AIUC-1

AIUC-1 × ISO 42001

ISO 42001 is an international standard for AI management systems (AIMS) covering responsible AI development and deployment.

AIUC-1 aligns with ISO 42001. Certification against AIUC-1:

Incorporates the majority of controls from ISO 42001

Translates ISO's management system approach into concrete, auditable requirements

Extends ISO 42001 with third-party testing requirements of, e.g., hallucinations and jailbreak attempts

Addresses additional key concerns such as AI failure plans and AI-specific system security

ISO 42001 crosswalks by clause

ISO control objective

4.1: Understanding the organization and its context

ISO control

The organization shall determine external and internal issues relevant to the AI management system’s purpose and ability to achieve intended results.

Gap analysis
Partial Gap
AIUC-1 is focused on defining acceptable use and assessing risk of the AI system
ISO control objective

4.2: Understanding the needs and expectations of interested parties

ISO control

The organization shall determine interested parties and their relevant requirements to the AI management system.

Relevant AIUC-1 requirements
Gap analysis
Full Gap
Outside the scope of AIUC-1
ISO control objective

4.3: Determining the scope of the AI management system

ISO control

The organization shall define and document the scope of the AI management system, including applicability and boundaries.

Gap analysis
No Gap
ISO control objective

4.4: AI management system

ISO control

The organization shall establish, implement, maintain, and continually improve the AI management system.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Met by organizations that opt-in to the optional quality management system requirement
ISO control objective

5.1: Leadership and commitment

ISO control

Top management shall demonstrate leadership and commitment to the AI management system and its effectiveness.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

5.2: AI policy

ISO control

Top management shall establish an AI policy appropriate to the organization and supportive of AI objectives.

Gap analysis
No Gap
AI Acceptable Use Policy and Transparency Policy collectively fulfil the ISO control. Organizations may develop a standalone AI policy
ISO control objective

5.3: Roles, responsibilities and authorities

ISO control

Top management shall assign roles, responsibilities, and authorities for the AI management system.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

6.1.1: Actions to address risks and opportunities — General

ISO control

The organization shall plan actions to address risks and opportunities, integrate them into processes, and evaluate their effectiveness.

Gap analysis
No Gap
ISO control objective

6.1.2: AI risk assessment

ISO control

The organization shall establish and maintain a process for AI risk assessment, including identification, analysis, and evaluation of risks.

Gap analysis
No Gap
ISO control objective

6.1.3: AI risk treatment

ISO control

The organization shall establish and maintain a process for AI risk treatment, including selecting and implementing necessary controls.

Gap analysis
No Gap
ISO control objective

6.1.4: AI system impact assessment

ISO control

The organization shall conduct AI system impact assessments covering potential effects on individuals, groups, and society.

Gap analysis
Partial Gap
AIUC-1 requires risk assessment and organizations can opt-in to the optional quality management system requirement, but does not require impact assessment specifically
ISO control objective

6.2: AI objectives and planning to achieve them

ISO control

The organization shall establish AI objectives at relevant functions and levels, consistent with the AI policy, and maintain plans to achieve them.

Relevant AIUC-1 requirements
Gap analysis
Full Gap
Requiring high-level AI objectives is outside the scope of AIUC-1
ISO control objective

6.3: Planning of changes

ISO control

The organization shall plan and control changes to the AI management system in a planned manner.

Gap analysis
No Gap
AIUC-1 requires that both system changes and process changes are reviewed
ISO control objective

7.1: Resources

ISO control

The organization shall determine and provide necessary resources for the AI management system.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
Organizations opting-in to the optional quality management system requirement will be required to documenting resource management, including security-of-supply related measures
ISO control objective

7.2: Competence

ISO control

The organization shall ensure competence of persons working under its control based on education, training, or experience.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 requires that accountability is clearly assigned, but does not require competence assessment specifically
ISO control objective

7.3: Awareness

ISO control

Persons under the organization’s control shall be aware of the AI policy, objectives, and their contribution to the AI management system.

Relevant AIUC-1 requirements
Gap analysis
Full Gap
Internal training processes are outside the scope of AIUC-1
ISO control objective

7.4: Communication

ISO control

The organization shall determine internal and external communications relevant to the AI management system.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 does not specify internal communication requirements
ISO control objective

7.5.1: Documented information — General

ISO control

The organization shall document information required by the AI management system and by ISO42001.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Organizations opting-in to the optional quality management system requirement will meet this control
ISO control objective

7.5.2: Creating and updating documented information

ISO control

The organization shall ensure documented information is properly created, updated, and controlled for suitability and adequacy.

