ISO/IEC 42001:2023 Crosswalk
This document maps the FSI Agent Governance Framework controls to ISO/IEC 42001:2023 — Artificial Intelligence Management System (AIMS), the international standard for organizational AI governance.
ISO/IEC 42001 is complementary to NIST AI RMF (see NIST AI RMF Crosswalk) — the frameworks address different needs and many FSI organizations implement both. NIST AI RMF supports continuous risk identification and measurement; ISO/IEC 42001 provides a certifiable management-system structure (Plan-Do-Check-Act) that aligns with ISO 27001, ISO 9001, and other ISO management systems FSI firms already operate.
Scope note. This crosswalk maps clauses 4–10 (the certifiable management-system requirements) and Annex A (control objectives) to FSI-AgentGov controls. It is provided as an implementation aid for organizations preparing for ISO/IEC 42001 certification or third-party audit. It is not a conformity assessment and does not substitute for a formal gap analysis by an accredited certification body. Organizations should verify scope statements with their internal audit / compliance teams before relying on this mapping for certification evidence.
How to Use This Crosswalk
| Audience |
Use |
| Compliance Officer preparing for ISO 42001 certification |
Identify which FSI controls already provide implementation evidence; flag clauses with Partial or N/A coverage for gap remediation. |
| Internal Auditor |
Validate that FSI-AgentGov controls produce the artifacts ISO 42001 auditors expect (policies, risk register, monitoring records, management review minutes). |
| External Auditor (ISO 42001 certification body) |
Use the mapping as a roadmap for evidence collection — most clauses are addressed by existing Pillar 2 (Management) and Pillar 3 (Reporting) controls. |
| AI Governance Lead |
Pair this crosswalk with the NIST AI RMF Crosswalk for end-to-end coverage of both frameworks. |
Coverage Status Legend
| Status |
Meaning |
| Full |
One or more FSI-AgentGov controls directly address the clause requirements with documented procedures and evidence. |
| Partial |
FSI-AgentGov controls provide partial coverage; additional organization-specific procedures or policies are required. |
| Framework |
Addressed at the framework layer (governance principles, operating model) rather than via a specific control. |
| Org |
Organization-specific responsibility; FSI-AgentGov provides supporting controls but the AIMS scope, policy, and management review must be authored by the organization. |
| N/A |
Clause is administrative or scoping in nature and does not map to a technical control. |
Microsoft AI Service Certification Context
Microsoft has achieved ISO/IEC 42001 certification covering the following AI services in scope (per Microsoft Learn — ISO/IEC 42001 offering page, retrieved May 2026):
- GitHub Copilot
- Microsoft 365 Copilot
- Microsoft Copilot Health
- Microsoft Copilot Studio
- Microsoft Dragon Copilot
- Microsoft Foundry
- Microsoft Security Copilot
Audit reports and scope statements are available through the Microsoft Service Trust Portal.
Caveat for FSI maintainers: Microsoft's certification covers Microsoft's own service operations as the AI provider. It does not transfer to customer governance, customer use cases, or the customer's own AIMS. FSI organizations pursuing their own ISO 42001 certification must build and operate their own management system on top of these certified services. Use vendor certification as input to Control 2.7 (Vendor Risk Management) — not as a substitute for the customer's own AIMS evidence.
Clause 4: Context of the Organization
Clause 5: Leadership
Clause 6: Planning
| Clause |
Requirement |
FSI Controls / Artifacts |
Coverage |
| 6.1.1 Actions to address risks and opportunities |
Plan AIMS actions for risks/opportunities |
2.6 — Model Risk Management, Adoption Roadmap |
Full |
| 6.1.2 AI risk assessment |
Establish, implement, maintain AI risk assessment process |
2.6, 2.11 — Bias Testing, 2.20 — Adversarial Testing / Red Team |
Full |
| 6.1.3 AI risk treatment |
Risk treatment plan with documented controls |
2.6, Pillar 1 (Security) controls catalog |
Full |
| 6.1.4 AI system impact assessment |
Assess potential impacts on individuals, groups, society |
2.11, 2.19 — Customer AI Disclosure |
Partial |
| 6.2 AI objectives and planning to achieve them |
Establish measurable AIMS objectives |
Adoption Roadmap, Governance Cadence |
Org |
| 6.3 Planning of changes |
Plan changes to the AIMS in a controlled manner |
2.3 — Change Management |
Full |
Clause 7: Support
Clause 8: Operation
Clause 10: Improvement
Annex A — AI Management System Controls
ISO/IEC 42001 Annex A defines control objectives organized into nine categories (A.2 through A.10). The mapping below covers the categories most directly addressed by the FSI-AgentGov catalog. Annex A is informative in the standard — organizations document which Annex A controls they apply via a Statement of Applicability (SoA).
