Are You an AI Provider or an AI User? ISO/IEC 42001 Roles Explained
ISO/IEC 42001 requires you to determine your role, and that role decides which Annex A controls apply. How to tell whether you are an AI provider, producer, customer or user.
ISO Lead Auditors · PCI QSA and 3DS Assessor · SOC and government assessors. Conflict-free, across six regions.
ISO/IEC 42001 requires you to determine your role, and that role decides which Annex A controls apply. How to tell whether you are an AI provider, producer, customer or user.
What ISO/IEC 42001 control A.10.2 requires when your AI runs on someone else’s cloud, the gaps we find as auditors, and four steps to take before your audit.
A risk assessment asks what could harm the organisation. An AI system impact assessment asks who the organisation could harm. ISO/IEC 42005:2025 is the first international standard devoted to the second question, and it is the implementation detail behind ISO/IEC 42001 clause 6.1.4.
Generative AI removed every tell that phishing training taught. A cybersecurity assessor explains why user detection can no longer be your primary defence, and what replaces it.
AI is entering payment environments fast. How PCI DSS applies to AI and LLM systems, where cardholder data leaks, and how to keep it safe.
AI now mediates hiring, healthcare, education, policing and public benefits. A rights-based analysis of where AI presses hardest on internationally recognised human rights, and the ten-pillar governance framework that closes the gap between principle and enforceable accountability.
Datacom’s Datascape is the first New Zealand-based recipient of ISO/IEC 42001:2023 certification for AI management systems, audited by Cianaa’s independent auditors with the certificate issued by MSECB.
ISO/IEC 42001:2023 is the world’s first international standard dedicated to Artificial Intelligence Management Systems (AIMS). Published in 2023, this standard provides a comprehensive, certifiable framework for organizations to govern the…
AI governance is becoming the next pillar of enterprise compliance. This practical guide outlines the framework and controls organisations need to deploy AI responsibly and demonstrate accountability under ISO/IEC 42001.
We use essential cookies to run this site and, with your consent, analytics & tools (e.g. Google Analytics, HubSpot) to improve it. See our Cookies & Privacy Policy.