Relevant AIUC-1 requirements
Gap analysis
No Gap
The combination of quarterly internal reviews and annual recertification requirements fulfils this control
ISO control objective

7.5.3: Control of documented information

ISO control

The organization shall control documented information required by the AI management system and ISO42001.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Required as part of AIUC-1 certification process
ISO control objective

8.1: Operational planning and control

ISO control

The organization shall plan, implement, and control processes needed for the AI management system, ensuring outputs meet requirements.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Organizations opting-in to the optional quality management system requirement will meet this control
ISO control objective

8.2: AI risk assessment

ISO control

The organization shall perform AI risk assessments at planned intervals and when significant changes occur.

Gap analysis
No Gap
ISO control objective

8.3: AI risk treatment

ISO control

The organization shall implement AI risk treatment plans and review them when assessments identify new or ineffective controls.

Gap analysis
No Gap
ISO control objective

8.4: AI system impact assessment

ISO control

The organization shall perform AI system impact assessments at planned intervals and when significant changes are proposed.

Gap analysis
Partial Gap
AIUC-1 requires risk assessment and organizations can opt-in to the optional quality management system requirement, but does not require impact assessment specifically
ISO control objective

9.1: Monitoring, measurement, analysis and evaluation

ISO control

The organization shall determine monitoring, measurement, analysis, and evaluation needed to ensure conformity and effectiveness.

Gap analysis
No Gap
Organizations opting-in to the optional quality management system requirement will meet this control
ISO control objective

9.2.1: Internal audit - General

ISO control

The organization shall conduct internal audits at planned intervals to provide information on the AI management system.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

9.2.2: Internal audit programme

ISO control

Top management shall review the AI management system at planned intervals for continuing suitability, adequacy, and effectiveness.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

9.3.1: Management review - General

ISO control

The organization shall review the AI management system at planned intervals to ensure its suitability, adequacy, and effectiveness.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

9.3.2: Management review inputs

ISO control

Management review inputs shall include audits, performance trends, nonconformities, feedback, risks, changes, and resources.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 internal review requirement is smaller in scope, so fulfilment of 9.3.2 depends on organizational implementation
ISO control objective

9.3.3: Management review results

ISO control

Management review results shall include decisions on improvements, policy/objectives, resources, and follow-up actions.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 internal review requirement is smaller in scope, so fulfilment of 9.3.2 depends on organizational implementation
ISO control objective

10.1: Continual improvement

ISO control

The organization shall continually improve the AI management system’s suitability, adequacy, and effectiveness.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Organizations opting-in to the optional quality management system requirement will meet this control
ISO control objective

10.2: Nonconformity and corrective action

ISO control

The organization shall address nonconformities by correcting them, dealing with consequences, and preventing recurrence.

Gap analysis
No Gap
Organizations opting-in to the optional quality management system requirement will meet this control
ISO control objective

A.2.2: AI policy

ISO control

The organization shall document a policy for the development or use of AI systems.

Gap analysis
No Gap
AI Acceptable Use Policy and Transparency Policy collectively fulfil the ISO control. Organizations may develop a standalone AI policy
ISO control objective

A.2.3: Alignment with other organizational policies

ISO control

The organization shall determine where other policies can be affected by or apply to the organization's objectives with respect to AI systems.

Gap analysis
Partial Gap
AIUC-1 does not require review of internal policies specifically, but require regulatory compliance reviews and regular internal reviews
ISO control objective

A.2.4: Review of the AI policy

ISO control

The AI policy shall be reviewed at planned intervals or additionally as needed to ensure its continuing suitability, adequacy and effectiveness.

Gap analysis
No Gap
ISO control objective

A.3.2: AI roles and responsibilities

ISO control

Roles and responsibilities for AI shall be defined and allocated according to the needs of the organization.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

A.3.3: Reporting of concerns

ISO control

The organization shall define and put in place a process to report concerns about the organization's role with respect to an AI system throughout its life cycle.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 does not require internal reporting processes specifically, but require regular internal reviews
ISO control objective

A.4.2: Resource documentation

ISO control

The organization shall identify and document relevant resources required for all activities at given AI system life cycle stages and other AI-related activities relevant for the organization.

