ISO/IEC 42001:2023. AI GOVERNANCE THAT OPERATES.
ISO 42001 AI Governance Software for US Teams
Connect AI Use, Risk and Accountability Across US Operations
ZEBSOFT AI governance software helps US teams establish and operate an Artificial Intelligence Management System (AIMS) using ISO/IEC 42001. Connect AI inventories, owners, assessments, suppliers, approvals and evidence across business units, with configurable workflows supporting your chosen governance approach.
The platform controls how governance work moves. It does not decide whether an AI system is acceptable, invent evidence or replace competent human judgment.

STANDARDS, GUIDANCE AND APPLICABLE REQUIREMENTS
Separate Management Standards, Risk Guidance and Legal Duties
A current AI governance program must distinguish the management-system standard from impact-assessment guidance, certification rules and applicable law. These sources can reinforce one another, but they are not interchangeable.
ISO/IEC 42001 certification does not by itself establish legal compliance. Assess applicable requirements for each AI system, use, market and responsible entity.
A MANAGEMENT SYSTEM—NOT A PRODUCT CLAIM
What ISO/IEC 42001 Does and Does Not Mean
ISO/IEC 42001 uses a management-system approach. It asks the organization to understand its context, lead and plan the AIMS, support and operate it, evaluate performance and improve. The standard is designed to be applicable to organizations that develop, provide or use AI systems.
THE OPERATING STRUCTURE
Run Clauses 4–10 as One Connected AIMS
ISO/IEC 42001 follows the familiar management-system structure. The clauses should work together around real AI systems and decisions rather than exist as isolated policy documents.
KNOW WHICH AI YOU GOVERN
Build a Usable AI System Inventory
An AIMS cannot govern an AI estate that nobody can describe. The inventory should cover internally developed systems, third-party services, embedded AI features, general-purpose models, automated decision support and approved employee uses.
ZEBSOFT relates the inventory to ownership, affected parties, suppliers, risks, assessments, obligations, controls, incidents, changes and evidence.

ASSESS EFFECTS BEFORE AND DURING USE
Connect ISO/IEC 42005 Impact Assessment to AI Risk Management
ISO/IEC 42005:2025 provides lifecycle guidance for assessing foreseeable impacts on individuals, groups and society. ISO/IEC 23894:2023 provides guidance on AI risk management. ZEBSOFT can connect both forms of analysis to the AIMS without pretending they are the same exercise.
The system preserves inputs, reasoning, evidence, consultation, assumptions and approvals. Competent people determine assessment conclusions and whether the remaining risk and impact are acceptable.
CONTROL THE COMPLETE AI LIFECYCLE
Govern the Decision Route From Proposal to Retirement
AI governance fails when approval is treated as the end of the process. Models, data, suppliers, usage and legal expectations change. The control route must continue while the system is in use.
GENERATIVE AI NEEDS OPERATING CONTROLS
Move Beyond a Generic AI Acceptable-Use Policy
A policy can state expectations, but it cannot prove how specific tools and uses are approved, monitored and changed. Generative AI requires controls around information, output, human review, disclosure and provider dependency.
NIST AI RMF: CONNECT RISK GUIDANCE TO OPERATIONS
Put Govern, Map, Measure and Manage Into Practice
The voluntary NIST AI RMF organizes AI risk management around four functions. Configure responsibilities, records and review routes to support relevant outcomes; using the framework does not confer ISO certification or establish legal compliance.
THIS IS HOW WE SOLVE THE PROBLEM
Put a Controlled Route Around Every Important AI Decision
Most organizations already have AI policies, risk templates, supplier questionnaires and project approvals. The weakness is that the controls are separated from the systems, people and changes they are meant to govern.
Humans remain responsible for the decisions, work, approvals and consequences. AI may assist analysis; it does not acquire organizational accountability.
CERTIFICATION READINESS
Operate the AIMS While Preserving Certification Independence
ISO/IEC 42006:2025 sets additional requirements for bodies that audit and certify AIMS. ZEBSOFT can help the organization prepare and present controlled evidence, but certification remains an independent conformity-assessment decision.
