Docply Browse kits
Compliance Suite · ISO/IEC 42001

An AI management system that produces evidence, not just documents.

A complete ISO/IEC 42001 AI management system — clauses 4 to 10, all 38 Annex A controls, the impact assessment process the standard is built around, and the nine registers that produce the evidence an auditor samples.

One process per procedure, with its records in separate files. Nothing is included unless a clause requires it or an applicable control implies it — which is why it is 39 files and not a hundred.

Compliance Suite · One-time payment
€590 excl. VAT
39 audit-ready files
Clauses 4–10 and all 38 Annex A controls
Statement of Applicability pre-populated
Impact assessment process and record
Editable DOCX & XLSX formats
Lifetime access · Free updates
Secure checkout · Instant download · Last updated August 2026

VAT is added at checkout according to your country. Businesses in another EU Member State can enter a VAT number for reverse charge.

What you get

Sixteen processes, nine registers, and a reason for every file.

Each procedure covers one process and carries its own records as separate modules. The registers that ISO 42001 requires are separate files with one owner each, because a single shared workbook stops working the moment two people need it at once.

Procedures & policy
16 files
Record forms
9 files
Registers
9 files
Guidance
4 files
The nine registers, one file each
AIMS-01-M1 · AI System Inventory
4.3 · 8.4 · A.4.2
AIMS-03-M2 · Objectives Register
6.2
AIMS-05-M1 · AI Resources Register
A.4.2–A.4.6
AIMS-05-M2 · Competence Register
7.2 (d)
AIMS-06-M1 · AI Risk Register and Treatment Plan
6.1.2 · 6.1.3 · 8.2 · 8.3
AIMS-06-M2 · Statement of Applicability — all 38 controls
6.1.3
AIMS-13-M1 · Supplier and Responsibility Allocation Register
A.10.2 · A.10.3
AIMS-15-M1 · Nonconformity and Corrective Action Register
10.2 (f) · 10.2 (g)
AIMS-16-M1 · Legal and Contractual Requirements Register
4.2 · 6.2
Annex A coverage

All 38 controls, each with the file that discharges it.

The Statement of Applicability arrives with every control listed and a field for the decision. A document set that covers only the controls you expect to apply is incomplete by definition — the exclusions need a justification as much as the inclusions do.

A.2
Policies related to AI
AI Policy · AIMS-02
A.3
Internal organisation and reporting of concerns
Concerns and AI Incidents · AIMS-12
A.4
Resources for AI systems — data, tooling, computing, human
Competence and AI Resources · AIMS-05
A.5
Assessing impacts of AI systems
AI System Impact Assessment · AIMS-07
A.6.1
Objectives for responsible development
AI System Life Cycle · AIMS-08
A.6.2
AI system life cycle — design to retirement
AI System Life Cycle · AIMS-08
A.7
Data for AI systems — provenance, quality, preparation
Data Management · AIMS-10
A.8
Information for interested parties
Transparency and Information · AIMS-11
A.9
Responsible use of AI systems
Operation, Monitoring and Logging · AIMS-09
A.10
Third parties, suppliers and customers
Third Parties · AIMS-13
What makes it audit-ready

Documents prove intent. Records prove operation.

A certification body reads your documents at stage 1 and samples your records at stage 2. You can buy the first and only earn the second — which is why this suite is built around the files that produce evidence rather than around the ones that look complete.

The impact assessment is a process, not a form

With criteria, a trigger list and the rule that at least one assessor did not build the system. It is performed for low-impact systems too, in short form, because the conclusion that a system is low-impact is itself a conclusion that has to be documented.

Risk assessed for people, not only for the organisation

The risk register carries separate consequence columns for the organisation, for individuals and for societies, with the highest driving the level. A single organisational scale would quietly discard exactly what ISO 42001 exists to capture.

Human oversight defined so it can be measured

Per system, in operational terms: who reviews, what they see, what they can change. With the measure that reveals nominal oversight — how many outputs were overridden in the last hundred.

Built to merge with an existing management system

Same template, same section skeleton and same conventions as our ISO 27001 suite. The six shared processes reference what you already run instead of creating a parallel set, and Annex D of the standard anticipates exactly this.

Questions

Before you buy.

Is ISO 42001 certification mandatory?

No. It is a voluntary management system standard. It is increasingly asked for in enterprise procurement and in security questionnaires, and it builds most of the machinery the EU AI Act's obligations run on — but the Act is assessed against the Act, not against the standard.

We already hold ISO 27001. How much of this do we already have?

Most of the management system clauses and very little of Annex A. Eight requirements transfer fully, seven partially, and the AI system impact assessment has no equivalent at all. This suite is written to reference an existing management system rather than duplicate it.

Does the kit include the Statement of Applicability?

Yes, pre-populated with all 38 Annex A controls, each with the field for the applicability decision and the justification. Exclusions need a justification as much as inclusions do, which is where most Statements of Applicability fail.

What is the impact assessment, and why is it separate from risk?

It asks what consequences the system has for individuals, for groups of individuals and for societies — including when it works exactly as designed. A model that performs well overall and worse for one subgroup has not failed in the risk sense. The assessment feeds the risk process; it does not replace it.

Can we use this alongside ISO 13485 or another quality system?

Yes. Annex D of ISO 42001 explicitly names ISO 13485 and IEC 62304 among the sector standards an AI management system integrates with. The shared processes in this suite reference your existing document control, internal audit and corrective action rather than creating a second set.

How long before we can be certified?

The documentation is weeks. The records are months, because a certification body samples evidence produced across a period. Six to nine months from a standing start is a realistic planning assumption; organisations that already hold ISO 27001 move faster.

What format are the files?

Editable DOCX for procedures and forms, XLSX for the registers. No locked templates, no portal, no subscription. You download them and they are yours.

Ready to ship

ISO 42001 documentation,
ready to deploy.

€590 excl. VAT · 39 files · Instant download · Lifetime free updates.

See every file