Swipe to see all columns →
| Clause | Requirement | Runback capability | Evidence |
|---|---|---|---|
| 6.1 | Actions to address risks and opportunities in the AI management system. | Risk dashboard + policy engine | A policy rule evaluated on a real tool call See it in the dashboard → |
| 8.4 | Assessment of AI system impacts — maintain documented information of AI system impacts. | Compliance artifact download + ledger | An entry in the hash-chained, append-only ledger See it in the dashboard → |
| 9.1 | Monitoring, measurement, analysis, and evaluation of AI system performance. | Fleet benchmarks + error rate tracking | A captured run in the audit trace See it in the dashboard → |
| 9.3 | Management review of the AI management system at planned intervals. | Compliance report export (machine-readable) | Aggregated from real run data into a compliance report See it in the dashboard → |
| 10.2 | Nonconformity and corrective action — document and retain evidence. | Golden test + incident-to-test auto-enroll | A captured run in the audit trace See it in the dashboard → |
Honest limits
What this page does not claim.
- ISO 42001 certification is an organisational audit, not a software feature. Runback supplies evidence for the clauses below; it does not make an organisation certified.
- Runback itself does not hold ISO 42001 certification. The security page states exactly what is and isn't certified today.
- This is a capability map, not a conformity determination. Whether your deployment satisfies ISO/IEC 42001 is a determination for your own assessor — what's listed above is the evidence that argument draws on.