessment methodology for ISO/IEC 42001 — build the AI system inventory, analyze context, identify risks, score likelihood and impact, treat risks — covering AI-intrinsic risk categories such as bias, opacity, malfunction, and supply chain

AI Standards & Certification

28 Jul 2026

AI Risk Assessment: a Five-Step Methodology That Holds Up in an Audit

The 10 mandatory documents an ISO/IEC 42001 certification audit checks — AI policy, scope, risk assessment and SoA, impact assessment, objectives, competence records, internal audit, management review, corrective-action log, AI supplier records

AI Standards & Certification

28 Jul 2026

ISO 42001 Documentation: the 10 Documents Your Certification Audit Will Check

AI Standards & Certification

16 Jul 2026

The 5 Nonconformities Most Likely to Appear in Your ISO 42001 Audit

Comparison diagram of ISO 42001, the EU AI Act, and NIST AI RMF — ISO/IEC 42001 as the certifiable AI management-system spine, the EU AI Act as binding law with four risk tiers (prohibited, high-risk, limited, minimal), and NIST AI RMF's Govern-Map-Measure-Manage cycle as the voluntary method, all converging on one integrated control set and evidence base.

Regulation & Developments

24 Jun 2026

ISO 42001, the EU AI Act, and NIST AI RMF: How the Three Fit Together

Diagram showing how to extend a certified ISO/IEC 27001 ISMS into an ISO/IEC 42001 AIMS, sorting Annex A controls into three groups: reuse and supplement from the ISMS (management-system structure Clauses 4-10, existing policies and roles A.2/A.3), extend to the AI context (AI asset classification A.4, AI system lifecycle A.6, AI supply chain A.10), and build new for AI (AI impact assessment A.5, AI data management A.7, information for stakeholders A.8, use of the system A.9), with audit points marking each transition.

AI Standards & Certification

23 Jun 2026

Extending an ISO/IEC 27001 ISMS to ISO/IEC 42001

Comparison of ISO 42001 and ISO 27001 in four parts: what they share — common Clauses 4-10 under the ISO harmonized structure (Annex SL), shown as a Plan-Do-Check-Act flow between the two standards; where they differ — ISO 27001 as an ISMS aimed at the CIA triad against external threats, ISO 42001 as an AIMS aimed at responsible AI against bias, opacity, malfunction, and human-oversight risks; what ISO 42001 adds — AI policy, AI impact assessment, AI supply chain, and human oversight; and how to run them together as one integrated management system through shared documentation, extended risk assessment, and combined audits.

AI Standards & Certification

19 Jun 2026

ISO 42001 vs ISO 27001: the differences, and how to run them together