ZEBSOFT does not certify organizations and cannot guarantee certification. It helps responsible people demonstrate how the AIMS is controlled, operated, evaluated and improved.
CONNECT GOVERNANCE WITHOUT COLLAPSING INTENT
Integrate AI Governance With Security, Privacy, Quality and Risk
An AIMS can share organizational processes with other management systems, but each standard and legal duty retains its own scope, criteria and evidence.
MOVE FROM POLICY PACKS TO OPERATING GOVERNANCE
Migrate Without Losing Ownership, Evidence or History
ZEBSOFT can replace or connect fragmented spreadsheets, SharePoint lists, policy folders, ticketing tools and supplier files. Migration should improve control, not merely copy old disorder into a new database.
The migration plan can be phased by AI risk, business unit or lifecycle state. Live high-impact systems and imminent regulatory duties should not wait behind low-value historical cleanup.
CONTROLLED EVIDENCE
Make AI Governance Verifiable From the Work Itself
A customer, auditor, regulator or governing body should be able to follow a reported position back to the system, assessment, control, evidence and authorized human decision.
| AI governance activity | Fragmented approach | ZEBSOFT controlled operation |
|---|---|---|
| AI system inventory | A spreadsheet with uncertain ownership and status | Each system has a purpose, owner, role, provider, lifecycle state, affected parties and linked obligations |
| Impact and risk assessment | A one-off document prepared before approval | Assessment conclusions, assumptions, controls, owners, evidence and review triggers remain connected |
| Deployment decision | Informal sign-off in email or a project meeting | Named competent people review defined criteria, record conditions and retain an authorized decision |
| Supplier or model change | Updates are discovered after behavior or terms change | Change triggers reassessment, testing, approval, communication and monitoring |
| Assurance | Evidence is reconstructed for audit or customer review | Dashboards and reports trace to current records, exceptions, decisions and human accountability |
PRACTICAL QUESTIONS
ISO 42001 AI Management System Software FAQs
Use the licensed standards, current regulator information and competent professional advice when determining exact requirements.
What is ISO/IEC 42001:2023?
It is the current international requirements standard for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System.
Does ZEBSOFT certify an AIMS?
No. ZEBSOFT supports implementation, operation, evidence, audit and improvement. An independent competent certification body reaches the certification decision.
Is ISO/IEC 42005 part of ISO/IEC 42001?
It is a separate 2025 guidance standard for AI system impact assessment. It complements ISO/IEC 42001 and can strengthen the organization’s impact-assessment method.
Does every AI system need the same controls?
No. The organization determines proportionate controls from context, use, effects, risk, obligations and lifecycle stage. It must consider relevant Annex A control objectives and justify its approach.
Can we govern third-party and embedded AI?
Yes. The inventory and supplier processes can cover hosted tools, models, APIs and AI embedded in wider products, with controls reflecting the organization’s actual role and influence.
Does ISO 42001 certification prove EU AI Act compliance?
No. Certification can support structured governance and evidence, but legal compliance depends on the applicable provisions and facts of each organization and AI system.
How can US teams use the NIST AI RMF?
Use the voluntary framework to organize AI risk work through Govern, Map, Measure and Manage. Map relevant outcomes to owners, assessments, controls and review evidence; it is not a certification scheme.
Can AI complete our governance records?
AI may help authorized users interrogate and analyze approved information. Humans remain responsible for assessments, controls, evidence, approvals, interpretations and decisions.
Can we integrate ISO 42001 with ISO 27001?
Yes. Common processes can be connected while the AIMS and ISMS retain their own scope, specialist requirements, risks, controls and audit conclusions.
Where can we verify the current position?
See the official ISO/IEC 42001 page, ISO/IEC 42005 page, ISO/IEC 42006 page, the European Commission AI Act enforcement timeline, the NIST AI RMF and current guidance from the relevant US regulators.
BRING ONE REAL AI USE CASE
See How ZEBSOFT Makes AI Governance Operable and Verifiable
Bring one AI use case from your US operations, such as automated inspection, customer support or an employee AI tool. Explore inventory, assessment, approval and monitoring workflows, and discuss rollout, time-zone coordination and data-location needs with our UK-based team.

