Job to be done · ISO/IEC 42001

A management system, not a binder.

Clauses 4 to 10 and the Annex A controls, run as a gated programme with a Statement of Applicability produced from the work rather than maintained alongside it. The audit pack assembles from the same register, sealed and tamper-evident.

No card · EU-hosted · 5 minutes to a first classification
Veritome ISO/IEC 42001 programme — gated phases, one record per step, and the steps credited by work already on file
The reality

Where certification programmes go wrong.

What we hear

“Our SoA is a spreadsheet nobody has opened since the gap analysis.”

What the product does

An SoA maintained beside the work is out of date the week after it is written. Produced from the programme, it cannot disagree with what was actually done.

What we hear

“We excluded controls and cannot remember why.”

What the product does

An exclusion without a justification is the first thing an auditor pulls. Here it will not save without one.

What we hear

“We are doing 27001 and 42001 as two projects.”

What the product does

They share a clause spine and a good deal of evidence. Fourteen templates carry both placements — one record, two programmes.

What you get

The programme, gated in order.

01

Phases that lock

A later phase stays locked while an earlier one is incomplete, so the programme cannot be run out of order and then reconciled.

02

The SoA as a view

Applied and excluded controls, produced from the steps. Exclusions need a justification sentence; the steps open pre-filled where a field is genuinely empty.

03

Controls that carry evidence

Approving a step produces a control with the evidence attached, rather than a claim that evidence exists elsewhere.

04

ISO 27001 shared once

Fourteen record templates carry a second placement. Complete one and the sibling programme re-plans around it.

05

The audit pack, sealed

Exported as a PDF with a SHA-256 manifest of every source document — tamper-evident chain of custody rather than a zip of screenshots.

06

Article 17 ticked from real work

Where the management system genuinely carries an Art. 17 aspect, the checklist ticks from it — tick-only, never a status the software awards itself.

In practice

Three routes to an audit.

Use case 01

A provider preparing a first 42001 certification.

  • Establish, then map, then operate — phases gate in that order.
  • The SoA fills as steps complete, with exclusions justified in place.
  • Art. 17 checklist items tick where the system genuinely carries them.
  • The pack exports sealed, with an integrity manifest.
Veritome ISO/IEC 42001 programme — gated phases, one record per step, and the steps credited by work already on file
Use case 02

A company already certified to ISO 27001.

  • Fourteen records count toward both standards — a large head start, not a fresh project.
  • Approving one re-plans the other programme.
  • Clause 4 to 10 structures line up, so scope and context are written once.
  • A step your ISO 27001 work already covers is Done, credited — never done twice.
Veritome programmes — each standard you switched on, its phases and the next step, beside the EU AI Act spine
Use case 03

A team asked for an SoA by a customer's security review.

  • The SoA is a view, so it is current the moment the programme is.
  • Applied and excluded controls, each with its reason.
  • Exported without assembling anything by hand.
  • It states what is assigned, not what is implemented — the distinction an auditor will test.
Veritome Statement of Applicability — every ISO/IEC 42001 Annex A control with its decision, justification and the measure that addresses it
Also included

What sits beside the programme.

Straight answers

Straight answers about certification.

Does ISO/IEC 42001 make us EU AI Act compliant?

No, and anyone who tells you otherwise is selling something. A certified management system is strong evidence of governance, but requirement equivalence needs a harmonised standard cited in the Official Journal, and prEN 18286 is not there yet. Article 17(3) does let providers already subject to quality-management obligations under sectoral Union law fold the Article 17(1) aspects into that system — but a voluntary standard is not sectoral Union law, so 42001 does not open that route.

What is the Statement of Applicability, exactly?

The record of which Annex A controls you apply, which you exclude and why. In Veritome it is a view over the programme rather than a separate spreadsheet: the steps you have completed produce it, so it cannot drift from the work. An exclusion needs a justification sentence — a blank one will not pass an auditor and does not pass here either.

We already hold ISO 27001. Does that help?

Substantially. Fourteen of the record templates carry a second placement, so completing one satisfies the equivalent step in both programmes — one record, two programmes, and approving it re-plans the sibling. The clause structures share the same 4 to 10 spine.

How does the audit pack come together?

From the same register the programme runs on. Controls carry the evidence that proves them, policies carry owners and review dates, and the pack exports as a sealed PDF with an integrity manifest — the SHA-256 of every source document, so the bundle is tamper-evident.

Can Veritome issue the certificate?

No. Certification is issued by an accredited body after an audit, and no software can grant it. What Veritome does is get the management system into a state where the audit is about your organisation rather than about your paperwork.