Solutions / ISO 42001
ISO 42001, AI governance
you can actually prove
Your buyer stopped asking whether you use AI and started asking how you govern it. ISO 42001:2023 is the certifiable answer: an AI management system with scope, roles, impact assessments, and evidence that its controls operate. Screenata builds it from your real stack, and shares evidence with any other framework you run.
- Annex A controls, plus Clauses 4–10
- 38
- Per framework, under 50 people
- $5,988/yr
- Shared control hub
- NIST 800-53
- Price, no sales call
- Published
An AI management system, grounded in your stack
Annex A and the clauses, both seeded
ISO 42001:2023 is a management-system standard: the 38 Annex A controls are only half of it, and Clauses 4 through 10 carry the context, leadership, planning, and improvement requirements auditors actually test. Both are seeded as controls with evidence attached, not as a checklist you fill in yourself.
- AI policy, roles, and impact assessment scoped to your systems
- Clause requirements tracked with owners and dates like any other control
- Certifiable through an accredited body you choose
Security controls and AI controls, one program
An AI management system rests on ordinary security controls: access control, change management, logging, supplier management, incident response. Screenata builds those alongside the AI-specific ones, and maps every framework through NIST 800-53 so a shared requirement resolves to one control and one artifact.
- One MFA check satisfies ISO 42001, ISO 27001 A.8.5, and SOC 2 CC6.1
- Run it standalone, or add it to another framework without duplicating work
- Competitors charge $3–10K per additional framework
The AI-specific work, tracked properly
What ISO 42001 adds beyond ordinary security work is genuinely new: an inventory of AI systems, impact assessments, data and model provenance, human oversight, and the AI vendors in your supply chain. Screenata scopes each one and tracks it to an owner, showing gaps as gaps.
- AI vendors surfaced in the vendor inventory and risk register
- Impact assessment and oversight requirements with named owners
- Claims cited to specific Annex A controls
Continuous operation, documented
Certification is a point in time; surveillance audits are not. Scheduled scans, quarterly access reviews, and structured agent reports give you the operating-effectiveness record between visits.
- Signed with SHA-256 + RFC 3161 timestamps
- Every agent action logged, the trail itself is evidence
How an ISO 42001 program runs here
- 01
Add the framework
Start with ISO 42001, or add it to frameworks you already run. One program either way, scoped per framework.
- 02
Collapse the overlap
If you run another framework, its evidence maps to the shared clauses and controls automatically.
- 03
Fill the AI layer
Vera scopes the genuinely AI-specific controls and runs collection like any other gap.
Govern your AI, and prove it
Book a demo and see an Annex A control traced to the signed evidence that proves it, and to every other framework the same control satisfies.