ISO/IEC 42001 · AI Governance Toolkit
The ISO/IEC 42001 toolkit that comes with live AI threat intelligence.
59 audit-ready templates built natively on the SC 42 standards vocabulary (ISO/IEC 42001 · 42005 · 23894 · 22989 · 5338) — plus a daily AI threat feed that plugs straight into your risk register, and a certification-maintenance calendar that emails your team before deadlines slip.
Instant download · .docx / .xlsx · no macros · single-organization license
no conversion table
Why this toolkit is different
Most toolkits sell a document count.
This one ships an operating system.
Built on the standards, not around them
Every dropdown, scale, and lifecycle stage uses one SC 42 Codebook: ISO/IEC 22989 lifecycle stages, ISO/IEC 23894 Annex B risk sources, ISO/IEC 42001 Annex A control IDs, and shared rating bands. A 4×3 = 12 in your impact assessment is still 12 in your risk register. No conversion tables.
A daily AI threat intelligence feed
145+ curated AI threats — prompt injection, model theft, deepfake fraud, regulatory actions — tagged with the same codebook. Paste into the register's Bridge sheet and severity, source and lifecycle convert automatically. Your SoA cites live threat IDs as evidence for control selection.
Audit-grade, not just formatted
Designed by a practicing certification auditor: a full-standard internal audit checklist (all clauses + 38 Annex A controls, evidence pre-mapped), a management review agenda covering every 9.3.2 input, acceptance records with expiry tracking. The findings auditors actually raise are engineered out.
Certification-maintenance calendar with email reminders
Getting certified is day one. A multi-ISO annual calendar ships pre-filled with 68 ISO/IEC 42001 maintenance activities mapped to this toolkit's template IDs — plus starter sets for ISO/IEC 27001, 20000-1 and ISO 22301. Assign owners once: the 12-month matrix, dashboard and D-day tracking build themselves, and the bundled script emails each owner before their deadline and sends the certification manager a daily overdue/upcoming digest.
Multi-jurisdiction by design
EU AI Act Art. 27 FRIA report, Korea AI Framework Act Art. 35 report (decree items ①–⑦ in statutory order — rare in English), EU Annex IV-consistent technical documentation, and Art. 73 incident-reporting deadlines auto-computed. Two jurisdictions, one set.
Worked example
See it finished before you start.
A fictional AI recruitment-screening company, TalentFlow Inc., runs through all 57 files — so you start from a working system, not blank forms.
◆ Full Set exclusive · 57 completed filesEditions & pricing
Choose your starting point.
Every edition shares the same SC 42 codebook, so a suite today upgrades cleanly to the full system later.
Risk Management
11 AIRM templates + the SC 42 Codebook.
- 11 AIRM templates — procedure, criteria & scales, risk register with Intel Bridge, Bow-tie
- Statement of Applicability (38 controls) + acceptance records
- Incident register with EU Art. 73 deadlines auto-computed
Complete Toolkit
All 59 templates + Worked Example Pack + catalogs & codebook.
- Everything in both suites + all 29 Governance templates
- Certification-maintenance calendar (AIGV-G17) + email-reminder automation
- TalentFlow worked example — 57 completed files
- Full internal audit checklist, management review, SoA & both jurisdiction reports
Impact Assessment
19 AISIA templates for AI system impact assessment.
- 19 AISIA templates — inventory, screening, KR+EU classification
- System, data, stakeholder, rights & benefit–harm worksheets + scoring workbook
- EU FRIA report + Korea Art. 35 report
Suite → Complete: pay the difference within 90 days. · 14-day money-back guarantee. · Consultant & multi-organization licenses available on request.
What's inside · 59 templates
Three suites. One codebook. Zero mapping tables.
- AI Policy · Scope · Roles · Objectives
- Competence · Communication
- Document control + master list
- Internal audit programme / checklist / report
- Management review · NC / CAPA
- Reporting-of-concerns channel
- Development / data / logging / technical-doc procedures
- Model card · Responsible use
- Supplier due diligence
- Certification Maintenance Calendar (AIGV-G17)
- Risk management procedure
- Criteria & scales + SC 42 Codebook
- Identification worksheet (Annex B source library)
- Risk register with Threat-Intel Bridge
- Bow-tie deep-dive · Treatment plan
- Statement of Applicability (38 controls)
- Acceptance record · KRI monitoring
- Incident register (EU Art. 73 deadlines auto-computed)
- Procedure · Inventory
- Screening & high-impact / high-risk classification (KR+EU)
- System / data / stakeholder / rights worksheets
- Benefit–harm analysis
- Master report + scoring workbook
- Mitigation plan · Review & approval
- EU FRIA report
- Korea Art. 35 report
- Monitoring · Risk-transfer linkage
All formulas verified (0 errors), all documents validation-tested. .docx / .xlsx, no macros, no lock-in.
Quality assurance
Machine-verified. Standard-checked. Auditor-authored.
Machine-verified
Every Excel formula recalculated with zero errors, every Word document passes OOXML schema validation, and the impact-to-risk round-trip is tested end to end.
Standard-checked
All 38 ISO/IEC 42001 Annex A controls and the ISO/IEC 23894 Annex B risk sources verified against the standard texts — not paraphrased from memory.
Auditor-authored
Designed and reviewed by a practicing certification auditor for ISO/IEC 42001, 27001, 20000 and 22301 — the findings auditors raise are engineered out.
Before you buy
Frequently asked questions
How is this different from other ISO/IEC 42001 template packs?
We only need one suite — do we have to buy the full set?
Is this legal advice?
What does the license cover?
What's your refund policy?
Start from a working system, not blank forms.
59 audit-ready templates, a live AI threat feed, and a maintenance calendar that never lets a surveillance deadline slip.
Questions before you buy? support@ai42001.ai — answered by the auditor who built it.