Gap analysis
Partial Gap
AIUC-1 does not require resource documentation specifically, but requires maintaining a centralized repository of system documentation and documenting resource management for organizations opting in to the optional quality management system requirement
ISO control objective

A.4.3: Data resources

ISO control

As part of resource identification, the organization shall document information about the data resources utilized for the AI system.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Fulfilled by organisations opting into the capability-specific requirement A103: Track training data lineage. In addition, E017: Document system transparency policy lists documenting datasheets in control activities
ISO control objective

A.4.4: Tooling resources

ISO control

As part of resource identification, the organization shall document information about the tooling resources utilized for the AI system.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Included in transparency policy control activities
ISO control objective

A.4.5: System and computing resources

ISO control

As part of resource identification, the organization shall document information about the system and computing resources utilized for the AI system.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Included in transparency policy control activities
ISO control objective

A.4.6: Human resources

ISO control

As part of resource identification, the organization shall document information about the human resources and their competences utilized for the development, deployment, operation, change management, maintenance, transfer and decommissioning, as well as verification and integration of the AI system.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 is scoped to require documentation of clear accountability assigned for system changes
ISO control objective

A.5.2: AI system impact assessment process

ISO control

The organization shall establish a process to assess the potential consequences for individuals or groups of individuals, or both, and societies that can result from the AI system throughout its life cycle.

Gap analysis
Partial Gap
AIUC-1 requires risk assessment and organizations can opt-in to the optional quality management system requirement, but does not require impact assessment specifically
ISO control objective

A.5.3: Documentation of AI system impact assessments

ISO control

The organization shall document the results of AI system impact assessments and retain results for a defined period.

Gap analysis
Partial Gap
AIUC-1 requires risk assessment and organizations can opt-in to the optional quality management system requirement, but does not require impact assessment specifically
ISO control objective

A.5.4: Assessing AI system impact on individuals or groups of individuals

ISO control

The organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.

Gap analysis
Partial Gap
AIUC-1 requires risk assessment and organizations can opt-in to the optional quality management system requirement, but does not require impact assessment specifically
ISO control objective

A.5.5: Assessing societal impacts of AI systems

ISO control

The organization shall assess and document the potential societal impacts of their AI systems throughout their life cycle.

Gap analysis
Partial Gap
AIUC-1 requires risk assessment, but does not require impact assessment specifically. Impact on society is scoped to cyber and catastrophic misuse prevention
ISO control objective

A.6.1.2: Objectives for responsible development of AI system

ISO control

The organization shall identify and document objectives to guide the responsible development AI systems, and take those objectives into account and integrate measures to achieve them in the development life cycle.

Relevant AIUC-1 requirements
Gap analysis
Full Gap
Organizations pursuing AIUC-1 are naturally aligned with responsible AI principles, but AIUC-1 does not require documentation of responsible AI objectives specifically.
ISO control objective

A.6.1.3: Processes for responsible AI system design and development

ISO control

The organization shall define and document the specific processes for the responsible design and development of the AI system.

Relevant AIUC-1 requirements
Gap analysis
Full Gap
Organizations pursuing AIUC-1 are naturally aligned with responsible AI principles, but AIUC-1 does not require documentation of responsible AI processes specifically
ISO control objective

A.6.2.2: AI system requirements and specification

ISO control

The organization shall specify and document requirements for new AI systems or material enhancements to existing systems.

Gap analysis
No Gap
ISO control objective

A.6.2.3: Documentation of AI system design and development

ISO control

The organization shall document the AI system design and development based on organizational objectives, documented requirements and specification criteria.

Gap analysis
No Gap
ISO control objective

A.6.2.4: AI system verification and validation

ISO control

The organization shall define and document verification and validation measures for the AI system and specify criteria for their use.

Gap analysis
No Gap
ISO control objective

A.6.2.5: AI system deployment

ISO control

The organization shall document a deployment plan and ensure that appropriate requirements are met prior to deployment.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

A.6.2.6: AI system operation and monitoring

ISO control

The organization shall define and document the necessary elements for the ongoing operation of the AI system. At the minimum, this should include system and performance monitoring, repairs, updates and support.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 is focused on monitoring risk categories and does not have product performance monitoring/product quality metrics in scope
ISO control objective

A.6.2.7: AI system technical documentation

ISO control

The organization shall determine what AI system technical documentation is needed for each relevant category of interested parties, such as users, partners, supervisory authorities, and provide the technical documentation to them in the appropriate form.

