Skip to content

ISO/IEC 42001

Gamut supports work towards an ISO/IEC 42001 AI management system, with implementation guidance aligned to the standard’s clause headings and control themes.

ISO/IEC 42001 is the management-system standard for artificial intelligence, the AI equivalent of management-system standards in other domains. It frames AI governance as a managed system with policy, objectives, controls and continual improvement, rather than a one-off exercise. That framing maps directly onto Gamut’s governance lifecycle, which is itself built around continual improvement.

Gamut organises ISO/IEC 42001 work into eight sections, following the standard’s structure: the management-system clauses 4 to 10, plus the Annex A controls.

SectionClauseThemes covered
Context of the organisationClause 4Understanding the organisation, interested parties and the scope of the AI management system.
LeadershipClause 5Leadership and commitment, AI policy, roles and responsibilities.
PlanningClause 6AI risk assessment and treatment, AI system impact assessment, objectives.
SupportClause 7Resources, competence, awareness, communication and documented information.
OperationsClause 8Operational planning and control, risk assessment and treatment in operation.
Performance evaluationClause 9Monitoring, measurement, internal audit and management review.
ImprovementClause 10Nonconformity, corrective action and continual improvement.
Annex A controlsAnnex AThe reference set of AI-specific controls (23 control themes).

Gamut carries detailed clause-level mappings (33 mapped clauses) so that assessment work and evidence attach to the right part of the standard.

  • Clause-aligned assessment, organised around clauses 4 to 10 and Annex A.
  • Evidence management, the evidence and findings model a management system needs to demonstrate operation.
  • Continual improvement, the Improve stage, tracking remediation and change over time.
  • Management review, reporting outputs that support clause 9 review.

ISO/IEC 42001 work shares evidence with GTSAF (every GTSAF control carries ISO/IEC 42001 clause anchors), NIST AI RMF and the EU AI Act. Impact assessment under clause 6 aligns with ISO/IEC 42005. See the GTSAF crosswalk table.