NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
ISO 42001 compliance software

The AI management system you can certify.

Venvera is ISO 42001 compliance software that runs the AI management system ISO/IEC 42001:2023 asks for: all 38 Annex A controls with the evidence each one expects, the clause 6.1.2 risk assessment and the clause 6.1.4 impact assessment kept apart, and a Statement of Applicability that follows from your own decisions.

Clauses 4 to 1038 Annex A controls9 control objectivesStatement of ApplicabilityAI impact assessment

How much of ISO 42001 do you already have?

Pick the framework you already run. Every control domain that appears in both is listed with the requirement reference on each side, so you can see the reusable part of your existing programme before you scope any new work.

You already run
You have been asked to add
10 of the 53 domains in this crosswalk appear in both EU AI Act and ISO 42001.
DomainEU AI ActISO 42001
AI Impact Assessment
Art. 9(1)Has the organisation established, implemented, documented and maintained a risk management system for high-risk AI systems throughout their lifecycle?
Art. 9(2)(a)Are known and reasonably foreseeable risks identified, analysed and estimated for each high-risk AI system?
Art. 9(9)Are impacts on children, vulnerable groups and persons with disabilities specifically assessed in the risk management process?
A.5.2AI system impact assessment process
A.5.3Documentation of AI system impact assessments
A.5.4Assessing AI system impact on individuals or groups of individuals
AI System Requirements
Art. 15(1)Are high-risk AI systems designed and developed to achieve an appropriate level of accuracy, robustness and cybersecurity throughout their lifecycle?
Art. 15(3)Is the AI system resilient to errors, faults, or inconsistencies that may occur within the system or its operating environment?
A.6.2.2AI system requirements and specification
AI Design & Development Documentation
Annex IV(2)Are the design specifications, general logic, algorithms, key design choices, and classification methodology documented?
A.6.2.3Documentation of AI system design and development
AI Verification & Validation
Art. 9(5)–(7)Is the AI system tested to identify appropriate risk management measures and ensure consistent performance?
Annex IV(3)Are performance metrics, validation and testing procedures, and their results documented with clearly defined and explained metrics?
A.6.2.4AI system verification and validation
AI Technical Documentation
Art. 11(1)Is technical documentation drawn up before the AI system is placed on the market or put into service, and kept up to date?
Annex IV(1)Does the technical documentation contain a general description of the AI system including intended purpose, developer identity, version, and how it interacts with hardware/software?
Art. 11(2)Is the documentation maintained in a format suitable for assessment by conformity assessment bodies and market surveillance authorities?
A.6.2.7AI system technical documentation
AI Event Logging
Art. 12(1)Are high-risk AI systems designed and developed with capabilities enabling automatic recording of events (logs) throughout the system's lifetime?
Art. 12(2)Do logging capabilities enable monitoring of the system's operation with respect to the occurrence of situations that may result in risks to health, safety, or fundamental rights?
A.6.2.8AI system recording of event logs
AI Data Governance
Art. 10(2)Are training, validation and testing datasets subject to appropriate data governance and management practices?
A.7.2Data for development and enhancement of AI systems
A.7.6Data preparation
AI Data Quality
Art. 10(3)Are datasets relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose?
A.7.4Quality of data for AI systems
AI Data Provenance
Art. 10(2)(c)Is the provenance, origin, and legal basis of all training datasets documented and traceable?
A.7.3Acquisition of data
A.7.5Data provenance
Information for AI System Users
Art. 13(1)Are high-risk AI systems designed and developed to ensure their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately?
Art. 13(3)(a)–(b)Are instructions of use provided with each high-risk AI system, including the provider's identity, system characteristics, capabilities, and limitations of performance?
Art. 13(3)(b)(ii)Do instructions clearly describe the level of accuracy, robustness and cybersecurity against which the system has been tested, and any known limitations?
A.8.2System documentation and information for users

A row means the two requirements cover the same ground, so one implementation and one set of evidence can usually serve both. It does not mean satisfying one certifies the other: each framework keeps its own scope, wording and assessment, and some requirements have no counterpart at all. Treat this as a starting map for planning, then confirm each row against the requirement text.