Gap analysis
No Gap
ISO control objective

A.6.2.8: AI system recording of event logs

ISO control

The organization shall determine at which phases of the AI system life cycle, record keeping of event logs should be enabled, but at the minimum when the AI system is in use.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

A.7.2: Data for development and enhancement of AI system

ISO control

The organization shall define, document and implement data management processes related to the development of AI systems.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Met by organizations who opt-in to the capability specific requirements on training data quality and lineage
ISO control objective

A.7.3: Acquisition of data

ISO control

The organization shall determine and document details about the acquisition and selection of the data used in AI systems.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Met by organizations who opt-in to the capability specific requirement E103: Track training data lineage
ISO control objective

A.7.4: Quality of data for AI systems

ISO control

The organization shall define and document requirements for data quality and ensure that data used to develop and operate the AI system meet those requirements.

Relevant AIUC-1 requirements
Gap analysis
No Gap
Met by organizations who opt-in to the capability specific requirement on training data quality
ISO control objective

A.7.5: Data provenance

ISO control

The organization shall define and document a process for recording the provenance of data used in its AI systems over the life cycles of the data and the AI system.

Gap analysis
No Gap
ISO control objective

A.7.6: Data preparation

ISO control

The organization shall define and document its criteria for selecting data preparations and the data preparation methods to be used.

Relevant AIUC-1 requirements
Gap analysis
Partial Gap
AIUC-1 does not require data preparation methods specifically, but covers training data quality more broadly
ISO control objective

A.8.2: System documentation and information for users

ISO control

The organization shall determine and provide the necessary information to users of the AI system.

Gap analysis
No Gap
ISO control objective

A.8.3: External reporting

ISO control

The organization shall provide capabilities for interested parties to report adverse impacts of the AI system.

Gap analysis
Partial Gap
AIUC-1 requirement focuses on AI system users and does not require reporting capabilities for external parties
ISO control objective

A.8.4: Communication of incidents

ISO control

The organization shall determine and document a plan for communicating incidents to users of the AI system.

Gap analysis
No Gap
ISO control objective

A.8.5: Information for interested parties

ISO control

The organization shall determine and document their obligations to reporting information about the AI system to interested parties.

Gap analysis
No Gap
ISO control objective

A.9.2: Processes for responsible use of AI systems

ISO control

The organization shall define and document the processes for the responsible use of AI systems.

Gap analysis
No Gap
AIUC-1 requires an Acceptable Use policy which covers prohibited use cases to ensure responsible use of AI systems. In addition, AIUC-1 has a number of concrete requirements ensuring responsible use of the AI system including, e.g., flagging high risk recommendations for human review and monitoring AI risk categories
ISO control objective

A.9.3: Objectives for responsible use of AI system

ISO control

The organization shall identify and document objectives to guide the responsible use of AI systems.

Gap analysis
Partial Gap
Partially covered by Acceptable Use Policy, but AIUC-1 does not require documenting objectives specifically.
ISO control objective

A.9.4: Intended use of the AI system

ISO control

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

Gap analysis
No Gap
Acceptable Use Policy control activities require implementing detection and monitoring tools to track policy violations
ISO control objective

A.10.2: Allocating responsibilities

ISO control

The organization shall ensure that responsibilities within their AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

A.10.3: Suppliers

ISO control

The organization shall establish a process to ensure that its usage of services, products or materials provided by suppliers aligns with the organization's approach to the responsible development and use of AI systems.

Relevant AIUC-1 requirements
Gap analysis
No Gap
ISO control objective

A.10.4: Customers

ISO control

The organization shall ensure that its responsible approach to the development and use of AI systems considers their customer expectations and needs.

Relevant AIUC-1 requirements
Gap analysis
Full Gap
AIUC-1 does not have specific requirements concerning customer expectations and needs, but covers a broad range of safeguards required to protect users of AI systems including regular testing that safeguards work
Last updated September 18, 2025.
© 2025 Artificial Intelligence Underwriting Company. All rights reserved.
By accessing or using our website, you agree to our Terms of Service and Privacy Policy.