A.3 — Internal Organization
A.4 — Resources for AI Systems
A.5 — Assessing Impacts of AI Systems
A.6 — AI System Lifecycle
| Control Objective |
FSI Controls / Artifacts |
Coverage |
| A.6.1.2 Objectives for responsible development |
Operating Model, Adoption Roadmap |
Framework |
| A.6.1.3 Processes for responsible AI design and development |
2.5 — Testing, Validation, and Quality Assurance, 2.11 |
Full |
| A.6.2.2 AI system requirements and specification |
1.2 — Agent Registry, 3.1 — Agent Inventory |
Full |
| A.6.2.3 Documentation of AI system design and development |
2.13 |
Full |
| A.6.2.4 AI system verification and validation |
2.5, 2.20 — Adversarial Testing / Red Team |
Full |
| A.6.2.5 AI system deployment |
2.1 — Managed Environments, 2.3 — Change Management, 2.15 — Environment Routing |
Full |
| A.6.2.6 AI system operation and monitoring |
2.9 — Agent Performance Monitoring, 3.2 — Usage Analytics |
Full |
| A.6.2.7 AI system technical documentation |
2.13, 2.19 |
Full |
| A.6.2.8 AI system event logs |
1.7 — Comprehensive Audit Logging, 3.9 — Microsoft Sentinel Integration |
Full |
A.7 — Data for AI Systems
A.9 — Use of AI Systems
A.10 — Third-Party and Customer Relationships
Coverage Summary
| Coverage |
Count (Approx.) |
Notes |
| Full |
22 |
Direct mapping to documented controls |
| Partial |
4 |
Supported but require organization-specific augmentation |
| Framework |
9 |
Addressed at framework / governance-principles layer |
| Org |
6 |
Organization-specific responsibility (AIMS scope, policy, management review) |
Interpretation. A high Full count indicates that a customer pursuing ISO/IEC 42001 certification can use FSI-AgentGov as a substantial implementation backbone for an M365 / Power Platform AI estate. The Org-coverage clauses (4.3 scope, 5.2 AI policy, 6.2 objectives, 7.1 resources, 9.3 management review, A.2.2 AI policy approval) are deliberately customer-owned — no external framework can author them on the organization's behalf. The Partial-coverage rows generally require domain-specific impact-assessment language that the organization writes against its own products and customer base.
Relationship to NIST AI RMF
NIST AI RMF and ISO/IEC 42001 are complementary, not competitive:
| Aspect |
NIST AI RMF |
ISO/IEC 42001 |
| Nature |
Voluntary risk-management framework |
Certifiable management-system standard |
| Structure |
4 functions (Govern, Map, Measure, Manage), 72 subcategories |
PDCA management system (Plan-Do-Check-Act), Annex A control objectives |
| Certification |
Not certifiable |
Third-party certifiable by accredited bodies |
| Geography |
U.S.-focused |
International |
| Primary value |
Continuous risk identification and measurement |
Formal governance structure and certifiable evidence |
Recommended sequencing for FSI organizations:
- Begin with NIST AI RMF risk assessments (lower implementation barrier) — see NIST AI RMF Crosswalk
- Formalize findings into ISO/IEC 42001 AIMS policies and Annex A control mapping
- Pursue ISO/IEC 42001 certification (typically 12–18 month engagement with an accredited certification body)
- Use NIST AI RMF for continuous risk monitoring between annual ISO 42001 surveillance audits
References
Updated: May 2026 | Version: v1.6.2 | ISO/IEC 42001 Mapping Last Verified: May 2026