ISO 42001 compliance software with the full Annex A control set

Venvera is ISO 42001 compliance software for building and running an AI management system against ISO/IEC 42001:2023. It ships all 38 Annex A controls under the nine objectives the standard numbers A.2 to A.10, each with authored evidence guidance, an owner and a status, and it scores the management system itself across clauses 4 to 10 with a 50-question gap assessment. Your applicability decisions produce the Statement of Applicability, the recurring duties the standard creates land on a compliance calendar with owners and dates, and a board report summarises the position for the management body. Where the standard overlaps the EU AI Act, evidence propagates across ten mapping groups instead of being produced twice.

What is ISO 42001, and who is asking you for it?

ISO/IEC 42001:2023 is the international standard for AI management systems, and it is certifiable by an accredited body, which makes it the first AI standard someone can ask you to hold rather than claim. It is built the way ISO 27001 is: clauses 4 to 10 set the management system requirements, from context and leadership through planning, support, operation, performance evaluation and improvement, and Annex A carries 38 controls under nine objectives numbered A.2 to A.10. Certification runs a three-year cycle with annual surveillance audits, the same rhythm as ISO 27001. It is asked for by enterprise buyers who now put AI questions into vendor review, by boards that want AI governance to be a system rather than a series of arguments between legal, the model owners and whoever signed the vendor contract, and by organisations operationalising the EU AI Act, which assumes this machinery exists without requiring this certificate.

 app.venvera.com
/ ISO 42001 · clauses, controls and evidence in one view
/ ISO 42001 · clauses, controls and evidence in one view
38
Annex A controls, each with guidance
9
Control objectives, A.2 through A.10
50
Gap questions across clauses 4 to 10
2023
ISO/IEC 42001 edition supported
Annex A

All 38 Annex A controls, with the evidence each one expects.

Every control in ISO/IEC 42001:2023, grouped under the nine objectives the standard numbers A.2 to A.10: policies related to AI, internal organization, resources for AI systems, assessing impacts of AI systems, AI system life cycle, data for AI systems, information for interested parties of AI systems, use of AI systems, and third-party and customer relationships. Each control carries authored guidance on what would satisfy it, an owner, a status and its own evidence, so the control set is a working record rather than a list somebody still has to interpret.

  • All 38 controls under the nine Annex A objectives
  • Authored evidence guidance written for each control
  • An owner, a status and its own evidence on every control
  • Applicability decisions recorded with the reasoning behind them
  • Control reviews scheduled, so the record does not go stale
 app.venvera.com
/ CONTROLS · an owner, a status and the evidence on each one
/ CONTROLS · an owner, a status and the evidence on each one
Clauses 4 to 10

Score the management system, not only the controls.

Annex A is half of ISO 42001. Clauses 4 to 10 are the other half and the part you certify against: context, leadership, planning, support, operation, performance evaluation and improvement. Venvera scores those with a 50-question gap assessment, so you can see whether the management system itself would survive an audit rather than only whether the controls are in place. What comes back is a ranked list of what is missing, re-scored as the work lands instead of frozen on the day a consultant visited.

  • A 50-question gap assessment across clauses 4 to 10
  • Context, leadership, planning, support, operation, evaluation, improvement
  • A ranked list of gaps rather than a narrative report
  • Re-scored as the work lands, not fixed at the assessment date
  • Findings link through to the controls and duties that close them
 app.venvera.com
/ GAP ASSESSMENT · clauses 4 to 10, scored
/ GAP ASSESSMENT · clauses 4 to 10, scored
Clause 6.1

The risk assessment and the impact assessment are not one document.

Clause 6.1.2 asks for an AI risk assessment: risks to the organisation and to the intended outcomes of the management system. Clause 6.1.4 asks for an AI system impact assessment: the consequences of an AI system for individuals, groups of individuals and societies. They answer different questions for different audiences, and an auditor expects to see both. Venvera keeps them as separate records with separate owners and separate review dates, so neither gets quietly absorbed into the other, which is the most common way an ISO 42001 programme comes apart at the audit.

