This page is for AI governance leads, ISMS or AIMS owners, and the engineers asked to make an ISO/IEC 42001 programme real for a fleet of AI agents. It maps the controls Praesidia provides to the clauses of ISO/IEC 42001:2023 and the Annex A controls that agent deployments stress most, and it lists the evidence you can export for each.
ISO/IEC 42001 is a management-system standard. It follows the harmonised structure shared with ISO 27001: context (clause 4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9), and improvement (10). Annex A lists reference controls; Annex B gives implementation guidance. The standard does not care which framework your agents run on. It cares whether you know what AI systems you operate, have assessed their risks and impacts, operate controls proportionate to those risks, monitor them, and improve.
Agents make several clauses concrete in uncomfortable ways. Clause 6.1.2 asks for an AI risk assessment, which requires a complete inventory; agents get created by developers in an afternoon. A.6.2.8 asks for event logs; agents call tools and other agents across boundaries traditional logging does not cover. A.10 asks for third-party responsibility allocation; an agent's model provider and the MCP servers it calls are third parties. The ISO/IEC 42001 post covers the standard in depth; the SOC 2 versus ISO 42001 comparison explains how the two programmes divide the work.
Control mapping
| Requirement / criterion | What Praesidia provides | Evidence you can produce |
|---|---|---|
| Clause 6.1.2 / 8.2 — AI risk assessment, repeated on change | Per-agent risk classification aligned with ISO 42001 and the EU AI Act, reassessable as scope or configuration changes, with history retained. Risk criteria and acceptance are yours. | Classification record and revision history per agent; list of agents by tier. |
| Clause 6.1.3 / 8.3 — AI risk treatment | Per-connection guardrails, policies, budgets, and human approval gates as implemented treatments; each treatment attached to the connection it mitigates. | Treatment-to-connection mapping; control configuration export; risk-treatment plan cross-reference you maintain. |
| Clause 6.1.4 / 8.4 and A.5 — AI system impact assessment | Customer control; Praesidia contributes the recorded scope, purpose, permitted tools, and risk tier per agent as inputs, and the audit trail as evidence of actual behaviour against assessed behaviour. | Per-agent scope export; behaviour metrics for the assessment period; your completed impact assessment. |
| Clause 7.5 — Documented information | Customer control; Praesidia contributes machine-readable configuration for every agent, connection, and control, retrievable over the API for inclusion in your AIMS documentation. | Configuration exports with timestamps; change history. |
| Clause 9.1 — Monitoring, measurement, analysis, evaluation | OpenTelemetry metrics and traces, guardrail hit rates, denied-request counts, spend attribution per agent and team, alert rules on the audit stream, SIEM forwarding. | Metric exports and dashboards for the review period; alert history. |
| Clause 9.2 — Internal audit | Tamper-evident audit trail export, access-review workflows, and gap analysis against the 42001 control set as audit inputs. | Exported audit bundle with verifier result; completed access reviews; gap-analysis report. |
| Clause 9.3 — Management review | Compliance reports mapped to recognised frameworks, including ISO 42001, summarising posture and open gaps. | Generated compliance report for the review; trend of gaps closed. |
| A.3.2 — Roles and responsibilities | Role-based access control for the control plane, SSO and SCIM tied to your identity provider, and scoped API keys for automation. | Role assignments; SCIM lifecycle records; API-key scope listing. |
| A.4.5 / A.4.4 — System, computing, and tooling resources | Inventory of every agent, MCP server, and application with credentials; bring-your-own-key model-provider configuration; hard spend caps and rate limits on computing consumption. | Inventory export; provider configuration; budget and rate-limit settings with triggered events. |
| A.6.2.6 — AI system operation and monitoring | Bidirectional guardrails, intent rules with block or flag verdicts, non-human identity with rotation and single-agent revocation, alerting. | Guardrail decisions; revocation events; alert history. |
| A.6.2.8 — Recording of event logs | Append-only record of every request, response, and policy decision on routed connections; optional cryptographic tamper-evidence; offline verifier; optional public transparency-log anchoring. | Signed bundle export; verifier output reproducible by the auditor. |
