Checkpoint · ISO 42001

ISO 42001 software for AI governance

Checkpoint runs an ISO/IEC 42001 AI management system alongside your ISO 27001 one: an AI systems register, impact assessments and the Annex A controls, with the same risk register, audits and management reviews.

The demo is the real console with sample data. No sign-up.

Checkpoint Statement of Applicability for ISO 42001: AI management system controls with scope, status, cross-framework mappings, owner, assurance and evidence
Checkpoint, demo tenant with sample data. Open this screen in the demo

What Checkpoint holds for ISO 42001

  • The ISO/IEC 42001:2023 Annex A control set: policies, resourcing, impact assessment, life cycle, data, disclosure, use and third-party relationships.
  • Clauses 4–10 as requirement checklists, on the same clause register as ISO 27001.
  • An AI systems register and an AI impact assessment procedure.
  • AI-specific policies, kept separate from your information security documents.

Measured from your Microsoft 365

The scan flags high-privilege app grants in Microsoft Entra that nobody has reviewed, a common route for unapproved AI tools to reach your data.

Checkpoint signs in with Microsoft Entra and reads your settings through Microsoft Graph with read-only, delegated permissions. Your records are SharePoint lists in your own tenant, so if you stop using Checkpoint they are still yours. How Checkpoint works.

Questions

Do we need ISO 27001 first?
No, but most organisations pair them. Checkpoint runs both on one clause register and one risk register, so shared work is done once.
Is ISO 42001 certifiable?
Yes. ISO/IEC 42001 is a certifiable management system standard, audited by an accredited certification body.
Does it cover the EU AI Act?
Checkpoint does not run the EU AI Act as a framework. ISO 42001 is commonly used as the management system behind AI Act obligations; the free EU AI Act classifier on our ISO 42001 page helps you check where a system may fall.
Microsoft Teams