A complete ISO/IEC 42001 AI management system — clauses 4 to 10, all 38 Annex A controls, the impact assessment process the standard is built around, and the nine registers that produce the evidence an auditor samples.
One process per procedure, with its records in separate files. Nothing is included unless a clause requires it or an applicable control implies it — which is why it is 39 files and not a hundred.
VAT is added at checkout according to your country. Businesses in another EU Member State can enter a VAT number for reverse charge.
Each procedure covers one process and carries its own records as separate modules. The registers that ISO 42001 requires are separate files with one owner each, because a single shared workbook stops working the moment two people need it at once.
The Statement of Applicability arrives with every control listed and a field for the decision. A document set that covers only the controls you expect to apply is incomplete by definition — the exclusions need a justification as much as the inclusions do.
A certification body reads your documents at stage 1 and samples your records at stage 2. You can buy the first and only earn the second — which is why this suite is built around the files that produce evidence rather than around the ones that look complete.
With criteria, a trigger list and the rule that at least one assessor did not build the system. It is performed for low-impact systems too, in short form, because the conclusion that a system is low-impact is itself a conclusion that has to be documented.
The risk register carries separate consequence columns for the organisation, for individuals and for societies, with the highest driving the level. A single organisational scale would quietly discard exactly what ISO 42001 exists to capture.
Per system, in operational terms: who reviews, what they see, what they can change. With the measure that reveals nominal oversight — how many outputs were overridden in the last hundred.
Same template, same section skeleton and same conventions as our ISO 27001 suite. The six shared processes reference what you already run instead of creating a parallel set, and Annex D of the standard anticipates exactly this.
No. It is a voluntary management system standard. It is increasingly asked for in enterprise procurement and in security questionnaires, and it builds most of the machinery the EU AI Act's obligations run on — but the Act is assessed against the Act, not against the standard.
Most of the management system clauses and very little of Annex A. Eight requirements transfer fully, seven partially, and the AI system impact assessment has no equivalent at all. This suite is written to reference an existing management system rather than duplicate it.
Yes, pre-populated with all 38 Annex A controls, each with the field for the applicability decision and the justification. Exclusions need a justification as much as inclusions do, which is where most Statements of Applicability fail.
It asks what consequences the system has for individuals, for groups of individuals and for societies — including when it works exactly as designed. A model that performs well overall and worse for one subgroup has not failed in the risk sense. The assessment feeds the risk process; it does not replace it.
Yes. Annex D of ISO 42001 explicitly names ISO 13485 and IEC 62304 among the sector standards an AI management system integrates with. The shared processes in this suite reference your existing document control, internal audit and corrective action rather than creating a second set.
The documentation is weeks. The records are months, because a certification body samples evidence produced across a period. Six to nine months from a standing start is a realistic planning assumption; organisations that already hold ISO 27001 move faster.
Editable DOCX for procedures and forms, XLSX for the registers. No locked templates, no portal, no subscription. You download them and they are yours.
€590 excl. VAT · 39 files · Instant download · Lifetime free updates.