The AI standard
an auditor can certify.
Keep the policy, impact assessments and lifecycle records where your systems live — not in a binder.
What an auditor asks to see.
ISO/IEC 42001 certifies how you run things, not a snapshot. An auditor checks that a real, running process produced each of these records.
AI risk assessment
A defined risk process you actually use, with the results kept on record.
Operational control
The AI lifecycle run the way your management system says it is run.
Audit and review
Proof you check yourselves — and that leadership reads the result and acts on it.
AI system impact assessment
What a system could do to people and society — assessed, and revisited as it changes.
AI system life cycle
Design, verification, deployment, operation and retirement — each stage with a record.
Data for AI systems
Where your data came from, its quality, and how it was prepared.
The certification path
Where an auditor actually reads your evidence.
Certification audits your cycle, not a folder of documents — and two of its stages are where what you hold gets read.
Surveillance audits come every year, and the cycle recertifies rather than ending.
From standard to practice.
ISO/IEC 42001 says what a management system must do. Getting certified means connecting that to the systems, controls and evidence that run day to day.
Your AIMS boundary only holds if you know every AI system inside it.
A control is real when someone owns it between audits.
An impact assessment stands up when its supporting evidence is kept with it.
Change a model, and the records written against the old one must follow.
From Annex A controls to live AI governance.
Strai8 connects the standard’s clauses and controls to the systems, assessments and evidence across your AI environment.
Discovery
Find the AI in scope.
Find every AI system before you draw the boundary — endpoints, apps, models, third-party services.
Control mapping
Connect Annex A to systems.
Map each control to the systems, owners and processes it actually applies to.
Impact assessments
Keep A.5 on the record.
Keep impact assessments on the system, versioned with the model they were written for.
Evidence
Attach proof to the control.
Store each proof against the requirement it satisfies, not in a folder named after it.
Monitoring
Keep the loop turning.
Get told when a change makes an earlier record out of date.
Audit pack
Turn the record into an audit trail.
Generate the Stage 1 and Stage 2 evidence trail from what you already hold.
Questions teams ask about ISO/IEC 42001.
Hold the management system in the estate.
Thirty minutes on your own systems: which controls carry evidence, and which have gone stale.