Scrydon
Compliance

ISO/IEC 42001

How Scrydon supports an AI Management System under ISO/IEC 42001 — the AI-specific counterpart to ISO 27001.

ISO/IEC 42001 is the international standard for AI management systems. It complements ISO 27001 by adding AI-specific lifecycle, risk, and governance requirements.

This page maps Scrydon's controls to ISO 42001's clauses.

Scope

ISO 42001 governs how an organisation manages its AI systems — risk, lifecycle, transparency, post-deployment monitoring. Like ISO 27001, the standard is organisational. Scrydon provides the platform-side artefacts that make conformance evidenceable.

Clause coverage

Clause 6 — Planning

RequirementScrydon support
6.1.2 AI risk assessmentStructured impact-and-risk assessment artefacts per workflow / agent. See AI governance.
6.1.3 AI risk treatmentRego policies, mask strategies, guardrails block. See DLP.
6.1.4 AI system impact assessmentPer-system impact assessment template. See AI governance → Impact assessment.

Clause 7 — Support

RequirementScrydon support
7.3 AwarenessInline help, doc cross-references, hover-tooltips on every governance control.
7.4 CommunicationAudit log forwarder, change-management events.
7.5 Documented informationThis documentation site + machine-readable manifests for every component.

Clause 8 — Operation

RequirementScrydon support
8.2 AI lifecycleWorkflow versioning, ontology branches, deployment events. See Branches & proposals.
8.3 Data qualityManaged-table profiles, classification, evaluator block. See Schema inference.
8.4 Bias / fairnessBias-fairness evaluation hooks. See AI governance → Bias & fairness.
8.5 TransparencyPer-instance provenance from the ontology layer. See Bindings.

Clause 9 — Performance evaluation

RequirementScrydon support
9.1 MonitoringPlatform metrics + workflow run logs + audit log.
9.2 Internal auditAudit log queryable with structured filters. See Audit logging.
9.3 Management reviewDecisions log + quarterly review template. See AI governance.

Clause 10 — Improvement

RequirementScrydon support
10.1 Continual improvementContinuous-improvement record template.
10.2 Nonconformity & corrective actionFindings + action-items template.

AI-specific artefacts

ISO 42001 expects evidence specific to AI systems. The platform provides templates and emits some automatically:

ArtefactWhat it captures
AI system inventoryEvery deployed workflow + its capabilities, owner, classification
Impact assessmentThe business impact, affected stakeholders, mitigations
Risk assessmentThe AI-specific risks (hallucination, bias, data leakage) and treatments
Validation recordPre-deployment validation outcomes (evaluator scores, test runs)
Post-deployment monitoringRun logs, evaluator scores, anomaly detection signals
Decommissioning recordWhen and why a workflow was retired

These templates live in the AI governance section and are auditable through the audit log.

  • AI governance — the AI-specific lifecycle artefacts.
  • ISO 27001 — the information-security baseline.
  • EU AI Act — overlaps significantly with 42001's risk and transparency controls.
  • NIST AI RMF — alternative AI risk framework.
On this page

On this page