| A.8.4 — Communication of incidents | Customer control; Praesidia contributes forensic search, hop-by-hop attribution across agent chains, and signed webhooks and SIEM forwarding to feed your incident process. | Incident-period export; forwarded event records. |
| A.9.4 — Intended use of the AI system | Declared connections and permitted tools per agent enforce intended use; tool out of scope is a rule class the intent layer can block. | Connection and tool-authorization configuration; out-of-scope block records. |
| A.10.3 / A.10.4 — Suppliers and customers | Customer control; Praesidia contributes model-provider BYOK (you own the provider relationship), governed MCP-server connections with per-tool authorization, and a published subprocessor list on the security page. | Provider and MCP-server inventory; your supplier assessments. |
What this mapping is not
This mapping supports your assessment and does not constitute certification. ISO/IEC 42001 certificates are issued by accredited certification bodies after a staged audit of your management system. A vendor can neither issue one nor stand in for the management system itself.
Large parts of the standard are organisational by design. Clause 4 (understanding your context and interested parties), clause 5 (leadership, policy, and roles), clause 6.2 (AI objectives), clause 7.2 and 7.3 (competence and awareness), and clause 10 (nonconformity and continual improvement) are things people do. Praesidia gives those activities a system of record and real operating data; it does not perform them.
Two scoping points should appear in your statement of applicability. The audit trail covers connections routed through Praesidia; agent traffic that bypasses the platform is not visible to it. And if you enable cryptographic signing, the offline verifier proves that exported records were not altered after signing, not that every action was captured in the first place. Both limits are stated at /security/verify-your-audit-trail, and an internal auditor should read them before relying on the export.
Getting started
- Build the inventory first. Register every agent, MCP server, and application at /start; the getting-started guide covers the first entity and connection. Clause 6.1.2 is impossible against an incomplete list.
- Record a risk tier and intended use per agent, then attach the treatments (guardrails, policies, budgets, approval gates) to each connection so the risk-treatment plan and the running configuration are the same document.
- Produce one piece of A.6.2.8 evidence end to end by following from agent action to audit evidence and verifying the export offline per /security/verify-your-audit-trail.
- Put clause 9 on a calendar: monthly monitoring review, access reviews using the access review guide, and a compliance report generated for each management review.
Common questions
A management-system standard, in the same family as ISO 27001. It asks whether your organization has an AI management system (AIMS) with leadership commitment, planning, risk and impact assessment, operational controls, performance evaluation, and improvement. Annex A lists the controls; Annex B explains how to implement them. Technology helps you operate the AIMS; it is not the AIMS.
No. Certification is granted by an accredited certification body after auditing your management system. A vendor supplies controls and evidence for parts of Annex A and helps clauses 8 and 9 run on real data instead of spreadsheets. This mapping supports your assessment and does not constitute certification.
A.6.2.6 (operation and monitoring), A.6.2.8 (recording of event logs), A.4 (resources, including computing and tooling), A.9 (responsible use and intended use), A.10 (third-party relationships, which covers model providers and MCP servers), and A.5 (impact assessment) when agents affect individuals.
ISO/IEC 42005 gives guidance for the AI system impact assessment that 42001 requires in clause 6.1.4 and 8.4 and control A.5. Praesidia records the per-agent risk tier and scope that feed such an assessment; the assessment itself, and the decision on acceptable impact, are yours. See the ISO/IEC 42005 post linked below.
Monitoring data (guardrail hit rates, denied requests, budget events) for clause 9.1, the audit-trail export and completed access reviews as internal-audit inputs for 9.2, and gap-analysis and compliance reports against the 42001 control set as management-review material for 9.3.