  • Clause 6.1.2 AI risk assessment, scored and treated
  • Clause 6.1.4 impact assessment on individuals, groups and societies
  • Separate owners, separate records, separate review cycles
  • Risk treatment decisions feed the Statement of Applicability
  • Both reviews carried on the compliance calendar
 app.venvera.com
/ RISK · assessed and treated, and kept apart from impact
/ RISK · assessed and treated, and kept apart from impact
Applicability

A Statement of Applicability that follows from your decisions.

Certification turns on the Statement of Applicability: which of the 38 Annex A controls apply, which do not, and why. Venvera builds it from the decision already recorded against each control, with the justification and the evidence attached, so the document an auditor reads is the record your team works in rather than a parallel spreadsheet written the week before. Change an applicability decision and the statement changes with it, and its review sits on the calendar like every other recurring duty.

  • Generated from the applicability decision on each control
  • Justification recorded for inclusion and for exclusion
  • Evidence attached to the control, not to a separate document
  • Changes tracked, so the statement is never rebuilt from memory
  • Statement of Applicability review scheduled as a recurring duty
 app.venvera.com
/ APPLICABILITY · decisions recorded with their evidence
/ APPLICABILITY · decisions recorded with their evidence
Calendar

The duties that keep the certificate alive, each on a date.

ISO 42001 does not stop at the certificate. It runs on a three-year cycle with annual surveillance audits, and the year in between has to produce a record. Venvera carries the recurring duties on the compliance calendar with an owner, a task and a reminder: the internal audit, the management review, the AI risk assessment, the impact assessment review, the policy review, the Statement of Applicability review, the competence review and the surveillance audit itself. A board report summarises the position for the management body when the management review comes round.

  • Internal audit and management review scheduled and owned
  • AI risk assessment and impact assessment reviews carried yearly
  • Policy, Statement of Applicability and competence reviews tracked
  • The surveillance audit on the calendar before it arrives
  • Board report generated for the management body
 app.venvera.com
/ CALENDAR · the recurring duties, owned and dated
/ CALENDAR · the recurring duties, owned and dated
EU AI Act

Do the overlap with the AI Act once.

An AI management system is how an organisation operationalises its EU AI Act obligations, but certification to ISO 42001 is not conformity with the regulation and nobody should sell it to you as though it were. What Venvera does is stop you producing the shared work twice: evidence propagates between ISO 42001 and the EU AI Act across ten mapping groups, covering impact assessment, system requirements, design documentation, verification and validation, technical documentation, event logging, data governance, data quality, data provenance and information for users. Where the two diverge, the gap stays visible instead of being papered over.

  • Ten mapping groups between ISO 42001 and the EU AI Act
  • Impact assessment, system requirements and design documentation
  • Verification and validation, technical documentation, event logging
  • Data governance, data quality and data provenance
  • Information for users, with each side keeping its own reference
 app.venvera.com
/ CROSSWALK · one control, every requirement it answers
/ CROSSWALK · one control, every requirement it answers
Why switch

The spreadsheet or Venvera.

Manual approach
Venvera
Annex A controls
Spreadsheet of 38 rows, guidance looked up per control
38 controls with authored evidence guidance, owner and status
Clauses 4 to 10
A consultant assessment that is stale by the next month
50-question gap assessment, re-scored as the work lands
Risk and impact
One document asked to do both jobs
Clause 6.1.2 and clause 6.1.4 kept as separate records
Statement of Applicability
Rebuilt by hand before each audit
Generated from the applicability decision on each control
Recurring duties
Calendar invites and whoever remembers
Scheduled obligations with an owner, a task and a reminder
EU AI Act overlap
The same evidence produced twice
Propagation across ten mapping groups, gaps left visible

ISO 42001, answered.

ISO 42001 and AI governance guides

See how far your AI governance already is.

Start with a free gap report on the framework that is blocking you - 10 minutes, no email to start.

Every paid plan: audit-ready in 90 days, or your money back*

10 minutes · no email to start · no credit card · yours to keep