Skip to content

ISO/IEC 42001 with zGentic

This page is for the people responsible for AI governance in your organisation: owners, admins, compliance and audit. It explains how zGentic helps you run an AI management system that meets ISO/IEC 42001 (AI management systems), and which features provide the evidence.

What zGentic does and does not do for you

ISO/IEC 42001 certifies your organisation's management system, not a piece of software. No tool makes you compliant on its own: you still need your AI policy, your risk and impact assessments, defined roles and an internal audit. What zGentic gives you is the operational controls and the evidence for the parts of the standard that concern how AI is actually used: an inventory of your AI systems, human oversight, traceability, and records an auditor can rely on.

How the standard maps to zGentic

What ISO/IEC 42001 asks for How you do it in zGentic Where
Know which AI systems you use (inventory) The AI inventory lists every model, provider, agent, skill, connector and tool, with owner, purpose, status and risk class. Download it as CSV or JSON for your register. Admin → AI inventory
Classify AI systems by risk Give each agent and skill a risk class (minimal, limited, high) and an intended use. Every change to a classification is recorded. The agent's settings
Assess and treat risks High-risk agents get stricter treatment automatically: every tool use needs approval, their plans never start on their own, and nobody may approve their own request. Follows from the risk class
Human oversight Approvals for actions you choose; HITL rules for what needs a person; escalation of approvals that wait too long; required reasons when rejecting; an option to hold poorly supported answers for review. Admin → Approvals; HITL rules in the agent's settings and in your own tool-safety settings
Defined roles and responsibilities Owners, admins, members, viewers and reviewers, plus custom roles built from a catalogue of capabilities. A custom role can never grant more than its creator holds. Admin → Users (custom roles are there too)
Traceability of AI decisions Every answer records which model version the provider actually served. Each turn's steps (tools used, approvals, waits) are kept with the chat. The chat; Admin → Audit log
Records that cannot be altered The audit log is append-only and hash-chained: each entry is linked to the one before it, so a missing or altered entry is detected. Verify integrity checks the whole chain on demand. Admin → Audit log
Retention of records Owners set how long audit records are kept (at least one year; by default everything is kept). Admin → Audit log
Change management for AI systems Model configuration changes are recorded with before and after. Agents are versioned: compare versions, pin one, roll back. Admin → Model backend; the agent's page
Data governance Answers use only material the asking person may open (permission-aware retrieval). Organisations are fully separated. Deleting an organisation also deletes its stored files. Built in
Operational control of third-party AI Choose your model providers per organisation, restrict which models people may pick, set fallbacks, and control what each connector's tools may do. Admin → Model settings, Connectors
Monitoring and measurement Usage and spend per person, model and agent; the approvals overview shows how many approvals are open, overdue or escalated, and how long decisions take. Admin → Billing & usage, Approvals

Evidence an auditor will ask for

The table below is a starting checklist for an internal or certification audit.

Evidence How to produce it
The AI system register Download the AI inventory (CSV or JSON).
Risk classification of each AI system The inventory's risk column, plus the audit entries for each classification change.
Proof that oversight happened The audit log's approval entries: who decided, when, and the reason chosen.
Integrity of the records Run Verify integrity on the audit log and keep the result with your audit file. Exports can also be verified offline.
Which model produced an answer Recorded on every answer; model configuration changes are in the audit log.
Access control The people and roles lists, and the audit entries for role changes.

What is still yours to do

zGentic does not write these for you:

  • your AI policy and its objectives;
  • AI risk and impact assessments, beyond the risk class you record per agent;
  • the statement of applicability for the standard's controls;
  • competence and awareness of your people;
  • internal audit and management review of the management system.