Compliance · ISO 42001

The AI questionnaire your customers started sending.

ISO/IEC 42001, AI management systems

ISO/IEC 42001 sets out how to run an AI management system, and for most teams it arrives from customers rather than regulators — a line in a supplier questionnaire, then a clause in a contract. The standard begins where every AI programme begins: a register of the AI systems in use, a named person accountable for each, controls over the AI your suppliers bring with them, and the inputs to an impact assessment. KeyCaliber produces that material from read-only connections to the tools you already run. We do not certify anyone. We give you the evidence an assessor and a customer both ask to see.

What ISO 42001 expects.

  • A register of the AI systems in use across the organization
  • A named person accountable for each one
  • Controls over the AI your suppliers bring with them
  • Inputs to an AI impact assessment

What KeyCaliber gives you.

One register, four kinds of AI

Hosted services, AI features inside apps you already approved, model runtimes on laptops and servers, and remote endpoints in use.

A named owner on every app

Recorded on the app, with who set it and when. It is the column the standard asks for, and the one most inventories leave blank.

Your suppliers' AI, documented

Each vendor's published training policy and certifications, read from their own pages and dated, with the vendors they hand your data to alongside.

Evidence, not assertion

Every value says how it was arrived at: observed from your telemetry, curated, entered by your team, or not yet assessed. Nothing is rounded down to a clean answer.

Held to more than one?

The same connections serve all of them. Nothing new to integrate.

Answer the questionnaire with evidence.

Connect the tools you already run and see your own picture.

Request a demo