AI governance · ISO/IEC 42001:2023

ISO 42001 software built for consultants who run AI governance for clients

Your clients are shipping AI features and their customers are asking about AI governance. NovaGRC gives you all 38 ISO 42001 Annex A controls — plus NIST AI RMF and the EU AI Act — in a separate workspace per client.

Live sandbox with sample data — no signup, no credit card.

Why AI governance engagements stall

No catalogue to start from

Most teams rebuild the ISO 42001 control list by hand from the standard for every engagement.

AI work lives apart from the rest

AI risks sit in one spreadsheet while ISO 27001 and SOC 2 controls live in another, so overlap is never mapped.

Reporting takes days

Turning a gap assessment into a client-ready readiness report is manual formatting work.

How NovaGRC handles ISO 42001

All 38 Annex A controls pre-loaded

A.2 through A.10 — AI policy, impact assessment, lifecycle, data, transparency, and third-party relationships — ready the moment you create a plan.

NIST AI RMF and EU AI Act alongside

Run the frameworks your client actually needs, side by side, with cross-framework mapping to ISO 27001 and SOC 2.

Evidence, owners, and testing

Assign control owners, attach evidence once and link it everywhere, and schedule control tests with pass/fail history.

AI risks in the same register

Log model bias, data leakage, and vendor-AI risks in the 5×5 risk register and link them to the controls that treat them.

Separate workspace per client

Isolated data and branding for every client, all visible from one multi-client dashboard.

White-label readiness reports

Generate a client-branded readiness report from the live data instead of rebuilding it in Word.

Free: ISO 42001 Readiness Checklist

All 38 Annex A controls, grouped by objective, with a plain-English description of what an auditor expects to see. Use it for your next AI governance gap assessment.

No spam. One email with the checklist; unsubscribe any time.

Frequently asked questions

What is ISO 42001?

ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS). It sets requirements for governing how an organization develops, provides, or uses AI, and includes 38 Annex A controls across nine objectives.

Does NovaGRC certify my client for ISO 42001?

No. Certification is issued by an accredited certification body. NovaGRC is where you run the readiness work — control tracking, evidence, risk treatment, and reporting — before the audit.

Can I run ISO 42001 together with ISO 27001?

Yes. Both catalogues are built in, and cross-framework mapping shows where work on one carries over to the other.

Is there a free way to try it?

Yes. The live sandbox opens in one click with sample data and no signup, and the Starter plan is free.

See it with real sample data.

Open the live sandbox in one click, or request a tailored walkthrough.