ISO/IEC 42001 on AI agents.
The certifiable AIMS, the Annex SL chassis shared with ISO/IEC 27001, and the sampleable record the controller produces toward an audit.
What does ISO 42001 require for AI agents
Requirement, controller, artifact.
Requirement names the instrument. What GW Slate™ does is the existing controller capability. The artifact is what an auditor samples. Counsel decides what an obligation requires of a given deployment.
| Requirement | What GW Slate™ does | The artifact an auditor samples |
|---|---|---|
| Operate an AI management system (AIMS) under ISO/IEC 42001:2023. | GW Slate™ is the Sovereign Orchestrator: brand-aligned intelligence rails that hold identity, policy, runtime, and receipts over the stack you already run. Hybrid is the default posture. Quiet governance, visible proof — every material action is accountable before it becomes business truth. | The four rails on the run: identity says who, policy says may, runtime says enforced, receipts say happened. |
| Annex SL chassis shared with ISO/IEC 27001 — existing ISMS work transfers. | Four rails — identity says who, policy says may, runtime says enforced, receipts say happened. | The versioned policy pack and the identity bound to every governed action. |
| ISO/IEC 23894 — AI risk management guidance. | Sovereign Orchestrator — scopes authority per action and holds policy as a hard constraint in code. | The per-action verdict sealed on the Actuality Receipt — allow, deny, or human. |
| ISO/IEC 38507 — board governance of AI. | GW Slate™ is the modular controller and human command surface. It routes each task to the model that fits, holds authority and policy on the controller, and runs multi-agent workflows to completion. | The Actuality Receipt a board packet can sample: who acted, under which policy, with what outcome. |
| CSA AI Controls Matrix v1.1 — published AICM-to-ISO 42001 mapping. | GW Slate™ runs multi-agent workflows across the systems you already run, using custom MCP rails and open interoperability standards so agents coordinate across otherwise disconnected AI ecosystems. Workflows scale dynamically and your risk-management posture holds, because every route is policy-gated and every action carries a receipt. | The tamper-evident cryptographic record Receipt Rail™ emits for every governed action. |
Last reviewed: 2026-09-08
Questions
01What does ISO 42001 require for AI agents?
ISO/IEC 42001:2023 is the certifiable AI management system (AIMS). An organization operates policies, processes, and controls over AI. GW Slate™ produces the identity, policy, runtime, and Actuality Receipt record an auditor samples toward that audit.
02What does GW Slate™ produce toward an ISO 42001 audit?
GW Slate™ holds identity, policy, runtime, and receipts over the stack you already run. Every governed action emits a verifiable, tamper-evident receipt through Receipt Rail™ — the artifact an auditor samples.
03How does ISO/IEC 27001 work transfer into an AIMS?
ISO/IEC 42001:2023 uses the Annex SL chassis shared with ISO/IEC 27001, so existing ISMS work transfers. The controller keeps the same four rails — identity, policy, runtime, and receipts — as the operating record.
04Which other ISO AI documents sit beside 42001?
ISO/IEC 23894 supplies AI risk management guidance. ISO/IEC 38507 supplies board governance of AI. The Cloud Security Alliance AI Controls Matrix v1.1 publishes an AICM-to-ISO 42001 mapping.
Continue the work
Diagnostic Sprint, then Department, then Sovereign Enterprise.
$7,500 standard / $10,000 regulated, 100% creditable.
Govern, Map, Measure, Manage on agentic systems.
GPAI, Article 50, and high-risk timing.
Operational controls inside the workflow.
The controller that holds identity, policy, runtime, and receipts.