Today we are launching ISO 42001 on RateYourCyber.
Over the past year we have spoken to organisations of every size about AI governance. Almost all of them are using AI in some form. Very few can demonstrate that it is being governed in a structured, auditable way.
That is the challenge ISO/IEC 42001 was created to solve. It is not another AI policy or checklist. It is the first certifiable management system standard for AI, providing a framework for governing AI systems with the same discipline organisations apply to information security or quality management.
We built our ISO 42001 module to help organisations move from good intentions to demonstrable evidence.
AI system inventory with EU AI Act classification
The module starts where governance starts: knowing what you have. The AI System Inventory records every system with its EU AI Act risk classification, ownership, lifecycle stage, data sources, degree of autonomy and the human oversight applied to it.
Impact assessments with mandatory sign-off
AI System Impact Assessments run forty questions across eight impact areas, with mandatory sign-off and a 1,000-point scoring model, so the question "what could this system do to people, and who accepted that risk" has a documented answer.
The full standard, measured for maturity
The assessment covers all 38 Annex A controls and 32 clause requirements, each scored across five maturity levels with clear evidence requirements and policy tracking. Conformity tells you whether a control exists; maturity tells you how well it runs. The module measures both and keeps them separate, because compliance and capability are different measures.
Statement of Applicability, generated
The Statement of Applicability is produced automatically from the assessment: control applicability, justification and implementation status, ready for a certification body.
Gaps that become work, with a price on inaction
Gap management turns findings into implementation tasks with owners and deadlines. Where it helps the business case, gaps can be quantified as financial exposure using FAIR annualised loss expectancy, so the board sees what an ungoverned AI system costs, not just that one exists.
Assurance built in
Internal audits, red teaming, bias testing, robustness testing, penetration testing and structured management reviews are aligned with ISO 42001, giving the management system the assurance loop the standard expects.
Executive reporting, in English and Arabic
Executive reporting separates conformity from maturity throughout, and the entire module is available in English and Arabic.
Govern AI with evidence, not intentions
The ISO 42001 module is available now on RateYourCyber
Get StartedWhy now
As AI adoption accelerates, organisations will increasingly be expected to show that governance is systematic, measurable and auditable, and ISO 42001 is designed to support exactly that. If you want to understand the standard itself, our ISO 42001 glossary entry covers what an AI management system is and who needs one, alongside related coverage of ISO 27001 and NIS2.