Menu

Standard Mapping

ISO/IEC 42001
evidence, produced at runtime.

ISO/IEC 42001 specifies requirements for an AI management system. Certification covers the organization's management system, not a vendor's product — but the operational evidence that system needs has to come from somewhere. This maps where KriftAI supplies it.

Context

What certification covers, and what this page claims

ISO/IEC 42001 is a certifiable management-system standard for artificial intelligence, structured like ISO 27001 for information security. An accredited certification body audits an organization's AI management system against it.

The certificate belongs to the organization operating the management system. A platform cannot confer it, and no tool makes an organization compliant on its own — the standard asks for policy, roles, risk process, and continual improvement alongside operational controls.

What a platform can do is supply the operational evidence the management system depends on: records of what the AI did, who could access it, what was blocked, and under which policy. This page maps those contributions.

Operational Control

Controls that execute rather than describe

A management system requires that planned controls actually operate. These execute on every governed call.

Input controls

Prompt-injection detection across seven threat categories, evaluated before model invocation, with high-severity matches blocking the call.

Output controls

Universal and workspace-specific response rules with block, redact, and warn severities, applied before delivery.

Access control

Organization, workspace, and group role layers, plus default-deny tool gating and database-level tenant isolation.

Failure posture

Configurable fail-open or fail-closed behaviour when a control cannot execute, set per organization.

Documented Information

Records the management system can rely on

Management-system standards depend on documented information that is controlled, retrievable, and protected from unintended alteration.

Per-call record

One immutable ledger row per governed call — identity, persona, workspace, action, model, provider, token estimate, and governance verdict.

Retention control

Content-logging mode determines how much interaction content is retained: full, SHA-256 fingerprint, or metadata only.

Retrieval

Traceability feed with flagged-only filtering, plus full export as JSON or CSV with fixed column order, optionally scoped since a date.

Disposal

Owner-initiated certified deletion produces a tamper-evident SHA-256 certificate covering organization, requester, timestamp, row count, scope, and cutoff.

Human Oversight

Oversight as a recorded process

The standard expects human oversight to be defined and evidenced, not assumed.

Defined authority

Override authority is explicit — escalations require an admin decision, and reviewer identity is captured with notes.

Escalation lifecycle

Pending, approved, denied, or expired, with a queue listing outstanding requests oldest-first.

Decisions as records

Override outcomes write their own audit rows carrying the escalation ID, so oversight activity is auditable alongside the calls it governs.

Boundaries

What an adopting organization still has to supply

A mapping page that shows only coverage is not useful to someone actually pursuing certification.

The standard requires organizational elements no platform provides: AI policy signed off by leadership, defined roles and competencies, a documented risk assessment methodology, internal audit programme, management review, and continual improvement process.

Operational evidence for your management system

See which records, controls, and oversight processes the governance layer produces automatically.